Falhas do tipo CWE-284

7.169 resultados

Controle de acesso inadequado a recursos

A aplicação falha em validar ou aplica incorretamente as restrições de acesso, permitindo que usuários não autorizados acessem dados ou funcionalidades que deveriam estar protegidas. É uma das fragilidades mais comuns em segurança: o código não verifica corretamente quem está pedindo acesso e simplesmente concede.

Exemplo

Um e-commerce que permite acessar o perfil de qualquer cliente substituindo o ID na URL (ex: /usuario/123 → /usuario/124), sem validar se o usuário autenticado é o dono daquele perfil. Um atacante consegue ver dados pessoais, histórico de compras e endereços de outras pessoas.

Como mitigar

Implemente verificações explícitas em cada acesso a recurso: autentique o usuário, identifique qual recurso ele quer acessar, e valide se as permissões dele cobrem aquele recurso específico. Use listas de controle de acesso (ACLs) ou papéis (RBAC/ABAC) consistentemente em toda a API ou aplicação, nunca deixando a segurança implícita.

CVE-2026-61313MEDIUMVulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is aEPSS 0.2%CVE-2026-60884MEDIUMVulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Panel Processor). Supported versions that aEPSS 0.2%CVE-2026-71145MEDIUMVulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is EPSS 0.2%CVE-2022-3746MEDIUMA potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevatEPSS 0.2%CVE-2022-37410HIGHImproper access control for some Intel(R) Thunderbolt driver software before version 89 may allow an authenticated user to potentially enablEPSS 0.2%CVE-2023-28051HIGH Dell Power Manager, versions 3.10 and prior, contains an Improper Access Control vulnerability. A low-privileged attacker could potentiallyEPSS 0.2%CVE-2022-38466—A vulnerability has been identified in CoreShield One-Way Gateway (OWG) Software (All versions < V2.2). The default installation sets insecuEPSS 0.2%CVE-2025-43328LOWA permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26. An app may be able to access sensitivEPSS 0.2%CVE-2025-57197MEDIUMIn the Payeer Android application 2.5.0, an improper access control vulnerability exists in the authentication flow for the PIN change featuEPSS 0.2%CVE-2022-43702—Incomplete verification of installation file signatureEPSS 0.2%CVE-2026-71084MEDIUMVulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/ODBC). The supported version that is affected is 26.7.EPSS 0.2%CVE-2024-30211MEDIUMImproper access control in some Intel(R) ME driver pack installer engines before version 2422.6.2.0 may allow an authenticated user to potenEPSS 0.2%CVE-2025-69634CRITICALCross Site Request Forgery vulnerability in Dolibarr ERP & CRM v.22.0.9 allows a remote attacker to escalate privileges via the notes field EPSS 0.2%CVE-2026-28833MEDIUMA permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, visionOS EPSS 0.2%CVE-2025-2954MEDIUMmannaandpoem OpenManus File file_saver.py execute access controlEPSS 0.2%CVE-2023-21457MEDIUMImproper access control vulnerability in Bluetooth prior to SMR Mar-2023 Release 1 allows attackers to send file via Bluetooth without relatEPSS 0.2%CVE-2023-42969LOWAn app may be able to break out of its sandbox. This issue is fixed in iOS 17 and iPadOS 17, iOS 16.7 and iPadOS 16.7, macOS Sonoma 14, macOEPSS 0.2%CVE-2026-104678LOWCP Media Player < 1.3.4 - Contributor+ Media Player Settings UpdateEPSS 0.2%CVE-2024-27792MEDIUMThis issue was addressed by adding an additional prompt for user consent. This issue is fixed in macOS Sonoma 14.4. An app may be able to acEPSS 0.2%CVE-2023-31271MEDIUMImproper access control in some Intel(R) VROC software before version 8.0.8.1001 may allow an authenticated user to potentially enable escalEPSS 0.2%