Falhas do tipo CWE-284

7.170 resultados

Controle de acesso inadequado a recursos

A aplicação falha em validar ou aplica incorretamente as restrições de acesso, permitindo que usuários não autorizados acessem dados ou funcionalidades que deveriam estar protegidas. É uma das fragilidades mais comuns em segurança: o código não verifica corretamente quem está pedindo acesso e simplesmente concede.

Exemplo

Um e-commerce que permite acessar o perfil de qualquer cliente substituindo o ID na URL (ex: /usuario/123 → /usuario/124), sem validar se o usuário autenticado é o dono daquele perfil. Um atacante consegue ver dados pessoais, histórico de compras e endereços de outras pessoas.

Como mitigar

Implemente verificações explícitas em cada acesso a recurso: autentique o usuário, identifique qual recurso ele quer acessar, e valide se as permissões dele cobrem aquele recurso específico. Use listas de controle de acesso (ACLs) ou papéis (RBAC/ABAC) consistentemente em toda a API ou aplicação, nunca deixando a segurança implícita.

CVE-2026-60630MEDIUMVulnerability in Oracle APEX (component: Installation). Supported versions that are affected are 24.1, 24.2 and 26.1. Easily exploitable vEPSS 0.2%CVE-2026-62564MEDIUMVulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). TheEPSS 0.2%CVE-2025-50777HIGHThe firmware of the AZIOT 2MP Full HD Smart Wi-Fi CCTV Home Security Camera (version V1.00.02) contains an Incorrect Access Control vulnerabEPSS 0.2%CVE-2024-28170LOWImproper access control in Intel(R) RAID Web Console all versions may allow an authenticated user to potentially enable information disclosuEPSS 0.2%CVE-2025-43393MEDIUMA permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Tahoe 26.1. An app may be able to breakEPSS 0.2%CVE-2025-43313MEDIUMA logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7EPSS 0.2%CVE-2026-12460MEDIUMInsufficient policy enforcement in File System Access in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who had compromisedEPSS 0.2%CVE-2026-22628MEDIUMAn improper access control vulnerability in Fortinet FortiSwitchAXFixed 1.0.0 through 1.0.1 may allow an authenticated admin to execute systEPSS 0.2%CVE-2026-15430MEDIUMCVE-2026-15430EPSS 0.2%CVE-2025-61760HIGHVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.EPSS 0.2%CVE-2026-85004MEDIUMPopup Maker WP <= 1.4.5 - Subscriber+ Missing Authorization via sgpm_connectEPSS 0.2%CVE-2024-34022MEDIUMImproper Access Control in some Thunderbolt(TM) Share software before version 1.0.49.9 may allow an authenticated user to potentially enableEPSS 0.2%CVE-2026-92989MEDIUMSendPress Newsletters <= 1.26.1.20 - Subscriber+ Mailing List Sync and Newsletter QueueingEPSS 0.2%CVE-2026-103681MEDIUMFrontend Dashboard < 3.0.0 - Subscriber+ Profile and Post Field Deletion via fed_user_profile_deleteEPSS 0.2%CVE-2026-58043HIGHA flaw in Node.js Permission Model enforcement can over-grant filesystem access across radix-tree prefix boundaries. Under `--permission`EPSS 0.2%CVE-2023-27301MEDIUMImproper access control in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenticated user to potentEPSS 0.2%CVE-2026-60642HIGHVulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are EPSS 0.2%CVE-2023-21491HIGHImproper access control vulnerability in ThemeManager prior to SMR May-2023 Release 1 allows local attackers to write arbitrary files with sEPSS 0.2%CVE-2026-45313HIGHSandboxie-Plus: Sandboxie APC Injection Sandbox EscapeEPSS 0.2%CVE-2026-11187MEDIUMInappropriate implementation in Glic in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass navigation restrictions viaEPSS 0.2%