Falhas do tipo CWE-284

7.126 resultados

Controle de acesso inadequado a recursos

A aplicação falha em validar ou aplica incorretamente as restrições de acesso, permitindo que usuários não autorizados acessem dados ou funcionalidades que deveriam estar protegidas. É uma das fragilidades mais comuns em segurança: o código não verifica corretamente quem está pedindo acesso e simplesmente concede.

Exemplo

Um e-commerce que permite acessar o perfil de qualquer cliente substituindo o ID na URL (ex: /usuario/123 → /usuario/124), sem validar se o usuário autenticado é o dono daquele perfil. Um atacante consegue ver dados pessoais, histórico de compras e endereços de outras pessoas.

Como mitigar

Implemente verificações explícitas em cada acesso a recurso: autentique o usuário, identifique qual recurso ele quer acessar, e valide se as permissões dele cobrem aquele recurso específico. Use listas de controle de acesso (ACLs) ou papéis (RBAC/ABAC) consistentemente em toda a API ou aplicação, nunca deixando a segurança implícita.

CVE-2025-30132CRITICALAn issue was discovered on IROAD Dashcam V devices. It uses an unregistered public domain name as an internal domain, creating a security riEPSS 0.4%CVE-2025-10615MEDIUMitsourcecode E-Commerce Website products.php unrestricted uploadEPSS 0.4%CVE-2025-13185MEDIUMBdtask/CodeCanyon News365 profile unrestricted uploadEPSS 0.4%CVE-2020-8157—UniFi Cloud Key firmware <= v1.1.10 for Cloud Key gen2 and Cloud Key gen2 Plus contains a vulnerability that allows unrestricted root accessEPSS 0.4%CVE-2026-55112HIGHA malicious actor with access to the network and low privileges and under certain conditions could exploit an Improper Access Control vulnerEPSS 0.4%CVE-2026-21959MEDIUMVulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Loader). Supported versions that are affected EPSS 0.4%CVE-2026-60325HIGHVulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that EPSS 0.4%CVE-2025-55196HIGHExternal Secrets Operator Missing Namespace Restriction in PushSecret and SecretStore List() Calls Allows Unauthorized Secret AccessEPSS 0.4%CVE-2026-16454MEDIUMPrivilege Escalation in Eclipse hawkBit DDI allows Tenant-Isolated Firmware ExfiltrationEPSS 0.4%CVE-2026-0881CRITICALSandbox escape in the Messaging System componentEPSS 0.4%CVE-2026-60667HIGHVulnerability in the PeopleSoft Enterprise HCM Human Resources product of Oracle PeopleSoft (component: Core). The supported version that EPSS 0.4%CVE-2025-14083LOWKeycloak-server: keycloak: improper access control in admin rest api leads to information disclosureEPSS 0.4%CVE-2025-63686MEDIUMThere is an arbitrary file download vulnerability in GuoMinJim PersonManage thru commit 5a02b1ab208feacf3a34fc123c9381162afbaa95 (2020-11-23EPSS 0.4%CVE-2026-60860HIGHVulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that EPSS 0.4%CVE-2024-41703MEDIUMLibreChat through 0.7.4-rc1 has incorrect access control for message updates.EPSS 0.4%CVE-2025-8344MEDIUMopenviglet shio ShStaticFileAPI.java shStaticFileUpload unrestricted uploadEPSS 0.4%CVE-2025-13411MEDIUMCampcodes Retro Basketball Shoes Online Store admin_football.php unrestricted uploadEPSS 0.4%CVE-2025-8171MEDIUMcode-projects Document Management System insert.php unrestricted uploadEPSS 0.4%CVE-2026-28965HIGHA privacy issue was addressed with improved checks. This issue is fixed in iOS 26.5 and iPadOS 26.5. A user may be able to view restricted cEPSS 0.4%CVE-2026-28930HIGHA permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.5. An app may be able to access protecEPSS 0.4%