Fallos del tipo CWE-863

2989 resultados

Falha na verificação de autorização

O software implementa uma verificação de acesso, mas a lógica está incorreta ou incompleta, permitindo que um usuário acesse recursos ou execute ações que não deveria. O risco é grave porque a autenticação (você é quem diz ser) pode estar correta, mas a autorização (você tem direito a isto?) falha, abrindo brechas para escalação de privilégios ou acesso a dados sensíveis.

Ejemplo

Uma API verifica se o usuário está logado antes de retornar dados de perfil, mas não valida se ele é dono do perfil consultado. Um atacante consegue acessar dados de outros usuários apenas mudando um ID na requisição. Ou um sistema de permissões usa condições OR quando deveria usar AND, liberando acesso para mais atores que o pretendido.

Cómo mitigar

Implemente controle de acesso a cada operação sensível verificando explicitamente se o usuário autenticado tem permissão específica para aquele recurso (não assuma contexto). Use bibliotecas de autorização consolidadas, testes unitários que validem negação de acesso, e revise a lógica de permissões regularmente, especialmente em APIs e operações administrativas.

CVE-2021-24905Advanced Contact form 7 DB < 1.8.7 - Subscriber+ Arbitrary File DeletionEPSS 0.8%CVE-2021-21286HIGHAuthorization Bypass in AVideo PlatformEPSS 0.8%CVE-2023-27578CRITICALGalaxy vulnerable to unauthorized modification of pages/visualizations due to insufficient permission checkEPSS 0.8%CVE-2024-29892MEDIUMZITADEL's actions can overload reserved claimsEPSS 0.8%CVE-2022-21701MEDIUMPrivileged Escalation in IstioEPSS 0.8%CVE-2025-20674CRITICALIn wlan AP driver, there is a possible way to inject arbitrary packet due to a missing permission check. This could lead to remote escalatioEPSS 0.8%CVE-2024-37905HIGHImproper Access Control and Incorrect Authorization in github.com/goauthentik/authentikEPSS 0.8%CVE-2021-36778HIGHExposure of repository credentials to external third-party sourcesEPSS 0.8%CVE-2020-28397A vulnerability has been identified in SIMATIC Drive Controller family (All versions < V2.9.2), SIMATIC ET 200SP Open Controller CPU 1515SP EPSS 0.8%CVE-2021-39119MEDIUMAffected versions of Atlassian Jira Server and Data Center allow users who have watched an issue to continue receiving updates on the issue EPSS 0.8%CVE-2024-8001MEDIUMVIWIS LMS Print authorizationEPSS 0.8%CVE-2023-38218HIGHIncorrect Authorization - Customer account takeoverEPSS 0.8%CVE-2025-49586HIGHXWiki allows remote code execution through preview of XClass changes in AWM editorEPSS 0.7%CVE-2020-25167MEDIUMOSIsoft PI Vision Incorrect AuthorizationEPSS 0.7%CVE-2024-36265CRITICALApache Submarine Server Core: authorization bypassEPSS 0.7%CVE-2016-9575Ipa versions 4.2.x, 4.3.x before 4.3.3 and 4.4.x before 4.4.3 did not properly check the user's permissions while modifying certificate profEPSS 0.7%CVE-2024-22208MEDIUMphpMyFAQ sharing FAQ functionality can easily be abused for phishing purposesEPSS 0.7%CVE-2024-35187CRITICALStalwart Mail Server has privilege escalation by designEPSS 0.7%CVE-2026-47303HIGHASP.NET Core Elevation of Privilege VulnerabilityEPSS 0.7%CVE-2025-21555MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.40 and prior, 8EPSS 0.7%