Falhas do tipo CWE-284

7.073 resultados

Controle de acesso inadequado a recursos

A aplicação falha em validar ou aplica incorretamente as restrições de acesso, permitindo que usuários não autorizados acessem dados ou funcionalidades que deveriam estar protegidas. É uma das fragilidades mais comuns em segurança: o código não verifica corretamente quem está pedindo acesso e simplesmente concede.

Exemplo

Um e-commerce que permite acessar o perfil de qualquer cliente substituindo o ID na URL (ex: /usuario/123 → /usuario/124), sem validar se o usuário autenticado é o dono daquele perfil. Um atacante consegue ver dados pessoais, histórico de compras e endereços de outras pessoas.

Como mitigar

Implemente verificações explícitas em cada acesso a recurso: autentique o usuário, identifique qual recurso ele quer acessar, e valide se as permissões dele cobrem aquele recurso específico. Use listas de controle de acesso (ACLs) ou papéis (RBAC/ABAC) consistentemente em toda a API ou aplicação, nunca deixando a segurança implícita.

CVE-2023-4546LOWByzoro Smart S85F Management Platform licence.php access controlEPSS 1.3%CVE-2023-24320CRITICALAn access control issue in Axcora POS #0~gitf77ec09 allows unauthenticated attackers to execute arbitrary commands via unspecified vectors.EPSS 1.3%CVE-2026-24300CRITICALAzure Front Door Elevation of Privilege VulnerabilityEPSS 1.3%CVE-2022-35689MEDIUMAdobe Commerce Improper Access Control Security feature bypassEPSS 1.3%CVE-2022-3065MEDIUMImproper Access Control in jgraph/drawioEPSS 1.3%CVE-2025-29804HIGHVisual Studio Elevation of Privilege VulnerabilityEPSS 1.3%CVE-2026-44249HIGHNetty has an IPv6 Subnet Filter Bypass via Incorrect Comparator MaskingEPSS 1.3%CVE-2018-0436—Cisco Webex Teams Information Disclosure and Modification VulnerabilityEPSS 1.3%CVE-2020-10641—An unprotected logging route may allow an attacker to write endless log statements into the database without space limits or authentication.EPSS 1.3%CVE-2021-1243MEDIUMCisco IOS XR Software SNMP Management Plane Protection ACL Bypass VulnerabilityEPSS 1.3%CVE-2018-11456—A vulnerability has been identified in Automation License Manager 5 (All versions < 5.3.4.4). An attacker with network access to the device EPSS 1.3%CVE-2022-20859MEDIUMCisco Unified Communications Products Access Control VulnerabilityEPSS 1.3%CVE-2023-46501CRITICALAn issue in BoltWire v.6.03 allows a remote attacker to obtain sensitive information via a crafted payload to the view and change admin passEPSS 1.3%CVE-2020-14504MEDIUMThe web interface of the 1734-AENTR communication module mishandles authentication for HTTP POST requests. A remote, unauthenticated attackeEPSS 1.3%CVE-2021-32517HIGHQSAN Storage Manager - Improper Access ControlEPSS 1.3%CVE-2016-9368—An issue was discovered in Eaton xComfort Ethernet Communication Interface (ECI) Versions 1.07 and prior. By accessing a specific uniform reEPSS 1.3%CVE-2026-4201MEDIUMglowxq glowxq-oj SysFileController.java upload unrestricted uploadEPSS 1.3%CVE-2025-63353CRITICALA vulnerability in FiberHome GPON ONU HG6145F1 RP4423 allows the device's factory default Wi-Fi password (WPA/WPA2 pre-shared key) to be preEPSS 1.3%CVE-2018-10612—In 3S-Smart Software Solutions GmbH CODESYS Control V3 products prior to version 3.5.14.0, user access management and communication encryptiEPSS 1.3%CVE-2024-3765CRITICALXiongmai AHB7804R-MH-V2 Sofia Service access controlEPSS 1.3%