Falhas do tipo CWE-284

7.169 resultados

Controle de acesso inadequado a recursos

A aplicação falha em validar ou aplica incorretamente as restrições de acesso, permitindo que usuários não autorizados acessem dados ou funcionalidades que deveriam estar protegidas. É uma das fragilidades mais comuns em segurança: o código não verifica corretamente quem está pedindo acesso e simplesmente concede.

Exemplo

Um e-commerce que permite acessar o perfil de qualquer cliente substituindo o ID na URL (ex: /usuario/123 → /usuario/124), sem validar se o usuário autenticado é o dono daquele perfil. Um atacante consegue ver dados pessoais, histórico de compras e endereços de outras pessoas.

Como mitigar

Implemente verificações explícitas em cada acesso a recurso: autentique o usuário, identifique qual recurso ele quer acessar, e valide se as permissões dele cobrem aquele recurso específico. Use listas de controle de acesso (ACLs) ou papéis (RBAC/ABAC) consistentemente em toda a API ou aplicação, nunca deixando a segurança implícita.

CVE-2026-94278MEDIUMFile Media Renamer <= 1.3 - Author+ Arbitrary File Rename via save-attachment-compatEPSS 0.2%CVE-2022-36396HIGHImproper access control in some Intel(R) Aptio* V UEFI Firmware Integrator Tools before version iDmiEdit-Linux-5.27.06.0017 may allow a privEPSS 0.2%CVE-2026-104914MEDIUMMISP: Soft-Deleted Attributes from Other Organizations Exposed via Attribute Search and Paginated ViewEPSS 0.2%CVE-2021-25463MEDIUMImproper access control vulnerability in PENUP prior to version 3.8.00.18 allows arbitrary webpage loading in webview.EPSS 0.2%CVE-2026-83278MEDIUMVulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-integrations-neo4j). Supported versions that are affecEPSS 0.2%CVE-2024-43031MEDIUMautMan v2.9.6 was discovered to contain an access control issue.EPSS 0.2%CVE-2024-38310MEDIUMImproper access control in some Intel(R) Graphics Driver software installers may allow an authenticated user to potentially enable escalatioEPSS 0.2%CVE-2025-31268MEDIUMA permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26EPSS 0.2%CVE-2026-90913HIGHJoomla! Core - [20260903] - Core - Improper ACL checks for access level webservice endpoints in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3EPSS 0.2%CVE-2026-11326MEDIUMOpenAI Atlas before 1.2025.288.15 exposed privileged browser APIs to web content on *.openai.com origins. A cross-site scripting vulnerabiliEPSS 0.2%CVE-2025-43315MEDIUMThis issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26. An aEPSS 0.2%CVE-2026-11333MEDIUMtittuvarghese CollegeManagementSystem Student Data Upload Endpoint upload_student_data.php unrestricted uploadEPSS 0.2%CVE-2025-24197MEDIUMA logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26. An app may bEPSS 0.2%CVE-2025-43270HIGHAn access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS VeEPSS 0.2%CVE-2025-59923LOWAn improper access control vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.6, FortiAuthenticator 6.5 all versions, FortiAutheEPSS 0.2%CVE-2023-22014HIGHVulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Portal). Supported versions that are affectEPSS 0.2%CVE-2026-60804LOWVulnerability in the Oracle E-Business Intelligence product of Oracle E-Business Suite (component: Definition). Supported versions that areEPSS 0.2%CVE-2026-76281MEDIUMImproper Access Control in Splunk EnterpriseEPSS 0.2%CVE-2026-11277MEDIUMInsufficient policy enforcement in Chrome for iOS in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to bypass discretEPSS 0.2%CVE-2025-40939MEDIUMA vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1). The affected device contains a USB port which allows unautheEPSS 0.2%