Fallos del tipo CWE-863

3102 resultados

Falha na verificação de autorização

O software implementa uma verificação de acesso, mas a lógica está incorreta ou incompleta, permitindo que um usuário acesse recursos ou execute ações que não deveria. O risco é grave porque a autenticação (você é quem diz ser) pode estar correta, mas a autorização (você tem direito a isto?) falha, abrindo brechas para escalação de privilégios ou acesso a dados sensíveis.

Ejemplo

Uma API verifica se o usuário está logado antes de retornar dados de perfil, mas não valida se ele é dono do perfil consultado. Um atacante consegue acessar dados de outros usuários apenas mudando um ID na requisição. Ou um sistema de permissões usa condições OR quando deveria usar AND, liberando acesso para mais atores que o pretendido.

Cómo mitigar

Implemente controle de acesso a cada operação sensível verificando explicitamente se o usuário autenticado tem permissão específica para aquele recurso (não assuma contexto). Use bibliotecas de autorização consolidadas, testes unitários que validem negação de acesso, e revise a lógica de permissões regularmente, especialmente em APIs e operações administrativas.

CVE-2026-18703LOWImproper Enforcement of Authentication Mechanism Restrictions in MongoDB Server Allows Use of Disabled Authentication MethodEPSS 0.1%CVE-2022-31252MEDIUMpermissions: chkstat does not check for group-writable parent directories or target files in safeOpen()EPSS 0.1%CVE-2023-25185LOWAn issue was discovered on NOKIA Airscale ASIKA Single RAN devices before 21B. A mobile network solution internal fault was found in Nokia SEPSS 0.1%CVE-2025-43922HIGHThe FileWave Windows client before 16.0.0, in some non-default configurations, allows an unprivileged local user to escalate privileges to SEPSS 0.1%CVE-2024-45328HIGHAn incorrect authorization vulnerability [CWE-863] in FortiSandbox 4.4.0 through 4.4.6 may allow a low priviledged administrator to execute EPSS 0.1%CVE-2023-45793MEDIUMA vulnerability has been identified in Siveillance Control (All versions >= V2.8 < V3.1.1). The affected product does not properly check theEPSS 0.1%CVE-2025-0359HIGHDuring an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the ACAP Application framework thaEPSS 0.1%CVE-2026-49983MEDIUMDeno: process.loadEnvFile() bypasses env permission checks and mutates process.env with only read accessEPSS 0.1%CVE-2026-84617MEDIUMAn authorization issue was addressed with improved state management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, EPSS 0.1%CVE-2026-18171MEDIUMDocker Sandboxes read-only runtime mount writable through its shared-export aliasEPSS 0.1%CVE-2026-26949MEDIUMDell Device Management Agent (DDMA), versions prior to 26.02, contain an Incorrect Authorization vulnerability. A low privileged attacker wiEPSS 0.1%CVE-2026-84601MEDIUMA permissions issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27. An app may be able to bypass EPSS 0.1%CVE-2024-36055MEDIUMHw64.sys in Marvin Test HW.exe before 5.0.5.0 allows unprivileged user-mode processes to arbitrarily map physical memory with read/write accEPSS 0.1%CVE-2023-45023MEDIUMThe femanager extension 7 before 7.2.2 for TYPO3 has Incorrect Access Control: it lacks a check for permissions for the invitation componentEPSS 0.1%CVE-2026-92874MEDIUMIncorrect Authorization in GitLabEPSS 0.1%CVE-2026-19685HIGHNetworkmanager: networkmanager: 802-1x ca-path and phase2-ca-path bypass private_user restriction, allowing wpa-enterprise server validation bypass (incomplete fix for cve-2025-9615)EPSS 0.1%CVE-2026-32919MEDIUMOpenClaw < 2026.3.11 - Unauthorized Session Reset via agent Slash CommandsEPSS 0.1%CVE-2026-39402MEDIUMlxc lxc-user-nic insufficient ownership validation allows cross-tenant OVS port deletionEPSS 0.1%CVE-2026-84589MEDIUMA permissions issue was addressed with additional restrictions. This issue is fixed in macOS Golden Gate 27. An app may be able to modify PrEPSS 0.1%CVE-2024-47148MEDIUMSome Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause device service exceptiEPSS 0.1%