Fallos del tipo CWE-863

3104 resultados

Falha na verificação de autorização

O software implementa uma verificação de acesso, mas a lógica está incorreta ou incompleta, permitindo que um usuário acesse recursos ou execute ações que não deveria. O risco é grave porque a autenticação (você é quem diz ser) pode estar correta, mas a autorização (você tem direito a isto?) falha, abrindo brechas para escalação de privilégios ou acesso a dados sensíveis.

Ejemplo

Uma API verifica se o usuário está logado antes de retornar dados de perfil, mas não valida se ele é dono do perfil consultado. Um atacante consegue acessar dados de outros usuários apenas mudando um ID na requisição. Ou um sistema de permissões usa condições OR quando deveria usar AND, liberando acesso para mais atores que o pretendido.

Cómo mitigar

Implemente controle de acesso a cada operação sensível verificando explicitamente se o usuário autenticado tem permissão específica para aquele recurso (não assuma contexto). Use bibliotecas de autorização consolidadas, testes unitários que validem negação de acesso, e revise a lógica de permissões regularmente, especialmente em APIs e operações administrativas.

CVE-2026-49431LOWIncorrect user validation in ZFS_IOC_SET_PROP ioctlEPSS 0.1%CVE-2025-14305HIGHAcer|ListCheck.exe - Local Privilege EscalationEPSS 0.1%CVE-2025-30074HIGHAlludo Parallels Desktop before 19.4.2 and 20.x before 20.2.2 for macOS on Intel platforms allows privilege escalation to root via the VM crEPSS 0.1%CVE-2026-88848MEDIUMMasterStudy LMS 1.9 - < 3.7.50 - Subscriber+ Membership Plan Quota and Category Restriction BypassEPSS 0.1%CVE-2024-47157LOWSome Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause device service exceptiEPSS 0.1%CVE-2026-40224MEDIUMIn systemd 259 before 260, there is local privilege escalation in systemd-machined because varlink can be used to reach the root namespace.EPSS 0.1%CVE-2022-20558LOWIn registerReceivers of DeviceCapabilityListener.java, there is a possible way to change preferred TTY mode due to a permissions bypass. ThiEPSS 0.1%CVE-2026-78892HIGHIncorrect authorization in Chromoting in Google Chrome on on Windows prior to 152.0.7977.65 allowed a local attacker to bypass system accessEPSS 0.1%CVE-2025-49599MEDIUMHuawei EG8141A5 devices through V5R019C00S100, EG8145V5 devices through V5R019C00S100, and EG8145V5-V2 devices through V5R021C00S184 allow tEPSS 0.1%CVE-2026-62290HIGHcert-manager: Direct ACME Challenge resources can bypass Issuer DNS01 solver policy and use ClusterIssuer DNS credentialsEPSS 0.1%CVE-2025-54569MEDIUMIn Malwarebytes Binisoft Windows Firewall Control before 6.16.0.0, the installer is vulnerable to local privilege escalation.EPSS 0.1%CVE-2023-21035HIGHIn multiple functions of BackupHelper.java, there is a possible way for an app to get permissions previously granted to another app with theEPSS 0.1%CVE-2023-21256—In SettingsHomepageActivity.java, there is a possible way to launch arbitrary activities via Settings due to a logic error in the code. ThisEPSS 0.1%CVE-2023-21034HIGHIn multiple functions of SensorService.cpp, there is a possible access of accurate sensor data due to a permissions bypass. This could lead EPSS 0.1%CVE-2026-19816HIGHPackageKit: dnf5 backend ignores SIMULATE on RepoRemoveEPSS 0.1%CVE-2023-20971HIGHIn removePermission of PermissionManagerServiceImpl.java, there is a possible way to obtain dangerous permissions without user consent due tEPSS 0.1%CVE-2024-0017MEDIUMIn shouldUseNoOpLocation of CameraActivity.java, there is a possible confused deputy due to a permissions bypass. This could lead to local iEPSS 0.1%CVE-2026-91734HIGHIncorrect authorization in Core in Google Chrome on on Windows prior to 153.0.8010.47 allowed a local attacker to execute arbitrary code outEPSS 0.1%CVE-2023-40117HIGHIn resetSettingsLocked of SettingsProvider.java, there is a possible lockscreen bypass due to a permissions bypass. This could lead to localEPSS 0.1%CVE-2025-66433MEDIUMHTCondor Access Point before 25.3.1 allows an authenticated user to impersonate other users on the local machine by submitting a batch job. EPSS 0.1%