Fallos del tipo CWE-863

3002 resultados

Falha na verificação de autorização

O software implementa uma verificação de acesso, mas a lógica está incorreta ou incompleta, permitindo que um usuário acesse recursos ou execute ações que não deveria. O risco é grave porque a autenticação (você é quem diz ser) pode estar correta, mas a autorização (você tem direito a isto?) falha, abrindo brechas para escalação de privilégios ou acesso a dados sensíveis.

Ejemplo

Uma API verifica se o usuário está logado antes de retornar dados de perfil, mas não valida se ele é dono do perfil consultado. Um atacante consegue acessar dados de outros usuários apenas mudando um ID na requisição. Ou um sistema de permissões usa condições OR quando deveria usar AND, liberando acesso para mais atores que o pretendido.

Cómo mitigar

Implemente controle de acesso a cada operação sensível verificando explicitamente se o usuário autenticado tem permissão específica para aquele recurso (não assuma contexto). Use bibliotecas de autorização consolidadas, testes unitários que validem negação de acesso, e revise a lógica de permissões regularmente, especialmente em APIs e operações administrativas.

CVE-2026-68791HIGHAzure Machine Learning Information Disclosure VulnerabilityEPSS 0.6%CVE-2026-69118HIGHCachet 2.4.1 Authenticated Server-Side Template Injection RCEEPSS 0.6%CVE-2025-54265MEDIUMAdobe Commerce | Incorrect Authorization (CWE-863)EPSS 0.6%CVE-2026-28699HIGHGitea Basic Auth bypasses OAuth2 access token scopesEPSS 0.6%CVE-2024-31441HIGHArbitrary File Reading in DataEaseEPSS 0.6%CVE-2024-9693HIGHIncorrect Authorization in GitLabEPSS 0.6%CVE-2024-50650HIGHpython_book V1.0 is vulnerable to Incorrect Access Control, which allows attackers to obtain sensitive information of users with different IEPSS 0.5%CVE-2024-11672MEDIUMIncorrect authorization in the add permission component in Devolutions Remote Desktop Manager 2024.2.21 and earlier on Windows allows an autEPSS 0.5%CVE-2024-1738HIGHIncorrect Authorization in lunary-ai/lunaryEPSS 0.5%CVE-2023-25548HIGH A CWE-863: Incorrect Authorization vulnerability exists that could allow access to device credentials on specific DCE endpoints not being pEPSS 0.5%CVE-2026-73841HIGHOpenChoreo: Cross-project command execution and wirelog view access via OpenChoreo openchoreo-api exec and wirelogs endpointsEPSS 0.5%CVE-2025-30703LOWVulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.0-8.0.41, 8.4.0EPSS 0.5%CVE-2023-25415MEDIUMAten PE8108 2.4.232 is vulnerable to Incorrect Access Control. The device allows unauthenticated access to Event Notification configuration.EPSS 0.5%CVE-2025-24421MEDIUMAdobe Commerce | Incorrect Authorization (CWE-863)EPSS 0.5%CVE-2025-24436MEDIUMAdobe Commerce | Incorrect Authorization (CWE-863)EPSS 0.5%CVE-2026-16215MEDIUMgeex-arts django-jet OAuth Credential Revoke authorizationEPSS 0.5%CVE-2026-22595HIGHGhost has Staff Token permission bypassEPSS 0.5%CVE-2026-63512MEDIUMMicrosoft SharePoint Server Tampering VulnerabilityEPSS 0.5%CVE-2026-25040MEDIUMBudibase Vulnerable to Privilege Escalation via API Abuse – Creator Can Invite Users with Admin/Any RoleEPSS 0.5%CVE-2023-4997HIGHImproper authorisation in Uptime DCEPSS 0.5%