Falhas do tipo CWE-284

7.165 resultados

Controle de acesso inadequado a recursos

A aplicação falha em validar ou aplica incorretamente as restrições de acesso, permitindo que usuários não autorizados acessem dados ou funcionalidades que deveriam estar protegidas. É uma das fragilidades mais comuns em segurança: o código não verifica corretamente quem está pedindo acesso e simplesmente concede.

Exemplo

Um e-commerce que permite acessar o perfil de qualquer cliente substituindo o ID na URL (ex: /usuario/123 → /usuario/124), sem validar se o usuário autenticado é o dono daquele perfil. Um atacante consegue ver dados pessoais, histórico de compras e endereços de outras pessoas.

Como mitigar

Implemente verificações explícitas em cada acesso a recurso: autentique o usuário, identifique qual recurso ele quer acessar, e valide se as permissões dele cobrem aquele recurso específico. Use listas de controle de acesso (ACLs) ou papéis (RBAC/ABAC) consistentemente em toda a API ou aplicação, nunca deixando a segurança implícita.

CVE-2026-55014HIGHWindows Remote Help Defense Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-50373HIGHWindows Search Service Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2020-9046HIGHKantech EntraPass Security Management Software - System Permissions VulnerabilityEPSS 0.3%CVE-2026-26183HIGHRemote Access Management service/API (RPC server) Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-40381HIGHAzure Connected Machine Agent Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2024-46280HIGHPIX-LINK LV-WR22 RE3002-P1-01_V117.0 is vulnerable to Improper Access Control. The TELNET service is enabled with weak credentials for a rooEPSS 0.3%CVE-2026-50351HIGHWindows Audio Compression Manager (ACM) Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-50465HIGHWindows DNS Client Tampering VulnerabilityEPSS 0.3%CVE-2026-77252MEDIUMMCP Atlassian: JIRA_PROJECTS_FILTER and CONFLUENCE_SPACES_FILTER can be bypassed in search toolsEPSS 0.3%CVE-2026-50423HIGHWindows Kernel Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2025-29973HIGHMicrosoft Azure File Sync Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-50335HIGHWindows Operating Systems Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-41092HIGHMicrosoft Kinect Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-27914HIGHMicrosoft Management Console Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2025-27258MEDIUMEricsson Network Manager: escalation of privilege vulnerabilityEPSS 0.3%CVE-2026-11882LOWBuilderall for WordPress < 3.0.2 - Unauthenticated OAuth Access Token Poisoning via Public REST RoutesEPSS 0.3%CVE-2026-23595HIGHUnauthenticated Authentication Bypass in application API allows unauthorized administrative account creationEPSS 0.3%CVE-2026-61342MEDIUMVulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is aEPSS 0.3%CVE-2026-66804HIGHMicrosoft Windows Cross Device Service Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-50342HIGHWindows MIDI Service Module Elevation of Privileges VulnerabilityEPSS 0.3%