Falhas do tipo CWE-284

7.169 resultados

Controle de acesso inadequado a recursos

A aplicação falha em validar ou aplica incorretamente as restrições de acesso, permitindo que usuários não autorizados acessem dados ou funcionalidades que deveriam estar protegidas. É uma das fragilidades mais comuns em segurança: o código não verifica corretamente quem está pedindo acesso e simplesmente concede.

Exemplo

Um e-commerce que permite acessar o perfil de qualquer cliente substituindo o ID na URL (ex: /usuario/123 → /usuario/124), sem validar se o usuário autenticado é o dono daquele perfil. Um atacante consegue ver dados pessoais, histórico de compras e endereços de outras pessoas.

Como mitigar

Implemente verificações explícitas em cada acesso a recurso: autentique o usuário, identifique qual recurso ele quer acessar, e valide se as permissões dele cobrem aquele recurso específico. Use listas de controle de acesso (ACLs) ou papéis (RBAC/ABAC) consistentemente em toda a API ou aplicação, nunca deixando a segurança implícita.

CVE-2023-3039HIGH SD ROM Utility, versions prior to 1.0.2.0 contain an Improper Access Control vulnerability. A low-privileged malicious user may potentiallyEPSS 0.2%CVE-2022-41621LOWImproper access control in some Intel(R) QAT drivers for Windows before version 1.9.0 may allow an authenticated user to potentially enable EPSS 0.2%CVE-2026-70991MEDIUMVulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content AcquiEPSS 0.2%CVE-2023-20587HIGHImproper Access Control in System Management Mode (SMM) may allow an attacker access to the SPI flash potentially leading to arbitrary code EPSS 0.2%CVE-2026-96281MEDIUMFlatpak: flatpak: unprivileged active user can bypass anti-downgrade checks for system apps/runtimesEPSS 0.2%CVE-2025-64715MEDIUMCilium with misconfigured toGroups in policies can lead to unrestricted egress trafficEPSS 0.2%CVE-2022-39857HIGHImproper access control vulnerability in CameraTestActivity in FactoryCameraFB prior to version 3.5.51 allows attackers to access broadcastiEPSS 0.2%CVE-2022-41261MEDIUMSAP Solution Manager (Diagnostic Agent) - version 7.20, allows an authenticated attacker on Windows system to access a file containing sensiEPSS 0.2%CVE-2021-43986MEDIUMICSA-22-109-03 FANUC ROBOGUIDE Simulation PlatformEPSS 0.2%CVE-2022-39889MEDIUMImproper access control vulnerability in GalaxyWatch4Plugin prior to versions 2.2.11.22101351 and 2.2.12.22101351 allows attackers to accessEPSS 0.2%CVE-2022-36789HIGHImproper access control in BIOS firmware for some Intel(R) NUC 10 Performance Kits and Intel(R) NUC 10 Performance Mini PCs before version FEPSS 0.2%CVE-2024-40858HIGHA permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.1. An app may be able to access ContEPSS 0.2%CVE-2026-20638MEDIUMA logic issue was addressed with improved checks. This issue is fixed in iOS 26.3 and iPadOS 26.3. A user with Live Caller ID app extensionsEPSS 0.2%CVE-2025-60865HIGHInsecure Permissions vulnerability in avanquest Driver Updater v.9.1.57803.1174 allows a local attacker to escalate privileges via the DriveEPSS 0.2%CVE-2023-32477HIGH Dell Common Event Enabler 8.9.8.2 for Windows and prior, contain an improper access control vulnerability. A local low-privileged maliciousEPSS 0.2%CVE-2026-82745MEDIUMETS and Mnesia data layers overwrite an existing record on create instead of enforcing primary-key uniquenessEPSS 0.2%CVE-2024-25576HIGHimproper access control in firmware for some Intel(R) FPGA products before version 24.1 may allow a privileged user to enable escalation of EPSS 0.2%CVE-2025-69988MEDIUMBS Producten Petcam 33.1.0.0818 is vulnerable to Incorrect Access Control. An unauthenticated attacker in physical proximity can associate wEPSS 0.2%CVE-2022-39878MEDIUMImproper access control vulnerability in Samsung Checkout prior to version 5.0.55.3 allows attackers to access sensitive information via impEPSS 0.2%CVE-2022-46279MEDIUMImproper access control in the Intel(R) Retail Edge android application before version 3.0.301126-RELEASE may allow an authenticated user toEPSS 0.2%