Falhas do tipo CWE-284

7.167 resultados

Controle de acesso inadequado a recursos

A aplicação falha em validar ou aplica incorretamente as restrições de acesso, permitindo que usuários não autorizados acessem dados ou funcionalidades que deveriam estar protegidas. É uma das fragilidades mais comuns em segurança: o código não verifica corretamente quem está pedindo acesso e simplesmente concede.

Exemplo

Um e-commerce que permite acessar o perfil de qualquer cliente substituindo o ID na URL (ex: /usuario/123 → /usuario/124), sem validar se o usuário autenticado é o dono daquele perfil. Um atacante consegue ver dados pessoais, histórico de compras e endereços de outras pessoas.

Como mitigar

Implemente verificações explícitas em cada acesso a recurso: autentique o usuário, identifique qual recurso ele quer acessar, e valide se as permissões dele cobrem aquele recurso específico. Use listas de controle de acesso (ACLs) ou papéis (RBAC/ABAC) consistentemente em toda a API ou aplicação, nunca deixando a segurança implícita.

CVE-2026-75793MEDIUMSureCart < 4.7.0 - Unauthenticated Account Creation with Automatic LoginEPSS 0.3%CVE-2026-77695MEDIUMWoo Refund And Exchange Lite < 4.6.4 - Unauthenticated Guest Order Message Disclosure and ManipulationEPSS 0.3%CVE-2024-44303HIGHThe issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.1. A malicious application may be able to modify proteEPSS 0.3%CVE-2026-12688MEDIUMProfileGrid < 5.9.9.7 - Unauthenticated Payment Bypass and Forced Group Membership via PayPal IPN ForgeryEPSS 0.3%CVE-2026-42862HIGHFlowise: Mass Assignment in Tool Update Endpoint Allows Cross-Workspace Resource ReassignmentEPSS 0.3%CVE-2026-77010MEDIUMHEL Online Classroom: AI-powered Online Classrooms <= 1.0.3 - Unauthenticated Moderator Join URL Disclosure and Class Access Code BypassEPSS 0.3%CVE-2026-34312LOWVulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 19.3-19.30. Easily exploitable vulEPSS 0.3%CVE-2025-0744HIGHImproper Access Control vulnerability in EmbedAIEPSS 0.3%CVE-2026-14834MEDIUMMailgun for WordPress < 2.2.1 - Unauthenticated Arbitrary Mailgun List Subscription via add_list AJAXEPSS 0.3%CVE-2026-86812MEDIUMWPCafe 3.0.10 - 3.0.17 - Unauthenticated Order Disclosure and Modification via food-orders REST APIEPSS 0.3%CVE-2026-14315MEDIUMPixel Tag Manager for WooCommerce < 2.2.1 - Unauthenticated Forged Conversion Event SubmissionEPSS 0.3%CVE-2026-101146MEDIUMEleveo Quality Management GWT RPC QMUtilsService UtilsService.createAndSaveAudit information disclosureEPSS 0.3%CVE-2024-5270MEDIUMSAML to email switch possible when email signin is disabledEPSS 0.3%CVE-2024-0104MEDIUMNVIDIA Mellanox OS, ONYX, Skyway, MetroX-2 and MetroX-3 XC contain a vulnerability in the LDAP AAA component, where a user can cause impropeEPSS 0.3%CVE-2026-48956MEDIUMJoomla! Core - [20260710] - Incorrect Access Control in com_modulesEPSS 0.3%CVE-2025-50897MEDIUMA vulnerability exists in riscv-boom SonicBOOM 1.2 (BOOMv1.2) processor implementation, where valid virtual-to-physical address translationsEPSS 0.3%CVE-2026-83085HIGHVulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that EPSS 0.3%CVE-2025-10741MEDIUMSelleo Mentingo Profile Picture unrestricted uploadEPSS 0.3%CVE-2024-30148MEDIUMHCL Leap is affected by improper access controlEPSS 0.3%CVE-2026-20322CRITICALCisco Nexus Dashboard Software Security Hardening Release September 2026 - Improper Access ControlEPSS 0.3%