Falhas do tipo CWE-284

7.139 resultados

Controle de acesso inadequado a recursos

A aplicação falha em validar ou aplica incorretamente as restrições de acesso, permitindo que usuários não autorizados acessem dados ou funcionalidades que deveriam estar protegidas. É uma das fragilidades mais comuns em segurança: o código não verifica corretamente quem está pedindo acesso e simplesmente concede.

Exemplo

Um e-commerce que permite acessar o perfil de qualquer cliente substituindo o ID na URL (ex: /usuario/123 → /usuario/124), sem validar se o usuário autenticado é o dono daquele perfil. Um atacante consegue ver dados pessoais, histórico de compras e endereços de outras pessoas.

Como mitigar

Implemente verificações explícitas em cada acesso a recurso: autentique o usuário, identifique qual recurso ele quer acessar, e valide se as permissões dele cobrem aquele recurso específico. Use listas de controle de acesso (ACLs) ou papéis (RBAC/ABAC) consistentemente em toda a API ou aplicação, nunca deixando a segurança implícita.

CVE-2026-83432HIGHVulnerability in the Oracle Depot Repair product of Oracle E-Business Suite (component: Estimate and Actual Charges). Supported versions thEPSS 0.4%CVE-2026-83029CRITICALVulnerability in the Oracle Managed File Transfer product of Oracle Fusion Middleware (component: MFT Runtime Server). Supported versions tEPSS 0.4%CVE-2026-72595HIGHBadChoice Handesk - Broken Access ControlEPSS 0.4%CVE-2025-25734MEDIUMKapsch TrafficCom RIS-9160 & RIS-9260 Roadside Units (RSUs) v3.2.0.829.23, v3.8.0.1119.42, and v4.6.0.1211.28 was discovered to contain an uEPSS 0.4%CVE-2025-1259HIGHOn affected platforms running Arista EOS with OpenConfig configured, a gNOI request can be run when it should have been rejected.EPSS 0.4%CVE-2025-23164MEDIUMA misconfigured access token mechanism in the Unifi Protect Application (Version 5.3.41 and earlier) could permit the recipient of a "Share EPSS 0.4%CVE-2026-50881HIGHIncorrect access control in the impworks Bonsai v6.0 allows authenticated attackers with Editor privileges to escalate privileges to AdminisEPSS 0.4%CVE-2026-83152HIGHVulnerability in the Oracle Project Intelligence product of Oracle E-Business Suite (component: Internal Operations). Supported versions thEPSS 0.4%CVE-2025-37140MEDIUMAuthenticated Arbitrary File Download Vulnerabilities in CLI Binary of AOS-8 Controller/Mobility Conductor Web-Based Management InterfaceEPSS 0.4%CVE-2026-83434HIGHVulnerability in the Oracle Product Workbench product of Oracle E-Business Suite (component: Internal Operations). Supported versions that EPSS 0.4%CVE-2026-83447HIGHVulnerability in the Oracle Bills of Material product of Oracle E-Business Suite (component: Internal Operations). Supported versions that EPSS 0.4%CVE-2026-58545MEDIUMWindows Kernel Security Feature Bypass VulnerabilityEPSS 0.4%CVE-2026-15230HIGHYayPricing < 3.5.7 - Subscriber+ Pricing Configuration Modification and Coupon Code DisclosureEPSS 0.4%CVE-2026-36720HIGHInsecure permissions in bookcars v8.3 allows authenticated attackers to escalate privileges from user to admin via modifying their user typeEPSS 0.4%CVE-2026-83030HIGHVulnerability in the Oracle Managed File Transfer product of Oracle Fusion Middleware (component: MFT Runtime Server). Supported versions tEPSS 0.4%CVE-2025-50105HIGHVulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Administration). Supported veEPSS 0.4%CVE-2026-83455HIGHVulnerability in the Oracle Demand Signal Repository product of Oracle E-Business Suite (component: Internal Operations). Supported versionEPSS 0.4%CVE-2024-30418HIGHVulnerability of insufficient permission verification in the app management module. Impact: Successful exploitation of this vulnerability wiEPSS 0.4%CVE-2026-83177HIGHVulnerability in the Oracle One-to-One Fulfillment product of Oracle E-Business Suite (component: Documents). Supported versions that are aEPSS 0.4%CVE-2024-0810MEDIUMInsufficient policy enforcement in DevTools in Google Chrome prior to 121.0.6167.85 allowed an attacker who convinced a user to install a maEPSS 0.4%