Falhas do tipo CWE-284

7.145 resultados

Controle de acesso inadequado a recursos

A aplicação falha em validar ou aplica incorretamente as restrições de acesso, permitindo que usuários não autorizados acessem dados ou funcionalidades que deveriam estar protegidas. É uma das fragilidades mais comuns em segurança: o código não verifica corretamente quem está pedindo acesso e simplesmente concede.

Exemplo

Um e-commerce que permite acessar o perfil de qualquer cliente substituindo o ID na URL (ex: /usuario/123 → /usuario/124), sem validar se o usuário autenticado é o dono daquele perfil. Um atacante consegue ver dados pessoais, histórico de compras e endereços de outras pessoas.

Como mitigar

Implemente verificações explícitas em cada acesso a recurso: autentique o usuário, identifique qual recurso ele quer acessar, e valide se as permissões dele cobrem aquele recurso específico. Use listas de controle de acesso (ACLs) ou papéis (RBAC/ABAC) consistentemente em toda a API ou aplicação, nunca deixando a segurança implícita.

CVE-2026-60927HIGHVulnerability in the Oracle Public Sector Financials product of Oracle E-Business Suite (component: Internal Operations). Supported versionEPSS 0.3%CVE-2026-46935HIGHVulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Internal Operations). SEPSS 0.3%CVE-2026-62493HIGHVulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affEPSS 0.3%CVE-2026-61141HIGHVulnerability in the Oracle Advanced Benefits product of Oracle E-Business Suite (component: Affordable Care Act). Supported versions that EPSS 0.3%CVE-2026-20888MEDIUMGitea Pull Requests Auto-Merge: Read-Only Users Can Cancel Scheduled Auto-Merge via Web Endpoint (Authorization Bypass)EPSS 0.3%CVE-2026-62495HIGHVulnerability in the Oracle Process Manufacturing Process Execution product of Oracle E-Business Suite (component: Internal Operations). TEPSS 0.3%CVE-2026-70706HIGHVulnerability in the Oracle Sales product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affectedEPSS 0.3%CVE-2026-83002HIGHVulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that EPSS 0.3%CVE-2026-60770HIGHVulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported versions that are afEPSS 0.3%CVE-2026-46934HIGHVulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Internal Operations). SEPSS 0.3%CVE-2025-50075MEDIUMVulnerability in the Oracle Financial Services Revenue Management and Billing product of Oracle Financial Services Applications (component: EPSS 0.3%CVE-2025-1881MEDIUMi-Drive i11/i12 Video Footage/Live Video Stream access controlEPSS 0.3%CVE-2026-76142CRITICALGenians, Inc. Genian NAC/ZTNA Improper Access Control on the Internal InterfaceEPSS 0.3%CVE-2025-61758MEDIUMVulnerability in the PeopleSoft Enterprise FIN IT Asset Management product of Oracle PeopleSoft (component: IT Asset Management). The suppEPSS 0.3%CVE-2026-34248LOWZammad has an information disclosure in ticket detail view of customers in shared organizationsEPSS 0.3%CVE-2025-7100MEDIUMBoyunCMS Index.php unrestricted uploadEPSS 0.3%CVE-2023-39941HIGHImproper access control in some Intel(R) SUR software before version 2.4.10587 may allow an unauthenticated user to potentially enable deniaEPSS 0.3%CVE-2025-53035MEDIUMVulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (comEPSS 0.3%CVE-2024-1144MEDIUMImproper Access Control at Alma Devklan BlogEPSS 0.3%CVE-2024-42794MEDIUMKashipara Music Management System v1.0 is vulnerable to Incorrect Access Control via /music/ajax.php?action=save_user.EPSS 0.3%