Falhas do tipo CWE-284

7.169 resultados

Controle de acesso inadequado a recursos

A aplicação falha em validar ou aplica incorretamente as restrições de acesso, permitindo que usuários não autorizados acessem dados ou funcionalidades que deveriam estar protegidas. É uma das fragilidades mais comuns em segurança: o código não verifica corretamente quem está pedindo acesso e simplesmente concede.

Exemplo

Um e-commerce que permite acessar o perfil de qualquer cliente substituindo o ID na URL (ex: /usuario/123 → /usuario/124), sem validar se o usuário autenticado é o dono daquele perfil. Um atacante consegue ver dados pessoais, histórico de compras e endereços de outras pessoas.

Como mitigar

Implemente verificações explícitas em cada acesso a recurso: autentique o usuário, identifique qual recurso ele quer acessar, e valide se as permissões dele cobrem aquele recurso específico. Use listas de controle de acesso (ACLs) ou papéis (RBAC/ABAC) consistentemente em toda a API ou aplicação, nunca deixando a segurança implícita.

CVE-2021-26360HIGHAn attacker with local access to the system can make unauthorized modifications of the security configuration of the SOC registers. This couEPSS 0.2%CVE-2026-60238MEDIUMVulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.EPSS 0.2%CVE-2026-76610MEDIUMJoomla Extension - yootheme.com - Unauthenticated tag modifications in Zoo < 4.1.65EPSS 0.2%CVE-2025-70340MEDIUMA Broken Access Control vulnerability exists in ThingsBoard Professional Edition (PE) 4.21 and below, within the Alarms comments functionaliEPSS 0.2%CVE-2026-75824MEDIUMWP User Frontend 2.5.8 - 4.3.11 - Unauthenticated Account Creation with Registration DisabledEPSS 0.2%CVE-2024-40825MEDIUMThe issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15, visionOS 2. A malicious app with root privileges may EPSS 0.2%CVE-2026-77765MEDIUMBetter Payment < 2.3.4 - Unauthenticated Payment Amount ManipulationEPSS 0.2%CVE-2023-21969MEDIUMVulnerability in Oracle SQL Developer (component: Installation). Supported versions that are affected are Prior to 23.1.0. Easily exploitabEPSS 0.2%CVE-2024-42406MEDIUMUnauthorized access on archived channelsEPSS 0.2%CVE-2024-42795MEDIUMAn Incorrect Access Control vulnerability was found in /music/view_user.php?id=3 and /music/controller.php?page=edit_user&id=3 in Kashipara EPSS 0.2%CVE-2026-16986MEDIUMBooking Package < 1.7.25 - Unauthenticated Price Manipulation via Service and Option Cost ParametersEPSS 0.2%CVE-2021-4016MEDIUMRapid7 Insight Agent Improper Access ControlEPSS 0.2%CVE-2023-38005MEDIUMImproper Access Control and Exposure of Information Through Directory Listing vulnerabilities affect IBM Cloud Pak System[, ]EPSS 0.2%CVE-2024-32939MEDIUMEmail addresses of remote users visible in props regardless of server settingsEPSS 0.2%CVE-2026-11464LOWJeecgBoot User List Endpoint SysUserController.java queryPageList information disclosureEPSS 0.2%CVE-2022-20358HIGHIn startSync of AbstractThreadedSyncAdapter.java, there is a possible way to access protected content of content providers due to a missing EPSS 0.2%CVE-2023-43086HIGH Dell Command | Configure, versions prior to 4.11.0, contains an improper access control vulnerability. A local malicious user could potentiEPSS 0.2%CVE-2023-24485HIGHPrivilege Escalation on the system running a vulnerable version of Citrix Workspace app for WindowsEPSS 0.2%CVE-2025-29557MEDIUMExaGrid EX10 6.3 - 7.0.1.P08 is vulnerable to Incorrect Access Control in the MailConfiguration API endpoint, where users with operator-leveEPSS 0.2%CVE-2025-32992HIGHThermo Fisher Scientific ePort through 3.0.0 has Incorrect Access Control.EPSS 0.2%