Falhas do tipo CWE-284

7.165 resultados

Controle de acesso inadequado a recursos

A aplicação falha em validar ou aplica incorretamente as restrições de acesso, permitindo que usuários não autorizados acessem dados ou funcionalidades que deveriam estar protegidas. É uma das fragilidades mais comuns em segurança: o código não verifica corretamente quem está pedindo acesso e simplesmente concede.

Exemplo

Um e-commerce que permite acessar o perfil de qualquer cliente substituindo o ID na URL (ex: /usuario/123 → /usuario/124), sem validar se o usuário autenticado é o dono daquele perfil. Um atacante consegue ver dados pessoais, histórico de compras e endereços de outras pessoas.

Como mitigar

Implemente verificações explícitas em cada acesso a recurso: autentique o usuário, identifique qual recurso ele quer acessar, e valide se as permissões dele cobrem aquele recurso específico. Use listas de controle de acesso (ACLs) ou papéis (RBAC/ABAC) consistentemente em toda a API ou aplicação, nunca deixando a segurança implícita.

CVE-2026-12972MEDIUMPayPlus Payment Gateway < 8.2.2 - Unauthenticated Order Payment Metadata TamperingEPSS 0.3%CVE-2024-10241MEDIUMPrivate channel names leaked with Ctrl+K when ElasticSearch is enabledEPSS 0.3%CVE-2026-56217MEDIUMCapgo - Encrypted Bundle Policy Bypass via Direct PostgREST UpdateEPSS 0.3%CVE-2026-71120MEDIUMVulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is EPSS 0.3%CVE-2025-1115MEDIUMRT-Thread lwp_syscall.c sys_timer_settime information disclosureEPSS 0.3%CVE-2026-9590MEDIUMImproper access control in the permission validation component in Devolutions Server 2026.1.19 and earlier allows an authenticated user withEPSS 0.3%CVE-2026-28415MEDIUMGradio has Open Redirect in OAuth FlowEPSS 0.3%CVE-2026-61044MEDIUMVulnerability in the Oracle Production Scheduling product of Oracle E-Business Suite (component: Internal Operations). Supported versions tEPSS 0.3%CVE-2026-17012MEDIUMRestore PayPal Standard for WooCommerce <= 3.1.0 - Payment Bypass via Unvalidated receiver_emailEPSS 0.3%CVE-2026-34277MEDIUMVulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Fluid Core). Supported versions that are afEPSS 0.3%CVE-2024-1439MEDIUMInadequate access control vulnerability in MoodleEPSS 0.3%CVE-2022-42814MEDIUMA logic issue was addressed with improved checks. This issue is fixed in macOS Ventura 13. An app may be able to access user-sensitive data.EPSS 0.3%CVE-2025-4431MEDIUMFeatured Image Plus <= 1.6.4 - Missing Authorization to Authenticated (Subscriber+) Featured Image UpdateEPSS 0.3%CVE-2026-34298MEDIUMVulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Personalization). Supported versions thatEPSS 0.3%CVE-2026-51702MEDIUMIncorrect access control in the setIpPortFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alterEPSS 0.3%CVE-2026-51704MEDIUMIncorrect access control in the setWiFiMeshConfig function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter meEPSS 0.3%CVE-2026-51683MEDIUMIncorrect access control in the setLanCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter LAN networEPSS 0.3%CVE-2026-51678MEDIUMIncorrect access control in the setSyslogCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter loggingEPSS 0.3%CVE-2026-31150MEDIUMIncorrect access control in Kaleris YMS v7.2.2.1 allows authenticated attackers with only the shipping/receiving role to view the truck's daEPSS 0.3%CVE-2026-60940MEDIUMVulnerability in the Oracle Service Contracts product of Oracle E-Business Suite (component: Internal Operations). Supported versions that EPSS 0.3%