Falhas do tipo CWE-284

7.139 resultados

Controle de acesso inadequado a recursos

A aplicação falha em validar ou aplica incorretamente as restrições de acesso, permitindo que usuários não autorizados acessem dados ou funcionalidades que deveriam estar protegidas. É uma das fragilidades mais comuns em segurança: o código não verifica corretamente quem está pedindo acesso e simplesmente concede.

Exemplo

Um e-commerce que permite acessar o perfil de qualquer cliente substituindo o ID na URL (ex: /usuario/123 → /usuario/124), sem validar se o usuário autenticado é o dono daquele perfil. Um atacante consegue ver dados pessoais, histórico de compras e endereços de outras pessoas.

Como mitigar

Implemente verificações explícitas em cada acesso a recurso: autentique o usuário, identifique qual recurso ele quer acessar, e valide se as permissões dele cobrem aquele recurso específico. Use listas de controle de acesso (ACLs) ou papéis (RBAC/ABAC) consistentemente em toda a API ou aplicação, nunca deixando a segurança implícita.

CVE-2026-67284MEDIUMJoomla Extension - tabaoca.org - Improper ACL checks allow file operations in Cotton Cloud < 2.0.2EPSS 0.4%CVE-2026-4026HIGHFlexNet Manager Suite Privilege Escalation VulnerabilityEPSS 0.4%CVE-2026-40866HIGHHorilla: Unauthorized Document Overwrite via File Upload EndpointEPSS 0.4%CVE-2026-45043CRITICALRustFS: ImportIam Allows Creation of Backdoor Service Accounts Under Any Parent Including RootEPSS 0.4%CVE-2026-83174HIGHVulnerability in the Oracle CRM Technical Foundation product of Oracle E-Business Suite (component: Application Framework). Supported versiEPSS 0.4%CVE-2026-83448HIGHVulnerability in the Oracle Bills of Material product of Oracle E-Business Suite (component: Internal Operations). Supported versions that EPSS 0.4%CVE-2026-58545MEDIUMWindows Kernel Security Feature Bypass VulnerabilityEPSS 0.4%CVE-2026-83132HIGHVulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart). Supported versions that are affected are EPSS 0.4%CVE-2026-83029CRITICALVulnerability in the Oracle Managed File Transfer product of Oracle Fusion Middleware (component: MFT Runtime Server). Supported versions tEPSS 0.4%CVE-2026-83434HIGHVulnerability in the Oracle Product Workbench product of Oracle E-Business Suite (component: Internal Operations). Supported versions that EPSS 0.4%CVE-2026-87152HIGHVulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: Create Item Instance). Supported versions that arEPSS 0.4%CVE-2025-37142MEDIUMAuthenticated Arbitrary File Download Vulnerabilities in CLI Binary of AOS-8 Controller/Mobility Conductor Web-Based Management InterfaceEPSS 0.4%CVE-2026-83072HIGHVulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Search Bean [Incl. Advanced]). SupportedEPSS 0.4%CVE-2026-83089HIGHVulnerability in the Oracle Alert product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affectedEPSS 0.4%CVE-2026-72563HIGHBadChoice Handesk - Broken Access ControlEPSS 0.4%CVE-2025-25734MEDIUMKapsch TrafficCom RIS-9160 & RIS-9260 Roadside Units (RSUs) v3.2.0.829.23, v3.8.0.1119.42, and v4.6.0.1211.28 was discovered to contain an uEPSS 0.4%CVE-2026-83297HIGHVulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versions that are affecteEPSS 0.4%CVE-2026-87159HIGHVulnerability in the Oracle HRMS (India) product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are aEPSS 0.4%CVE-2026-33103MEDIUMMicrosoft Dynamics 365 (On-Premises) Information Disclosure VulnerabilityEPSS 0.4%CVE-2026-83177HIGHVulnerability in the Oracle One-to-One Fulfillment product of Oracle E-Business Suite (component: Documents). Supported versions that are aEPSS 0.4%