Falhas do tipo CWE-284

7.169 resultados

Controle de acesso inadequado a recursos

A aplicação falha em validar ou aplica incorretamente as restrições de acesso, permitindo que usuários não autorizados acessem dados ou funcionalidades que deveriam estar protegidas. É uma das fragilidades mais comuns em segurança: o código não verifica corretamente quem está pedindo acesso e simplesmente concede.

Exemplo

Um e-commerce que permite acessar o perfil de qualquer cliente substituindo o ID na URL (ex: /usuario/123 → /usuario/124), sem validar se o usuário autenticado é o dono daquele perfil. Um atacante consegue ver dados pessoais, histórico de compras e endereços de outras pessoas.

Como mitigar

Implemente verificações explícitas em cada acesso a recurso: autentique o usuário, identifique qual recurso ele quer acessar, e valide se as permissões dele cobrem aquele recurso específico. Use listas de controle de acesso (ACLs) ou papéis (RBAC/ABAC) consistentemente em toda a API ou aplicação, nunca deixando a segurança implícita.

CVE-2026-71129HIGHVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.EPSS 0.2%CVE-2026-51895MEDIUMRagflow 0.24.0 and prior contains improper access control in update_metadata_setting (api/apps/kb_app.py). Depending on the exposed entry, aEPSS 0.2%CVE-2026-74991MEDIUMWPForms Lite 1.8.8.2 - 2.0.1.1 - Unauthenticated Stripe Refund and Subscription Cancellation via External PaymentIntentEPSS 0.2%CVE-2023-35062MEDIUMImproper access control in some Intel(R) DSA software before version 23.4.33 may allow a privileged user to potentially enable escalation ofEPSS 0.2%CVE-2026-51896MEDIUMinfiniflow ragflow 0.25.3 contains improper access control in resume (api/apps/connector_app.py). Depending on the exposed entry, an attackeEPSS 0.2%CVE-2026-60775MEDIUMVulnerability in the Pasta product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12EPSS 0.2%CVE-2026-70698MEDIUMVulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Install). The supported version tEPSS 0.2%CVE-2022-36865MEDIUMImproper access control in Group Sharing prior to versions 13.0.6.15 in Android S(12), 13.0.6.14 in Android R(11) and below allows attackersEPSS 0.2%CVE-2025-65798MEDIUMIncorrect access control in usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily modify or delete attachments maEPSS 0.2%CVE-2025-31195MEDIUMThe issue was addressed by adding additional logic. This issue is fixed in macOS Sequoia 15.4. An app may be able to break out of its sandboEPSS 0.2%CVE-2024-39934HIGHRobotmk before 2.0.1 allows a local user to escalate privileges (e.g., to SYSTEM) if automated Python environment setup is enabled, because EPSS 0.2%CVE-2026-7373HIGHMetasploit Pro on Windows: Local Privilege Escalation via OpenSSL Configuration File LoadingEPSS 0.2%CVE-2022-36866MEDIUMImproper access control vulnerability in Broadcaster in Group Sharing prior to versions 13.0.6.15 in Android S(12), 13.0.6.14 in Android R(1EPSS 0.2%CVE-2025-61761MEDIUMVulnerability in the PeopleSoft Enterprise FIN Maintenance Management product of Oracle PeopleSoft (component: Work Order Management). TheEPSS 0.2%CVE-2025-65963MEDIUMCFiles Unauthorized Folder/ZIP Access in Public SpacesEPSS 0.2%CVE-2026-91077LOWEvent Booking Manager for WooCommerce 5.3.6 - 5.7.2 - Contributor+ Unpublished Event Disclosure via mpwem_load_event_listEPSS 0.2%CVE-2023-27391MEDIUMImproper access control in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.1.493 may allow a privileged usEPSS 0.2%CVE-2025-30138MEDIUMAn issue was discovered on G-Net Dashcam BB GONX devices. Managing Settings and Obtaining Sensitive Data and Sabotaging Car Battery can be pEPSS 0.2%CVE-2023-42542LOWImproper access control vulnerability in Samsung Push Service prior to 3.4.10 allows local attackers to get register ID to identify the deviEPSS 0.2%CVE-2023-28714HIGHImproper access control in firmware for some Intel(R) PROSet/Wireless WiFi software for Windows before version 22.220 HF (Hot Fix) may allowEPSS 0.2%