Falhas do tipo CWE-284

7.170 resultados

Controle de acesso inadequado a recursos

A aplicação falha em validar ou aplica incorretamente as restrições de acesso, permitindo que usuários não autorizados acessem dados ou funcionalidades que deveriam estar protegidas. É uma das fragilidades mais comuns em segurança: o código não verifica corretamente quem está pedindo acesso e simplesmente concede.

Exemplo

Um e-commerce que permite acessar o perfil de qualquer cliente substituindo o ID na URL (ex: /usuario/123 → /usuario/124), sem validar se o usuário autenticado é o dono daquele perfil. Um atacante consegue ver dados pessoais, histórico de compras e endereços de outras pessoas.

Como mitigar

Implemente verificações explícitas em cada acesso a recurso: autentique o usuário, identifique qual recurso ele quer acessar, e valide se as permissões dele cobrem aquele recurso específico. Use listas de controle de acesso (ACLs) ou papéis (RBAC/ABAC) consistentemente em toda a API ou aplicação, nunca deixando a segurança implícita.

CVE-2026-92989MEDIUMSendPress Newsletters <= 1.26.1.20 - Subscriber+ Mailing List Sync and Newsletter QueueingEPSS 0.2%CVE-2026-46848HIGHVulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 14.EPSS 0.2%CVE-2026-45313HIGHSandboxie-Plus: Sandboxie APC Injection Sandbox EscapeEPSS 0.2%CVE-2024-29077MEDIUMImproper access control in some JAM STAPL Player software before version 2.6.1 may allow an authenticated user to potentially enable escalatEPSS 0.2%CVE-2026-58043HIGHA flaw in Node.js Permission Model enforcement can over-grant filesystem access across radix-tree prefix boundaries. Under `--permission`EPSS 0.2%CVE-2024-34022MEDIUMImproper Access Control in some Thunderbolt(TM) Share software before version 1.0.49.9 may allow an authenticated user to potentially enableEPSS 0.2%CVE-2026-20603MEDIUMThis issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Tahoe 26.3. An app with root privileEPSS 0.2%CVE-2023-21442MEDIUMImproper access control vulnerability in Runestone application prior to version 2.9.09.003 in Android R(11) and 3.2.01.007 in Android S(12) EPSS 0.2%CVE-2026-47007HIGHVulnerability in the Oracle Communications Pricing Design Center product of Oracle Communications (component: On-premise Deployment). SuppoEPSS 0.2%CVE-2026-71154MEDIUMVulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected aEPSS 0.2%CVE-2026-70838MEDIUMVulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is EPSS 0.2%CVE-2023-21495MEDIUMImproper access control vulnerability in Knox Enrollment Service prior to SMR May-2023 Release 1 allow attacker install KSP app when device EPSS 0.2%CVE-2026-61339HIGHVulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that EPSS 0.2%CVE-2023-21493MEDIUMImproper access control vulnerability in SemShareFileProvider prior to SMR May-2023 Release 1 allows local attackers to access protected datEPSS 0.2%CVE-2023-26596LOWImproper access control in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenticated user to potentEPSS 0.2%CVE-2023-27509MEDIUMImproper access control in some Intel(R) ISPC software installers before version 1.19.0 may allow an authenticated user to potentially enablEPSS 0.2%CVE-2026-41993MEDIUMImproper Access Control vulnerability in the Removable Media Validation function of TXOne Networks products allows a local attacker with admEPSS 0.1%CVE-2025-46307MEDIUMA logic issue was addressed with improved restrictions. This issue is fixed in macOS Tahoe 26. An app may be able to access sensitive user dEPSS 0.1%CVE-2024-27200MEDIUMImproper access control in some Intel(R) Granulate(TM) software before version 4.30.1 may allow a authenticated user to potentially enable eEPSS 0.1%CVE-2022-21950MEDIUMcanna: unsafe handling of /tmp/.iroha_unix directoryEPSS 0.1%