Falhas do tipo CWE-284

7.165 resultados

Controle de acesso inadequado a recursos

A aplicação falha em validar ou aplica incorretamente as restrições de acesso, permitindo que usuários não autorizados acessem dados ou funcionalidades que deveriam estar protegidas. É uma das fragilidades mais comuns em segurança: o código não verifica corretamente quem está pedindo acesso e simplesmente concede.

Exemplo

Um e-commerce que permite acessar o perfil de qualquer cliente substituindo o ID na URL (ex: /usuario/123 → /usuario/124), sem validar se o usuário autenticado é o dono daquele perfil. Um atacante consegue ver dados pessoais, histórico de compras e endereços de outras pessoas.

Como mitigar

Implemente verificações explícitas em cada acesso a recurso: autentique o usuário, identifique qual recurso ele quer acessar, e valide se as permissões dele cobrem aquele recurso específico. Use listas de controle de acesso (ACLs) ou papéis (RBAC/ABAC) consistentemente em toda a API ou aplicação, nunca deixando a segurança implícita.

CVE-2026-11474MEDIUMKushan2k student-management-system Registration Endpoint RegisterService.php unrestricted uploadEPSS 0.3%CVE-2019-15967MEDIUMCisco TelePresence Collaboration Endpoint and RoomOS Audio Eavesdropping VulnerabilityEPSS 0.3%CVE-2026-104637MEDIUMonetwothreeneth HospitalManagementSystem controller.php edit_patient unrestricted uploadEPSS 0.3%CVE-2026-14848MEDIUMPaid Member Subscriptions < 3.0.8 - Subscriber+ Cross-User Subscription Hijack via process_checkoutEPSS 0.3%CVE-2022-26389HIGHImproper Access Control Vulnerability in ELI Electrocardiograph DevicesEPSS 0.3%CVE-2025-57212HIGHIncorrect access control in the component ApiOrderService.java of platform v1.0.0 allows attackers to access sensitive information via a craEPSS 0.3%CVE-2026-60533HIGHVulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Generic Unix Connector). Supported vEPSS 0.3%CVE-2025-63663HIGHIncorrect access control in the /api/v1/conversations/*/files API of GT Edge AI Platform before v2.0.10 allows unauthorized attackers to accEPSS 0.3%CVE-2025-63664HIGHIncorrect access control in the /api/v1/conversations/*/messages API of GT Edge AI Platform before v2.0.10-dev allows unauthorized attackersEPSS 0.3%CVE-2025-63409HIGHPrivilege escalation and improper access control in GCOM EPON 1GE C00R371V00B01 allows remote authenticated users to modify administrator onEPSS 0.3%CVE-2026-18466MEDIUMWP Maps < 4.9.8 - Subscriber+ Unlimited Autoloaded Option CreationEPSS 0.3%CVE-2025-57210HIGHIncorrect access control in the component ApiPayController.java of platform v1.0.0 allows attackers to access sensitive information via unspEPSS 0.3%CVE-2025-57213HIGHIncorrect access control in the component orderService.queryObject of platform v1.0.0 allows attackers to access sensitive information via aEPSS 0.3%CVE-2025-65239MEDIUMIncorrect access control in the /aux1/ocussd/trace endpoint of OpenCode Systems USSD Gateway OC Release:5, version 6.13.11 allows attackers EPSS 0.3%CVE-2025-15084LOWyoulaitech youlai-mall Order Payment OrderController.java orderService.payOrder access controlEPSS 0.3%CVE-2026-100906MEDIUMEyeplus ONVIF Device GetUsers information disclosureEPSS 0.3%CVE-2026-105145MEDIUMWeaviate Verba generate_stream Endpoint util.py get_environment information disclosureEPSS 0.3%CVE-2026-3932MEDIUMInsufficient policy enforcement in PDF in Google Chrome on Android prior to 146.0.7680.71 allowed a remote attacker to bypass navigation resEPSS 0.3%CVE-2026-96774MEDIUMSPON Communications IP Network Audio Device XC-9603 Configuration File Download sys_cfg.txt loadCfg information disclosureEPSS 0.3%CVE-2026-13953MEDIUMInappropriate implementation in SplitView in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the rendererEPSS 0.3%