Fallos del tipo CWE-863

3104 resultados

Falha na verificação de autorização

O software implementa uma verificação de acesso, mas a lógica está incorreta ou incompleta, permitindo que um usuário acesse recursos ou execute ações que não deveria. O risco é grave porque a autenticação (você é quem diz ser) pode estar correta, mas a autorização (você tem direito a isto?) falha, abrindo brechas para escalação de privilégios ou acesso a dados sensíveis.

Ejemplo

Uma API verifica se o usuário está logado antes de retornar dados de perfil, mas não valida se ele é dono do perfil consultado. Um atacante consegue acessar dados de outros usuários apenas mudando um ID na requisição. Ou um sistema de permissões usa condições OR quando deveria usar AND, liberando acesso para mais atores que o pretendido.

Cómo mitigar

Implemente controle de acesso a cada operação sensível verificando explicitamente se o usuário autenticado tem permissão específica para aquele recurso (não assuma contexto). Use bibliotecas de autorização consolidadas, testes unitários que validem negação de acesso, e revise a lógica de permissões regularmente, especialmente em APIs e operações administrativas.

CVE-2025-32348HIGHIn multiple locations, there is a possible background activity launch due to a missing permission check. This could lead to local escalationEPSS 0.1%CVE-2024-47025MEDIUMIn ppmp_protect_buf of drm_fw.c, there is a possible information disclosure due to a logic error in the code. This could lead to local inforEPSS 0.1%CVE-2026-102806MEDIUMOpenClaw before 2026.9.5 Sandbox Isolation Bypass via Media PipelinesEPSS —CVE-2026-103105HIGHPexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper access control on a product-internal API which allows an attacEPSS —CVE-2026-47571HIGHNVIDIA GPU Display Driver for Windows contains a vulnerability in kernel-mode escape handling where an attacker with local access could bypaEPSS —CVE-2026-95317LOWIncorrect authorization in MediaCapture in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to oEPSS —CVE-2026-71899—Apache DolphinScheduler: Missing Authorization in query-dynamic-sub-workflows API Leads to Information DisclosureEPSS —CVE-2026-95374—Incorrect authorization in Network in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass web origin policy via a craftEPSS —CVE-2026-95302LOWIncorrect authorization in WebAPKs in Google Chrome on on Android prior to 154.0.8037.57 allowed a local attacker to obtain cross-origin datEPSS —CVE-2026-103547CRITICALIn ldapd in OpenBSD 7.8 before errata 057 and 7.9 before errata 021, delegated BSD authentication results are correlated only by the LDAP chEPSS —CVE-2026-102330MEDIUMIncorrect authorization in SiteIsolation in Google Chrome prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer EPSS —CVE-2026-100273HIGHIn JetBrains YouTrack before 2026.2.19197 authorisation bypass in the scripts debugger allowed arbitrary code executionEPSS —CVE-2026-95289MEDIUMIncorrect authorization in Scroll in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to obtain EPSS —CVE-2026-100259MEDIUMIn JetBrains YouTrack before 2026.2.18991 improper access control on Gantt chart allowed edits by users with view-only accessEPSS —CVE-2026-95368MEDIUMIncorrect authorization in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to potenEPSS —CVE-2026-100278MEDIUMIn JetBrains YouTrack before 2026.2.19197 users with restricted permission could edit and hide other users' commentsEPSS —CVE-2026-100276MEDIUMIn JetBrains YouTrack before 2026.2.19197 guest users could remove a workflow action's visibility restriction and run the actionEPSS —CVE-2026-95314—Incorrect authorization in HID in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process toEPSS —CVE-2026-95375MEDIUMIncorrect authorization in BrowserTag in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer proEPSS —CVE-2026-78214MEDIUMApache DolphinScheduler: Actuator Endpoint Authentication Bypass via Percent-Encoded PathsEPSS —