Falhas do tipo CWE-284

7.123 resultados

Controle de acesso inadequado a recursos

A aplicação falha em validar ou aplica incorretamente as restrições de acesso, permitindo que usuários não autorizados acessem dados ou funcionalidades que deveriam estar protegidas. É uma das fragilidades mais comuns em segurança: o código não verifica corretamente quem está pedindo acesso e simplesmente concede.

Exemplo

Um e-commerce que permite acessar o perfil de qualquer cliente substituindo o ID na URL (ex: /usuario/123 → /usuario/124), sem validar se o usuário autenticado é o dono daquele perfil. Um atacante consegue ver dados pessoais, histórico de compras e endereços de outras pessoas.

Como mitigar

Implemente verificações explícitas em cada acesso a recurso: autentique o usuário, identifique qual recurso ele quer acessar, e valide se as permissões dele cobrem aquele recurso específico. Use listas de controle de acesso (ACLs) ou papéis (RBAC/ABAC) consistentemente em toda a API ou aplicação, nunca deixando a segurança implícita.

CVE-2025-45424MEDIUMIncorrect access control in Xinference before v1.4.0 allows attackers to access the Web GUI without authentication.EPSS 0.4%CVE-2025-45609HIGHIncorrect access control in the doFilter function of kob latest v1.0.0-SNAPSHOT allows attackers to access sensitive information via a craftEPSS 0.4%CVE-2026-90507MEDIUMvvbbnn00 WARP-Clash-API Subscription subscription.py get_surge_subscription access controlEPSS 0.4%CVE-2025-45613HIGHIncorrect access control in the component /user/list of Shiro-Action v0.6 allows attackers to access sensitive information via a crafted payEPSS 0.4%CVE-2022-32872LOWA logic issue was addressed with improved restrictions. This issue is fixed in iOS 16, iOS 15.7 and iPadOS 15.7. A person with physical acceEPSS 0.4%CVE-2026-83314HIGHVulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Service API). Supported versions that are affected areEPSS 0.4%CVE-2026-7696MEDIUMAcrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform uploadH5Files unrestricted uploadEPSS 0.4%CVE-2026-4586MEDIUMCodePhiliaX Chat2DB JDBC Driver Upload JdbcDriverController.java upload unrestricted uploadEPSS 0.4%CVE-2025-45614HIGHIncorrect access control in the component /api/user/manager of One v1.0 allows attackers to access sensitive information via a crafted payloEPSS 0.4%CVE-2026-16948HIGHSolace Extra < 1.6.1 - Subscriber+ Multiple Missing Authorization via Site-Wide Nonce ExposureEPSS 0.4%CVE-2025-45617HIGHIncorrect access control in the component /user/list of production_ssm v0.0.1-SNAPSHOT allows attackers to access sensitive information via EPSS 0.4%CVE-2026-28410MEDIUMThe Graph: Revocable vesting contracts allows early access to locked tokensEPSS 0.4%CVE-2025-47993HIGHMicrosoft PC Manager Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2026-28863MEDIUMA permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.4 and iPadOS 26.4, tvOS 26.4, visionOS 26.4, wEPSS 0.4%CVE-2026-60905CRITICALVulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are EPSS 0.4%CVE-2025-10608MEDIUMPortabilis i-Educar enrollment-history access controlEPSS 0.4%CVE-2026-21889LOWWeblate leaks information via screenshotsEPSS 0.4%CVE-2026-72596HIGHGhost Foundation Ghost - Broken Access ControlEPSS 0.4%CVE-2024-48010MEDIUMDell PowerProtect DD, versions prior to 8.1.0.0, 7.13.1.10, 7.10.1.40, and 7.7.5.50, contains an access control vulnerability. A remote highEPSS 0.4%CVE-2025-9406MEDIUMxuhuisheng lemon CmsArticleController.java uploadImage unrestricted uploadEPSS 0.4%