Falhas do tipo CWE-284

7.123 resultados

Controle de acesso inadequado a recursos

A aplicação falha em validar ou aplica incorretamente as restrições de acesso, permitindo que usuários não autorizados acessem dados ou funcionalidades que deveriam estar protegidas. É uma das fragilidades mais comuns em segurança: o código não verifica corretamente quem está pedindo acesso e simplesmente concede.

Exemplo

Um e-commerce que permite acessar o perfil de qualquer cliente substituindo o ID na URL (ex: /usuario/123 → /usuario/124), sem validar se o usuário autenticado é o dono daquele perfil. Um atacante consegue ver dados pessoais, histórico de compras e endereços de outras pessoas.

Como mitigar

Implemente verificações explícitas em cada acesso a recurso: autentique o usuário, identifique qual recurso ele quer acessar, e valide se as permissões dele cobrem aquele recurso específico. Use listas de controle de acesso (ACLs) ou papéis (RBAC/ABAC) consistentemente em toda a API ou aplicação, nunca deixando a segurança implícita.

CVE-2025-25950HIGHIncorrect access control in the component /rest/staffResource/update of Serosoft Solutions Pvt Ltd Academia Student Information System (SIS)EPSS 0.4%CVE-2026-83449HIGHVulnerability in the Oracle Bills of Material product of Oracle E-Business Suite (component: Internal Operations). Supported versions that EPSS 0.4%CVE-2025-64110HIGHCursor: Authentication Bypass Possible via New Cursorignore WriteEPSS 0.4%CVE-2026-45284MEDIUMNextcloud: Wrong condition in the User OIDC app's LdapService allowed deleted LDAP users to authenticateEPSS 0.4%CVE-2026-62246HIGHKamaji: TenantControlPlane namespace/name collision binds two tenants to the same SQL datastore schema + DB user, breaking per-tenant isolationEPSS 0.4%CVE-2025-12297MEDIUMatjiu pybbs UserApiController.java information disclosureEPSS 0.4%CVE-2026-25877MEDIUMChartbrew: Insecure Direct Object Reference (IDOR) in Chart OperationsEPSS 0.4%CVE-2026-101143MEDIUMEleveo Quality Management QMBODownload information disclosureEPSS 0.4%CVE-2026-73626HIGHJupyterLab before 4.6.2 Authentication Bypass via PyPIExtensionManagerEPSS 0.4%CVE-2024-0453MEDIUMAI ChatBot <= 5.3.4 - Missing Authorization via openai_file_delete_callbackEPSS 0.4%CVE-2022-29160LOWSensitive files/data exist after deletion of user account in Nextcloud AndroidEPSS 0.4%CVE-2024-45323MEDIUMAn improper access control vulnerability [CWE-284] in FortiEDR Manager API 6.2.0 through 6.2.2, 6.0 all versions may allow in a shared envirEPSS 0.4%CVE-2024-0452MEDIUMAI ChatBot <= 5.3.4 - Missing Authorization via openai_file_upload_callbackEPSS 0.4%CVE-2024-7429MEDIUMZotpress <= 7.3.12 - Missing AuthorizationEPSS 0.4%CVE-2024-39777HIGHMalicious remote can invite itself to an arbitrary local channelEPSS 0.4%CVE-2026-70701HIGHVulnerability in the Oracle Payables product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affecEPSS 0.4%CVE-2026-60771HIGHVulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Internal Operations). SEPSS 0.4%CVE-2026-62445HIGHVulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Tools). Supported versions tEPSS 0.4%CVE-2026-70881HIGHVulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supportEPSS 0.4%CVE-2026-60710HIGHVulnerability in the Oracle EDI Gateway product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are afEPSS 0.4%