Fallos del tipo CWE-863

3050 resultados

Falha na verificação de autorização

O software implementa uma verificação de acesso, mas a lógica está incorreta ou incompleta, permitindo que um usuário acesse recursos ou execute ações que não deveria. O risco é grave porque a autenticação (você é quem diz ser) pode estar correta, mas a autorização (você tem direito a isto?) falha, abrindo brechas para escalação de privilégios ou acesso a dados sensíveis.

Ejemplo

Uma API verifica se o usuário está logado antes de retornar dados de perfil, mas não valida se ele é dono do perfil consultado. Um atacante consegue acessar dados de outros usuários apenas mudando um ID na requisição. Ou um sistema de permissões usa condições OR quando deveria usar AND, liberando acesso para mais atores que o pretendido.

Cómo mitigar

Implemente controle de acesso a cada operação sensível verificando explicitamente se o usuário autenticado tem permissão específica para aquele recurso (não assuma contexto). Use bibliotecas de autorização consolidadas, testes unitários que validem negação de acesso, e revise a lógica de permissões regularmente, especialmente em APIs e operações administrativas.

CVE-2025-53943HIGHVoidBot Open-Source Has Improper Permission Check That Allows Unauthorized Command ExecutionEPSS 0.3%CVE-2024-25149MEDIUMLiferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 15, and oEPSS 0.3%CVE-2026-15388MEDIUMCookie Consent < 0.0.10 - Subscriber+ Consent Settings Update and Consent Log DisclosureEPSS 0.3%CVE-2026-48076MEDIUMOpenReception's bootstrap booking flow allows unauthenticated booking on isPublic=false channelsEPSS 0.3%CVE-2025-48881HIGHValtimo backend libraries allows objects in the object-api to be accessed and modified by unauthorized usersEPSS 0.3%CVE-2026-47238MEDIUMClipBucket: IDOR in videos subtitle editorEPSS 0.3%CVE-2026-21722MEDIUMPublic Dashboards time range restriction on annotations can be bypassedEPSS 0.3%CVE-2026-40213HIGHOpenStack Cyborg before 16.0.1 uses rule:allow (check_str='@') as the default policy for multiple API endpoints. This unconditionally authorEPSS 0.3%CVE-2024-5539CRITICALALC WebCTRL Carrier i-Vu Access Control BypassEPSS 0.3%CVE-2023-5553HIGHDuring internal Axis Security Development Model (ASDM) threat-modelling, a flaw was found in the protection for device tampering (commonly kEPSS 0.3%CVE-2026-5374MEDIUMrunZero Platform MCP information leakEPSS 0.3%CVE-2025-4972LOWIncorrect Authorization in GitLabEPSS 0.3%CVE-2026-5384MEDIUMrunZero Platform incorrect credential scopeEPSS 0.3%CVE-2026-55472MEDIUMSnipe-IT: API Location Creation Bypasses FMCS Parent-Child Company Boundary ValidationEPSS 0.3%CVE-2026-77786MEDIUMRank Math SEO < 1.0.277 - Editor+ Core Settings Modification via fix-site-seo AbilityEPSS 0.3%CVE-2026-63309MEDIUMSurrealDB < 3.1.5 Information Disclosure via ORDER BYEPSS 0.3%CVE-2026-89267MEDIUMstarlette-admin 0.16.1 through 0.17.1 Searchable Fields Allowlist BypassEPSS 0.3%CVE-2021-3469—Foreman versions before 2.3.4 and before 2.4.0 is affected by an improper authorization handling flaw. An authenticated attacker can impersoEPSS 0.3%CVE-2025-59683HIGHPexip Infinity 15.0 through 38.0 before 38.1 has Improper Access Control in the Secure Scheduler for Exchange service, when used with OfficeEPSS 0.3%CVE-2026-46635MEDIUMTwig: Sandbox property allowlist bypass via the `column` filter (array_column on objects)EPSS 0.3%