Falhas do tipo CWE-284

7.125 resultados

Controle de acesso inadequado a recursos

A aplicação falha em validar ou aplica incorretamente as restrições de acesso, permitindo que usuários não autorizados acessem dados ou funcionalidades que deveriam estar protegidas. É uma das fragilidades mais comuns em segurança: o código não verifica corretamente quem está pedindo acesso e simplesmente concede.

Exemplo

Um e-commerce que permite acessar o perfil de qualquer cliente substituindo o ID na URL (ex: /usuario/123 → /usuario/124), sem validar se o usuário autenticado é o dono daquele perfil. Um atacante consegue ver dados pessoais, histórico de compras e endereços de outras pessoas.

Como mitigar

Implemente verificações explícitas em cada acesso a recurso: autentique o usuário, identifique qual recurso ele quer acessar, e valide se as permissões dele cobrem aquele recurso específico. Use listas de controle de acesso (ACLs) ou papéis (RBAC/ABAC) consistentemente em toda a API ou aplicação, nunca deixando a segurança implícita.

CVE-2026-0547MEDIUMPHPGurukul Online Course Registration Student Registration edit-student-profile.php unrestricted uploadEPSS 0.4%CVE-2024-10937MEDIUMRelated Posts, Inline Related Posts, Contextual Related Posts, Related Content By PickPlugins <= 2.0.58 - Sensitive Information ExposureEPSS 0.4%CVE-2025-14199MEDIUMVerysync 微力同步 Web Administration text.txt unrestricted uploadEPSS 0.4%CVE-2020-12024—Baxter ExactaMix EM 2400 versions 1.10, 1.11, 1.13, 1.14 and ExactaMix EM1200 Versions 1.1, 1.2, 1.4 and 1.5 does not restrict access to theEPSS 0.4%CVE-2023-39731—The leakage of the client secret in Kaibutsunosato v13.6.1 allows attackers to obtain the channel access token and send crafted broadcast meEPSS 0.4%CVE-2026-0577MEDIUMcode-projects Online Product Reservation System prod.php unrestricted uploadEPSS 0.4%CVE-2026-55548MEDIUMYamcs: Insecure Direct Object Reference (IDOR) in PacketsApi allows unprivileged users to dump all telemetry packetsEPSS 0.4%CVE-2024-1942MEDIUMMattermost versions 8.1.x before 8.1.9, 9.2.x before 9.2.5, and 9.3.0 fail to sanitize the metadata on posts containing permalinks under speEPSS 0.4%CVE-2025-20153MEDIUMCisco ESA mail BypassEPSS 0.4%CVE-2025-60784MEDIUMA vulnerability in the XiaozhangBang Voluntary Like System V8.8 allows remote attackers to manipulate the zhekou parameter in the /topfirst.EPSS 0.4%CVE-2026-67975HIGHIncorrect access control in NASA cFS v7.0.1 allows attackers to arbitrarily remove low-index subscriptions and add new streams via sending TEPSS 0.4%CVE-2023-33155HIGHWindows Cloud Files Mini Filter Driver Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2024-28805CRITICALAn issue was discovered in Italtel i-MCS NFV 12.1.0-20211215. There is Incorrect Access Control.EPSS 0.4%CVE-2025-10371MEDIUMeCharge Hardy Barth Salia PLCC api.php unrestricted uploadEPSS 0.4%CVE-2023-47858MEDIUMDetails of archived public channels are leaked to members of another teamEPSS 0.4%CVE-2025-57247CRITICALThe BATBToken smart contract (address 0xfbf1388408670c02f0dbbb74251d8ded1d63b7a2, Compiler Version v0.8.26+commit.8a97fa7a) contains incorreEPSS 0.4%CVE-2026-2851MEDIUMyeqifu warehouse Inport Endpoint InportController.java deleteInport access controlEPSS 0.4%CVE-2023-52537HIGHVulnerability of package name verification being bypassed in the HwIms module. Impact: Successful exploitation of this vulnerability will afEPSS 0.4%CVE-2024-51988MEDIUMHTTP API's queue deletion endpoint does not verify that the user has a required permissionEPSS 0.4%CVE-2025-29421HIGHPerfreeBlog v4.0.11 has an arbitrary file read vulnerability in the getThemeFileContent function.EPSS 0.4%