Falhas do tipo CWE-284

7.111 resultados

Controle de acesso inadequado a recursos

A aplicação falha em validar ou aplica incorretamente as restrições de acesso, permitindo que usuários não autorizados acessem dados ou funcionalidades que deveriam estar protegidas. É uma das fragilidades mais comuns em segurança: o código não verifica corretamente quem está pedindo acesso e simplesmente concede.

Exemplo

Um e-commerce que permite acessar o perfil de qualquer cliente substituindo o ID na URL (ex: /usuario/123 → /usuario/124), sem validar se o usuário autenticado é o dono daquele perfil. Um atacante consegue ver dados pessoais, histórico de compras e endereços de outras pessoas.

Como mitigar

Implemente verificações explícitas em cada acesso a recurso: autentique o usuário, identifique qual recurso ele quer acessar, e valide se as permissões dele cobrem aquele recurso específico. Use listas de controle de acesso (ACLs) ou papéis (RBAC/ABAC) consistentemente em toda a API ou aplicação, nunca deixando a segurança implícita.

CVE-2026-32138HIGHNEXULEAN API Key LeakEPSS 0.4%CVE-2024-21589HIGHParagon Active Assurance Control Center: Information disclosure vulnerabilityEPSS 0.4%CVE-2024-1288MEDIUMSchema & Structured Data for WP & AMP <= 1.26 - Missing Authorization to reCaptcha Key ModificationEPSS 0.4%CVE-2026-77008MEDIUMHEL Online Classroom: AI-powered Online Classrooms <= 1.0.3 - Unauthenticated Plugin Settings UpdateEPSS 0.4%CVE-2025-7898MEDIUMCodecanyon iDentSoft Account Setting Page updateSetting unrestricted uploadEPSS 0.4%CVE-2024-7154MEDIUMTOTOLINK A3700R Password Reset wizard.html access controlEPSS 0.4%CVE-2024-37315LOWNextcloud Server's read-only users can restore old versionsEPSS 0.4%CVE-2026-82629MEDIUMjeecgboot jeewx-boot doUpload Endpoint MyJwWebJwid3Controller.java MyJwWebJwid3Controller.doUpload unrestricted uploadEPSS 0.4%CVE-2024-43590HIGHVisual C++ Redistributable Installer Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2026-66916MEDIUMJoomla Extension - joomgalleryfriends.net - Password-Protected Category Bypass via JSON Format in JoomGallery < 4.4.0EPSS 0.4%CVE-2025-45615CRITICALIncorrect access control in the /admin/ API of yaoqishan v0.0.1-SNAPSHOT allows attackers to gain access to Admin rights via a crafted requeEPSS 0.4%CVE-2023-39221MEDIUMImproper access control for some Intel Unison software may allow an authenticated user to potentially enable escalation of privilege via netEPSS 0.4%CVE-2024-49049HIGHVisual Studio Code Remote Extension Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2024-42354MEDIUMShopware vulnerable to Improper Access Control with ManyToMany associations in store-apiEPSS 0.4%CVE-2022-24930MEDIUMAn Improper access control vulnerability in StRetailModeReceiver in Wear OS 3.0 prior to Firmware update MAR-2022 Release allows untrusted aEPSS 0.4%CVE-2025-45616CRITICALIncorrect access control in the /admin/** API of brcc v1.2.0 allows attackers to gain access to Admin rights via a crafted request.EPSS 0.4%CVE-2026-22043MEDIUMRustFS has IAM deny_only Short-Circuit that Allows Privilege Escalation via Service Account MintingEPSS 0.4%CVE-2026-64793CRITICALJoomla Extension - regularlabs.com - Content access and publication bypass in Articles Anywhere and Modules Anywhere extensionsEPSS 0.4%CVE-2025-30127CRITICALAn issue was discovered on Marbella KR8s Dashcam FF 2.0.8 devices. Once access is gained either by default, common, or cracked passwords, thEPSS 0.4%CVE-2026-56335HIGHCapgo - Channel Configuration Mutation via Write-Scoped API KeysEPSS 0.4%