Falhas do tipo CWE-284

7.141 resultados

Controle de acesso inadequado a recursos

A aplicação falha em validar ou aplica incorretamente as restrições de acesso, permitindo que usuários não autorizados acessem dados ou funcionalidades que deveriam estar protegidas. É uma das fragilidades mais comuns em segurança: o código não verifica corretamente quem está pedindo acesso e simplesmente concede.

Exemplo

Um e-commerce que permite acessar o perfil de qualquer cliente substituindo o ID na URL (ex: /usuario/123 → /usuario/124), sem validar se o usuário autenticado é o dono daquele perfil. Um atacante consegue ver dados pessoais, histórico de compras e endereços de outras pessoas.

Como mitigar

Implemente verificações explícitas em cada acesso a recurso: autentique o usuário, identifique qual recurso ele quer acessar, e valide se as permissões dele cobrem aquele recurso específico. Use listas de controle de acesso (ACLs) ou papéis (RBAC/ABAC) consistentemente em toda a API ou aplicação, nunca deixando a segurança implícita.

CVE-2019-1866LOWCisco Webex Business Suite Host Header Value Integrity VulnerabilityEPSS 0.3%CVE-2026-83284HIGHVulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versions that are affecteEPSS 0.3%CVE-2026-60249CRITICALVulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.EPSS 0.3%CVE-2025-15050MEDIUMcode-projects Student File Management System save_file.php unrestricted uploadEPSS 0.3%CVE-2026-38470MEDIUMA Broken access control vulnerability in the API user endpoint in GazellePW (GazellePosterWall) commit 86c4bedf727691b5a97af42a4864869d18446EPSS 0.3%CVE-2026-9374MEDIUMyangzongzhuan RuoYi-Vue Common Upload Endpoint upload FileUploadUtils.upload unrestricted uploadEPSS 0.3%CVE-2026-37100MEDIUMAn issue in the Bluetooth Low Energy (BLE) control interface of the Yamaha SR-B30A sound bar firmware 2.40 (Mobile App: Sound Bar Remote / vEPSS 0.3%CVE-2025-20316MEDIUMA vulnerability in the access control list (ACL) programming of Cisco IOS XE Software for Cisco Catalyst 9500X and 9600X Series Switches couEPSS 0.3%CVE-2026-60805MEDIUMVulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Cost Planning). Supported versions that are affeEPSS 0.3%CVE-2025-0739HIGHImproper Access Control vulnerability in EmbedAIEPSS 0.3%CVE-2026-83234HIGHVulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience MaEPSS 0.3%CVE-2025-69220HIGHLibreChat has Insufficient Access Control for Agent FilesEPSS 0.3%CVE-2026-48578HIGHSecure Boot Security Feature Bypass VulnerabilityEPSS 0.3%CVE-2026-83265HIGHVulnerability in the Oracle Web Services Manager product of Oracle Fusion Middleware (component: Web Services Agent). Supported versions thEPSS 0.3%CVE-2025-48860HIGHA vulnerability in the web application of the ctrlX OS setup mechanism facilitated an authenticated (low privileged) attacker to gain remoteEPSS 0.3%CVE-2026-59501HIGHPriority – CWE-284: Improper Access ControlEPSS 0.3%CVE-2025-0740HIGHImproper Access Control vulnerability in EmbedAIEPSS 0.3%CVE-2026-37067MEDIUMIncorrect access control in /vfm-admin/admin-panel/view/save-cvs.php in Veno File Manager Project 4.4.9 allows an unauthenticated attacker tEPSS 0.3%CVE-2026-102132HIGHKiteworks Core Privilege Escalation through Improper Access ControlEPSS 0.3%CVE-2025-43947HIGHCodemers KLIMS 1.6.DEV lacks a proper access control mechanism, allowing a normal KLIMS user to perform all the actions that an admin can peEPSS 0.3%