Falhas do tipo CWE-284

7.097 resultados

Controle de acesso inadequado a recursos

A aplicação falha em validar ou aplica incorretamente as restrições de acesso, permitindo que usuários não autorizados acessem dados ou funcionalidades que deveriam estar protegidas. É uma das fragilidades mais comuns em segurança: o código não verifica corretamente quem está pedindo acesso e simplesmente concede.

Exemplo

Um e-commerce que permite acessar o perfil de qualquer cliente substituindo o ID na URL (ex: /usuario/123 → /usuario/124), sem validar se o usuário autenticado é o dono daquele perfil. Um atacante consegue ver dados pessoais, histórico de compras e endereços de outras pessoas.

Como mitigar

Implemente verificações explícitas em cada acesso a recurso: autentique o usuário, identifique qual recurso ele quer acessar, e valide se as permissões dele cobrem aquele recurso específico. Use listas de controle de acesso (ACLs) ou papéis (RBAC/ABAC) consistentemente em toda a API ou aplicação, nunca deixando a segurança implícita.

CVE-2025-47794LOWNextcloud Server vulnerable to insecure temporary file creation, race with write access and permissionEPSS 0.5%CVE-2024-1476MEDIUMUnder Construction / Maintenance Mode from Acurax <= 2.6 - Information ExposureEPSS 0.5%CVE-2026-19244MEDIUMHKUDS nanobot MCP enabledTools Scope mcp.py connect_mcp_servers access controlEPSS 0.5%CVE-2023-24546HIGHOn affected versions of the CloudVision Portal improper access controls on the connection from devices to CloudVision could enable a malicioEPSS 0.5%CVE-2026-42222HIGHnginx-ui: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeoverEPSS 0.5%CVE-2024-42048MEDIUMOpenOrange Business Framework version 1.15.5 installs to a directory with overly permissive access control, allowing all authenticated usersEPSS 0.5%CVE-2018-10905HIGHCloudForms Management Engine (cfme) is vulnerable to an improper security setting in the dRuby component of CloudForms. An attacker with accEPSS 0.5%CVE-2022-47634HIGHM-Link Archive Server in Isode M-Link R16.2v1 through R17.0 before R17.0v24 allows non-administrative users to access and manipulate archiveEPSS 0.5%CVE-2026-1424MEDIUMPHPGurukul News Portal Profile Pic unrestricted uploadEPSS 0.5%CVE-2020-15279MEDIUMScanning exclusion paths disclosure in BEST for WindowsEPSS 0.5%CVE-2023-41570—MikroTik RouterOS v7.1 to 7.11 was discovered to contain incorrect access control mechanisms in place for the Rest API.EPSS 0.5%CVE-2026-70849MEDIUMVulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is EPSS 0.5%CVE-2026-72909HIGHERPNext: Broken Access Control on certain endpointsEPSS 0.5%CVE-2025-0341MEDIUMCampCodes Computer Laboratory Management System edit unrestricted uploadEPSS 0.5%CVE-2025-5130MEDIUMTmall Demo uploadProductImage unrestricted uploadEPSS 0.5%CVE-2026-34390MEDIUMMantisBT: Privilege Escalation from Manager to AdministratorEPSS 0.5%CVE-2022-44643MEDIUMAccess policy with access to all tenants and using label selectors has more accessEPSS 0.5%CVE-2026-28974HIGHThis issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS SequoiEPSS 0.5%CVE-2025-10847HIGHDX UIM Probe Improper ACL Handling RCEEPSS 0.5%CVE-2026-28876HIGHA parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in iOS 18.7.7 and iPadOSEPSS 0.5%