Falhas do tipo CWE-284

7.165 resultados

Controle de acesso inadequado a recursos

A aplicação falha em validar ou aplica incorretamente as restrições de acesso, permitindo que usuários não autorizados acessem dados ou funcionalidades que deveriam estar protegidas. É uma das fragilidades mais comuns em segurança: o código não verifica corretamente quem está pedindo acesso e simplesmente concede.

Exemplo

Um e-commerce que permite acessar o perfil de qualquer cliente substituindo o ID na URL (ex: /usuario/123 → /usuario/124), sem validar se o usuário autenticado é o dono daquele perfil. Um atacante consegue ver dados pessoais, histórico de compras e endereços de outras pessoas.

Como mitigar

Implemente verificações explícitas em cada acesso a recurso: autentique o usuário, identifique qual recurso ele quer acessar, e valide se as permissões dele cobrem aquele recurso específico. Use listas de controle de acesso (ACLs) ou papéis (RBAC/ABAC) consistentemente em toda a API ou aplicação, nunca deixando a segurança implícita.

CVE-2026-13936MEDIUMInappropriate implementation in Passwords in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to obtain potentiallyEPSS 0.3%CVE-2025-62159HIGHExternal Secrets Operator's BeyondTrust Provider has Insecure Secret RetrievalEPSS 0.3%CVE-2025-8841MEDIUMzlt2000 microservices-platform FileController.java upload unrestricted uploadEPSS 0.3%CVE-2024-55402MEDIUM4C Strategies Exonaut before v22.4 was discovered to contain an access control issue.EPSS 0.3%CVE-2024-41905HIGHA vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V2.0). The affected application do not haEPSS 0.3%CVE-2024-55019MEDIUMIncorrect access control in the component download_wb.cgi of Weintek cMT-3072XH2 easyweb Web Version v2.1.53, OS v20231011 allows unauthentiEPSS 0.3%CVE-2026-60641HIGHVulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are EPSS 0.3%CVE-2025-46299MEDIUMA memory initialization issue was addressed with improved memory handling. This issue is fixed in Safari 26.2, iOS 26.2 and iPadOS 26.2, macEPSS 0.3%CVE-2026-41160MEDIUMEspoCRM: Broken Access Control / IDOR in Note Pinning API allows unauthorized modification of notesEPSS 0.3%CVE-2026-77689MEDIUMAmelia Pro 9.0 - 9.8 - Unauthenticated Payment BypassEPSS 0.3%CVE-2026-14822MEDIUMEvent Tickets < 5.29.0.1 - Unauthenticated PayPal Order Status ManipulationEPSS 0.3%CVE-2026-21447HIGHBagisto has IDOR in Customer Order Reorder FunctionalityEPSS 0.3%CVE-2025-46174HIGHRuoyi v4.8.0 vulnerable to Incorrect Access Control. There is a missing checkUserDataScope permission check in the resetPwd Method of SysUseEPSS 0.3%CVE-2026-84936MEDIUMEmbedPress 4.6.0 - 4.6.3 - Unauthenticated Google Reviews API Quota Consumption and Database BloatEPSS 0.3%CVE-2026-87840MEDIUMTripzzy < 1.5.1 - Unauthenticated Booking Data TamperingEPSS 0.3%CVE-2025-46175HIGHRuoyi v4.8.0 is vulnerable to Incorrect Access Control. There is a missing checkUserDataScope permission check in the authRole method of SysEPSS 0.3%CVE-2026-14322MEDIUMTimetics < 1.0.57 - Unauthenticated Booking Auto-Approval via Arbitrary payment_methodEPSS 0.3%CVE-2026-90976MEDIUMClean Login < 1.19 - Unauthenticated Account Creation with Registration DisabledEPSS 0.3%CVE-2026-12966MEDIUMDirect Payments for WooCommerce < 2.5.3 - Unauthenticated Cross-Customer Order Tampering via digages AJAX ActionsEPSS 0.3%CVE-2026-90922MEDIUMPaid Member Subscriptions < 3.0.9 - Unauthenticated Membership Payment Bypass via PayPal Standard Amount and Currency MismatchEPSS 0.3%