Falhas do tipo CWE-284

7.151 resultados

Controle de acesso inadequado a recursos

A aplicação falha em validar ou aplica incorretamente as restrições de acesso, permitindo que usuários não autorizados acessem dados ou funcionalidades que deveriam estar protegidas. É uma das fragilidades mais comuns em segurança: o código não verifica corretamente quem está pedindo acesso e simplesmente concede.

Exemplo

Um e-commerce que permite acessar o perfil de qualquer cliente substituindo o ID na URL (ex: /usuario/123 → /usuario/124), sem validar se o usuário autenticado é o dono daquele perfil. Um atacante consegue ver dados pessoais, histórico de compras e endereços de outras pessoas.

Como mitigar

Implemente verificações explícitas em cada acesso a recurso: autentique o usuário, identifique qual recurso ele quer acessar, e valide se as permissões dele cobrem aquele recurso específico. Use listas de controle de acesso (ACLs) ou papéis (RBAC/ABAC) consistentemente em toda a API ou aplicação, nunca deixando a segurança implícita.

CVE-2026-61124HIGHVulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are afEPSS 0.3%CVE-2025-7864MEDIUMthinkgem JeeSite FileUploadController.java upload unrestricted uploadEPSS 0.3%CVE-2025-64516HIGHGLPI incorrectly authorizes access to documentsEPSS 0.3%CVE-2023-52099HIGHVulnerability of foreground service restrictions being bypassed in the NMS module. Successful exploitation of this vulnerability may affect EPSS 0.3%CVE-2025-37131MEDIUMAuthenticated Arbitrary File Read allows Data Exposure in CLI InterfaceEPSS 0.3%CVE-2026-62458HIGHVulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). Supported versions that arEPSS 0.3%CVE-2026-87249HIGHVulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is EPSS 0.3%CVE-2024-43409MEDIUMGhost's improper authentication allows access to member information and actionsEPSS 0.3%CVE-2026-79316HIGHAn improper access control vulnerability exists in x-ui 0.3.2. Any authenticated panel user can modify the xray configuration template throuEPSS 0.3%CVE-2025-56405HIGHAn issue was discovered in litmusautomation litmus-mcp-server thru 0.0.1 allowing unauthorized attackers to control the target's MCP serviceEPSS 0.3%CVE-2026-87142HIGHVulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supportEPSS 0.3%CVE-2026-20622HIGHA privacy issue was addressed with improved handling of temporary files. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, mEPSS 0.3%CVE-2026-77753MEDIUMTemporary Login Without Password < 1.9.9 - Authenticated Temporary Access Revocation Bypass via Application PasswordsEPSS 0.3%CVE-2026-70764HIGHVulnerability in the Oracle General Ledger product of Oracle E-Business Suite (component: Internal Operations). Supported versions that areEPSS 0.3%CVE-2026-71048HIGHVulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues). The supported verEPSS 0.3%CVE-2023-49099LOWDiscourse secure uploads accessible to guests even when login is requiredEPSS 0.3%CVE-2025-0691MEDIUMImproper access control in permissions component in Devolutions Server 2025.1.10.0 and earlier allows an authenticated user to bypass the "EEPSS 0.3%CVE-2026-35066HIGHDell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Access Control vulnerability. A low privileged attacker with remEPSS 0.3%CVE-2026-60584HIGHVulnerability in the Oracle Transportation Management product of Oracle Supply Chain (component: CSV Management). The supported version thEPSS 0.3%CVE-2024-53348HIGHLoxiLB v.0.9.7 and before is vulnerable to Incorrect Access Control which allows attackers to obtain sensitive information and escalate privEPSS 0.3%