Fallos del tipo CWE-863

3003 resultados

Falha na verificação de autorização

O software implementa uma verificação de acesso, mas a lógica está incorreta ou incompleta, permitindo que um usuário acesse recursos ou execute ações que não deveria. O risco é grave porque a autenticação (você é quem diz ser) pode estar correta, mas a autorização (você tem direito a isto?) falha, abrindo brechas para escalação de privilégios ou acesso a dados sensíveis.

Ejemplo

Uma API verifica se o usuário está logado antes de retornar dados de perfil, mas não valida se ele é dono do perfil consultado. Um atacante consegue acessar dados de outros usuários apenas mudando um ID na requisição. Ou um sistema de permissões usa condições OR quando deveria usar AND, liberando acesso para mais atores que o pretendido.

Cómo mitigar

Implemente controle de acesso a cada operação sensível verificando explicitamente se o usuário autenticado tem permissão específica para aquele recurso (não assuma contexto). Use bibliotecas de autorização consolidadas, testes unitários que validem negação de acesso, e revise a lógica de permissões regularmente, especialmente em APIs e operações administrativas.

CVE-2026-6922HIGHWP Table Builder <= 2.2.1 - Incorrect Authorization to Authenticated (Subscriber+) Arbitrary Post Deletion via 'ids' ParameterEPSS 0.6%CVE-2026-32642LOWApache Artemis, Apache ActiveMQ Artemis: Temporary address auto-created for OpenWire consumer without createAddress permissionEPSS 0.6%CVE-2024-32470MEDIUMTolgee' API keys created by server admin users bypass the permission checkEPSS 0.6%CVE-2024-53941HIGHAn issue was discovered in Victure RX1800 WiFi 6 Router (software EN_V1.0.0_r12_110933, hardware 1.0) devices. A remote attacker (in proximiEPSS 0.6%CVE-2022-43940HIGHHitachi Vantara Pentaho Business Analytics Server - Incorrect AuthorizationEPSS 0.6%CVE-2024-35353CRITICALA vulnerability has been discovered in Diño Physics School Assistant version 2.3. The vulnerability impacts an unidentified code within the EPSS 0.6%CVE-2023-2759HIGHTAPHOME Improper Authentication in Core PlatformEPSS 0.6%CVE-2023-26056MEDIUMXWiki Platform allows macro execution as any user without programming rights through the context macroEPSS 0.6%CVE-2025-68476HIGHKEDA has Arbitrary File Read via Insufficient Path Validation in HashiCorp Vault Service Account CredentialEPSS 0.6%CVE-2026-90460HIGHAn issue was discovered in OpenStack Keystone before 29.0.3. Tokens obtained via delegated authentication methods (EC2 credentials, applicatEPSS 0.6%CVE-2025-5187MEDIUMNodes can delete themselves by adding an OwnerReferenceEPSS 0.6%CVE-2025-62506HIGHMinIO vulnerable to privilege escalation via session policy bypass in service accounts and STSEPSS 0.6%CVE-2024-3033CRITICALImproper Authorization in mintplex-labs/anything-llmEPSS 0.6%CVE-2024-9693HIGHIncorrect Authorization in GitLabEPSS 0.6%CVE-2025-54265MEDIUMAdobe Commerce | Incorrect Authorization (CWE-863)EPSS 0.6%CVE-2026-28699HIGHGitea Basic Auth bypasses OAuth2 access token scopesEPSS 0.6%CVE-2026-82463HIGHpac4j-core before 6.5.6 Authorization Bypass via Reversed Profile Type CheckEPSS 0.6%CVE-2024-31441HIGHArbitrary File Reading in DataEaseEPSS 0.6%CVE-2024-1738HIGHIncorrect Authorization in lunary-ai/lunaryEPSS 0.5%CVE-2024-50650HIGHpython_book V1.0 is vulnerable to Incorrect Access Control, which allows attackers to obtain sensitive information of users with different IEPSS 0.5%