Fallos del tipo CWE-863

3104 resultados

Falha na verificação de autorização

O software implementa uma verificação de acesso, mas a lógica está incorreta ou incompleta, permitindo que um usuário acesse recursos ou execute ações que não deveria. O risco é grave porque a autenticação (você é quem diz ser) pode estar correta, mas a autorização (você tem direito a isto?) falha, abrindo brechas para escalação de privilégios ou acesso a dados sensíveis.

Ejemplo

Uma API verifica se o usuário está logado antes de retornar dados de perfil, mas não valida se ele é dono do perfil consultado. Um atacante consegue acessar dados de outros usuários apenas mudando um ID na requisição. Ou um sistema de permissões usa condições OR quando deveria usar AND, liberando acesso para mais atores que o pretendido.

Cómo mitigar

Implemente controle de acesso a cada operação sensível verificando explicitamente se o usuário autenticado tem permissão específica para aquele recurso (não assuma contexto). Use bibliotecas de autorização consolidadas, testes unitários que validem negação de acesso, e revise a lógica de permissões regularmente, especialmente em APIs e operações administrativas.

CVE-2023-21390HIGHIn Sim, there is a possible way to evade mobile preference restrictions due to a permission bypass. This could lead to local escalation of pEPSS 0.1%CVE-2023-20800—In imgsys, there is a possible system crash due to a mssing ptr check. This could lead to local escalation of privilege with System executioEPSS 0.1%CVE-2026-13067HIGHtlsCATrusts Role Restriction Not Enforced via PROXY Protocol v2 on Unix Domain SocketEPSS 0.1%CVE-2023-21254—In getCurrentState of OneTimePermissionUserManager.java, there is a possible way to hold one-time permissions after the app is being killed EPSS 0.1%CVE-2023-20975HIGHIn getAvailabilityStatus of EnableContentCapturePreferenceController.java, there is a possible way to bypass DISALLOW_CONTENT_CAPTURE due toEPSS 0.1%CVE-2023-21245HIGHIn showNextSecurityScreenOrFinish of KeyguardSecurityContainerController.java, there is a possible way to access the lock screen during deviEPSS 0.1%CVE-2025-48523HIGHIn onCreate of SelectAccountActivity.java, there is a possible way to add contacts without permission due to a logic error in the code. ThisEPSS 0.1%CVE-2023-21116MEDIUMIn verifyReplacingVersionCode of InstallPackageHelper.java, there is a possible way to downgrade system apps below system image version due EPSS 0.1%CVE-2025-32333HIGHIn startSpaActivityForApp of SpaActivity.kt, there is a possible cross-user permission bypass due to a logic error in the code. This could lEPSS 0.1%CVE-2025-26436HIGHIn clearAllowBgActivityStarts of PendingIntentRecord.java, there is a possible way for an application to launch an activity from the backgroEPSS 0.1%CVE-2026-28663HIGHIn buildIntentSenderForUser of LauncherAppsService.java, there is a possible way to launch an activity from the background due to BAL BypassEPSS 0.1%CVE-2026-28620HIGHIn multiple locations, there is a possible unauthorized URI access due to a permissions bypass. This could lead to local escalation of priviEPSS 0.1%CVE-2022-33718MEDIUMAn improper access control vulnerability in Wi-Fi Service prior to SMR AUG-2022 Release 1 allows untrusted applications to manipulate the liEPSS 0.1%CVE-2025-47382HIGHIncorrect Authorization in BootEPSS 0.1%CVE-2023-20950HIGHIn AlarmManagerActivity of AlarmManagerActivity.java, there is a possible way to bypass background activity launch restrictions via a pendinEPSS 0.1%CVE-2023-21117HIGHIn registerReceiverWithFeature of ActivityManagerService.java, there is a possible way for isolated processes to register a broadcast receivEPSS 0.1%CVE-2025-26442MEDIUMIn onCreate of NotificationAccessConfirmationActivity.java, there is a possible incorrect verification of proper intent filters in NLS due tEPSS 0.1%CVE-2025-22428HIGHIn hasInteractAcrossUsersFullPermission of AppInfoBase.java, there is a possible way to grant permissions to an app on the secondary user frEPSS 0.1%CVE-2018-9374HIGHIn installPackageLI of PackageManagerService.java, there is a possible permissions bypass. This could lead to local escalation of privilege EPSS 0.1%CVE-2024-44099MEDIUMThere is a possible Local bypass of user interaction due to an insecure default value. This could lead to local information disclosure with EPSS 0.1%