Falhas do tipo CWE-284

7.169 resultados

Controle de acesso inadequado a recursos

A aplicação falha em validar ou aplica incorretamente as restrições de acesso, permitindo que usuários não autorizados acessem dados ou funcionalidades que deveriam estar protegidas. É uma das fragilidades mais comuns em segurança: o código não verifica corretamente quem está pedindo acesso e simplesmente concede.

Exemplo

Um e-commerce que permite acessar o perfil de qualquer cliente substituindo o ID na URL (ex: /usuario/123 → /usuario/124), sem validar se o usuário autenticado é o dono daquele perfil. Um atacante consegue ver dados pessoais, histórico de compras e endereços de outras pessoas.

Como mitigar

Implemente verificações explícitas em cada acesso a recurso: autentique o usuário, identifique qual recurso ele quer acessar, e valide se as permissões dele cobrem aquele recurso específico. Use listas de controle de acesso (ACLs) ou papéis (RBAC/ABAC) consistentemente em toda a API ou aplicação, nunca deixando a segurança implícita.

CVE-2026-62580LOWVulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is aEPSS 0.2%CVE-2024-41308HIGHAn issue in the Ping feature of IT Solutions Enjay CRM OS v1.0 allows attackers to escape the restricted terminal environment and gain root-EPSS 0.2%CVE-2026-83346MEDIUMVulnerability in the Oracle Fusion Middleware Control product of Oracle Fusion Middleware (component: Framework). Supported versions that aEPSS 0.2%CVE-2026-104912HIGHMISP Correlation Authorization Bypass Exposes Restricted Event and Attribute DataEPSS 0.2%CVE-2026-8545LOWObject corruption in Compositing in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer processEPSS 0.2%CVE-2021-33162HIGHImproper access control in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware may allow an authentEPSS 0.2%CVE-2026-10172MEDIUMBdtask Multi-Store Inventory Management System Component Module.php upload unrestricted uploadEPSS 0.2%CVE-2023-20065HIGHA vulnerability in the Cisco IOx application hosting subsystem of Cisco IOS XE Software could allow an authenticated, local attacker to elevEPSS 0.2%CVE-2026-10152MEDIUMTaleLin lin-cms-spring-boot book Endpoint BookController.java access controlEPSS 0.2%CVE-2026-48529MEDIUMGitHub MCP Server: Lockdown mode singleton in HTTP server causes cross-user GraphQL client confusionEPSS 0.2%CVE-2023-40071HIGHImproper access control in some Intel(R) GPA software installers before version 2023.3 may allow an authenticated user to potentially enableEPSS 0.2%CVE-2025-25730MEDIUMAn issue in Motorola Mobility Droid Razr HD (Model XT926) System Version: 9.18.94.XT926.Verizon.en.US allows physically proximate unauthorizEPSS 0.2%CVE-2025-55012HIGHZed AI Agent Remote Code ExecutionEPSS 0.2%CVE-2022-34457HIGH Dell command configuration, version 4.8 and prior, contains improper folder permission when installed not to default path but to non-secureEPSS 0.2%CVE-2024-30146MEDIUMHCL Domino Leap is affected by improper access controlEPSS 0.2%CVE-2026-0977MEDIUMIBM CICS Transaction Gateway for Multiplatforms Information DisclosureEPSS 0.2%CVE-2023-7025HIGHKylinSoft hedron-domain-hook DBus init_kcm access controlEPSS 0.2%CVE-2024-1898LOWImproper access control in the notification feature in Devolutions Server 2023.3.14.0 and earlier allows a low privileged user to change notEPSS 0.2%CVE-2025-43476HIGHA permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS TahoEPSS 0.2%CVE-2026-16387CRITICALSite isolation issue in the Networking componentEPSS 0.2%