Falhas do tipo CWE-284

7.103 resultados

Controle de acesso inadequado a recursos

A aplicação falha em validar ou aplica incorretamente as restrições de acesso, permitindo que usuários não autorizados acessem dados ou funcionalidades que deveriam estar protegidas. É uma das fragilidades mais comuns em segurança: o código não verifica corretamente quem está pedindo acesso e simplesmente concede.

Exemplo

Um e-commerce que permite acessar o perfil de qualquer cliente substituindo o ID na URL (ex: /usuario/123 → /usuario/124), sem validar se o usuário autenticado é o dono daquele perfil. Um atacante consegue ver dados pessoais, histórico de compras e endereços de outras pessoas.

Como mitigar

Implemente verificações explícitas em cada acesso a recurso: autentique o usuário, identifique qual recurso ele quer acessar, e valide se as permissões dele cobrem aquele recurso específico. Use listas de controle de acesso (ACLs) ou papéis (RBAC/ABAC) consistentemente em toda a API ou aplicação, nunca deixando a segurança implícita.

CVE-2025-7538MEDIUMCampcodes Sales and Inventory System product_update.php unrestricted uploadEPSS 0.4%CVE-2025-7470MEDIUMCampcodes Sales and Inventory System product_add.php unrestricted uploadEPSS 0.4%CVE-2025-55373MEDIUMIncorrect access control in Beakon Application before v5.4.3 allows authenticated attackers with low-level privileges to escalate privilegesEPSS 0.4%CVE-2022-23994LOWAn Improper access control vulnerability in StBedtimeModeReceiver in Wear OS 3.0 prior to Firmware update Feb-2022 Release allows untrusted EPSS 0.4%CVE-2026-48034HIGHHULUMI-H5 bypass via decoy sibling resources targeting a different bucketEPSS 0.4%CVE-2025-6422MEDIUMCampcodes Online Recruitment Management System About Content Page ajax.php unrestricted uploadEPSS 0.4%CVE-2026-95624MEDIUMTauri framework v2 malicious downgrade via allow_downgrades from frontend codeEPSS 0.4%CVE-2024-1678MEDIUMSubway – Private Site Option <= 2.1.4 - Improper Access Control to Sensitive Information Exposure via REST APIEPSS 0.4%CVE-2026-43713MEDIUMA permissions issue was addressed with additional restrictions. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS TaEPSS 0.4%CVE-2025-45422HIGHIncorrect access control in Proximus b-box v8c.725A allows authenticated attackers to bypass normal restrictions and make arbitrary changes EPSS 0.4%CVE-2026-21994CRITICALVulnerability in the Oracle Edge Cloud Infrastructure Designer and Visualisation Toolkit product of Oracle Open Source Projects (component: EPSS 0.4%CVE-2024-41251MEDIUMAn Incorrect Access Control vulnerability was found in /smsa/admin_teacher_register_approval.php and /smsa/admin_teacher_register_approval_sEPSS 0.4%CVE-2026-47164HIGHVaultwarden: SSO Email Auto-Link Can Bind an Existing Local Account to an Attacker-Controlled IdP IdentityEPSS 0.4%CVE-2025-41737HIGHImproper access control via php endpointEPSS 0.4%CVE-2025-49707HIGHAzure Virtual Machines Spoofing VulnerabilityEPSS 0.4%CVE-2026-28862MEDIUMA privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia 15.7.5, macOS SonomEPSS 0.4%CVE-2025-9153MEDIUMitsourcecode Online Tour and Travel Management System travellers.php unrestricted uploadEPSS 0.4%CVE-2026-71102CRITICALVulnerability in the Portable Clusterware component of Oracle Database Server. Supported versions that are affected are 19.3-19.32, 21.3-21EPSS 0.4%CVE-2025-52101CRITICALlinjiashop <=0.9 is vulnerable to Incorrect Access Control. When using the default-generated JWT authentication, attackers can bypass the auEPSS 0.4%CVE-2026-62638CRITICALVulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported EPSS 0.4%