Falhas do tipo CWE-284

7.168 resultados

Controle de acesso inadequado a recursos

A aplicação falha em validar ou aplica incorretamente as restrições de acesso, permitindo que usuários não autorizados acessem dados ou funcionalidades que deveriam estar protegidas. É uma das fragilidades mais comuns em segurança: o código não verifica corretamente quem está pedindo acesso e simplesmente concede.

Exemplo

Um e-commerce que permite acessar o perfil de qualquer cliente substituindo o ID na URL (ex: /usuario/123 → /usuario/124), sem validar se o usuário autenticado é o dono daquele perfil. Um atacante consegue ver dados pessoais, histórico de compras e endereços de outras pessoas.

Como mitigar

Implemente verificações explícitas em cada acesso a recurso: autentique o usuário, identifique qual recurso ele quer acessar, e valide se as permissões dele cobrem aquele recurso específico. Use listas de controle de acesso (ACLs) ou papéis (RBAC/ABAC) consistentemente em toda a API ou aplicação, nunca deixando a segurança implícita.

CVE-2026-101146MEDIUMEleveo Quality Management GWT RPC QMUtilsService UtilsService.createAndSaveAudit information disclosureEPSS 0.3%CVE-2025-7487MEDIUMJoeyBling SpringBoot_MyBatisPlus upload SysFileController unrestricted uploadEPSS 0.3%CVE-2025-24236MEDIUMAn access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app mEPSS 0.3%CVE-2026-101891CRITICALWatchGuard AP Improper Access Control in API Service Allows Unauthenticated AccessEPSS 0.3%CVE-2026-34082MEDIUMDify has IDOR in deleting someone else's chat conversationEPSS 0.3%CVE-2026-86858HIGHUnauthenticated Privilege Escalation via GraphQL in ServiceNow AI PlatformEPSS 0.3%CVE-2026-2205MEDIUMWeKan Meteor Publication cards.js CardPubSubBleed information disclosureEPSS 0.3%CVE-2026-56608LOWHCL iControl is affected by multiple security vulnerabilities(CVE-2026-56608 and CVE-2026-56609).EPSS 0.3%CVE-2024-27803LOWA permissions issue was addressed with improved validation. This issue is fixed in iOS 17.5 and iPadOS 17.5. An attacker with physical accesEPSS 0.3%CVE-2026-46696LOWOctober CMS: Safe Mode Sandbox Bypass via Session Store and Forwarded Builder CallsEPSS 0.3%CVE-2026-84200CRITICALKyverno before v1.13.0 Policy Bypass via Multiple ExceptionsEPSS 0.3%CVE-2026-70853LOWVulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is EPSS 0.3%CVE-2026-20167HIGHCisco IoT Field Network Director Remote Device Denial of Service VulnerabilityEPSS 0.3%CVE-2026-60521MEDIUMVulnerability in the Oracle Advanced Pricing product of Oracle E-Business Suite (component: Price List). Supported versions that are affectEPSS 0.3%CVE-2026-70788MEDIUMVulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affEPSS 0.3%CVE-2026-95263HIGHFeehi CMS 2.1.1 is vulnerable to Incorrect Access Control. A low-privilege backend administrator with administrator-update permission can chEPSS 0.3%CVE-2026-34324MEDIUMVulnerability in the Oracle Life Sciences InForm product of Oracle Life Science Applications (component: App Server). Supported versions thEPSS 0.3%CVE-2026-87965MEDIUMEasy Appointments < 4.0.2.2 - Unauthenticated Appointment Cancellation/Confirmation via Forgeable Email-Link TokenEPSS 0.3%CVE-2025-66223HIGHOpenObserve's Invite Token Lifecycle MisconfigurationEPSS 0.3%CVE-2026-71030HIGHVulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca ApplicEPSS 0.3%