Falhas do tipo CWE-284

7.147 resultados

Controle de acesso inadequado a recursos

A aplicação falha em validar ou aplica incorretamente as restrições de acesso, permitindo que usuários não autorizados acessem dados ou funcionalidades que deveriam estar protegidas. É uma das fragilidades mais comuns em segurança: o código não verifica corretamente quem está pedindo acesso e simplesmente concede.

Exemplo

Um e-commerce que permite acessar o perfil de qualquer cliente substituindo o ID na URL (ex: /usuario/123 → /usuario/124), sem validar se o usuário autenticado é o dono daquele perfil. Um atacante consegue ver dados pessoais, histórico de compras e endereços de outras pessoas.

Como mitigar

Implemente verificações explícitas em cada acesso a recurso: autentique o usuário, identifique qual recurso ele quer acessar, e valide se as permissões dele cobrem aquele recurso específico. Use listas de controle de acesso (ACLs) ou papéis (RBAC/ABAC) consistentemente em toda a API ou aplicação, nunca deixando a segurança implícita.

CVE-2025-68721HIGHAxigen Mail Server before 10.5.57 contains an improper access control vulnerability in the WebAdmin interface. A delegated admin account witEPSS 0.3%CVE-2025-55797MEDIUMAn improper access control vulnerability in FormCms v0.5.4 in the /api/schemas/history/[schemaId] endpoint allows unauthenticated attackers EPSS 0.3%CVE-2026-87229HIGHVulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is EPSS 0.3%CVE-2024-5470LOWImproper Access Control in GitLabEPSS 0.3%CVE-2024-40547MEDIUMPublicCMS v4.0.202302.e was discovered to contain an arbitrary file content replacement vulnerability via the component /admin/cmsTemplate/rEPSS 0.3%CVE-2020-1666MEDIUMJunos OS Evolved: 'console log-out-on-disconnect' fails to terminate session on console cable disconnectionEPSS 0.3%CVE-2025-10070MEDIUMPortabilis i-Educar enturmacao-em-lote access controlEPSS 0.3%CVE-2026-51610MEDIUMIncorrect access control in the RebootSystem function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to arbitrarily fEPSS 0.3%CVE-2025-8128MEDIUMzhousg letao product.js unrestricted uploadEPSS 0.3%CVE-2024-32124MEDIUMAn improper access control vulnerability [CWE-284] in FortiIsolator version 2.4.4, version 2.4.3, 2.3 all versions logging component may allEPSS 0.3%CVE-2025-10071MEDIUMPortabilis i-Educar cancelar-enturmacao-em-lote access controlEPSS 0.3%CVE-2026-61205HIGHVulnerability in the PeopleSoft Enterprise SCM Purchasing product of Oracle PeopleSoft (component: Purchasing). The supported version thatEPSS 0.3%CVE-2026-73925HIGHVulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected aEPSS 0.3%CVE-2026-82486LOWSiteServer SSCMS Agent Installation Workflow access controlEPSS 0.3%CVE-2026-63045HIGHApache HTTP Server: mod_proxy_ftp PASV address handlingEPSS 0.3%CVE-2019-10127—A vulnerability was found in postgresql versions 11.x prior to 11.3. The Windows installer for BigSQL-supplied PostgreSQL does not lock downEPSS 0.3%CVE-2025-10072MEDIUMPortabilis i-Educar enturmar access controlEPSS 0.3%CVE-2025-11078MEDIUMitsourcecode Open Source Job Portal controller.php unrestricted uploadEPSS 0.3%CVE-2026-69414HIGHMicrosoft Defender Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2024-24487MEDIUMAn issue discovered in silex technology DS-600 Firmware v.1.4.1 allows a remote attacker to cause a denial of service via crafted UDP packetEPSS 0.3%