Falhas do tipo CWE-284

7.074 resultados

Controle de acesso inadequado a recursos

A aplicação falha em validar ou aplica incorretamente as restrições de acesso, permitindo que usuários não autorizados acessem dados ou funcionalidades que deveriam estar protegidas. É uma das fragilidades mais comuns em segurança: o código não verifica corretamente quem está pedindo acesso e simplesmente concede.

Exemplo

Um e-commerce que permite acessar o perfil de qualquer cliente substituindo o ID na URL (ex: /usuario/123 → /usuario/124), sem validar se o usuário autenticado é o dono daquele perfil. Um atacante consegue ver dados pessoais, histórico de compras e endereços de outras pessoas.

Como mitigar

Implemente verificações explícitas em cada acesso a recurso: autentique o usuário, identifique qual recurso ele quer acessar, e valide se as permissões dele cobrem aquele recurso específico. Use listas de controle de acesso (ACLs) ou papéis (RBAC/ABAC) consistentemente em toda a API ou aplicação, nunca deixando a segurança implícita.

CVE-2025-24259CRITICALThis issue was addressed with additional entitlement checks. This issue is fixed in iPadOS 17.7.7, macOS Sequoia 15.4, macOS Sonoma 14.7.5, EPSS 0.8%CVE-2023-1862HIGHRemote access to warp-svc.exe in Cloudflare WARPEPSS 0.8%CVE-2022-31257—A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23.31), Mendix Applications using Mendix 8 (AllEPSS 0.8%CVE-2025-63223CRITICALThe Axel Technology StreamerMAX MK II devices (firmware versions 0.8.5 to 1.0.3) are vulnerable to Broken Access Control due to missing authEPSS 0.8%CVE-2025-43232CRITICALA permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS VenturEPSS 0.8%CVE-2025-3790MEDIUMbaseweb JSite Apache Druid Monitoring Console index.html access controlEPSS 0.8%CVE-2026-39006CRITICALAn issue in SNMP4J-Agent 3.8.3 allows a remote attacker to execute arbitrary code via the snmp4jCfgStoragePath component.EPSS 0.8%CVE-2024-49044MEDIUMVisual Studio Elevation of Privilege VulnerabilityEPSS 0.8%CVE-2014-8183HIGHIt was found that foreman, versions 1.x.x before 1.15.6, in Satellite 6 did not properly enforce access controls on certain resources. An atEPSS 0.7%CVE-2025-54603CRITICALAn incorrect OIDC authentication flow in Claroty Secure Access 3.3.0 through 4.0.2 can result in unauthorized user creation or impersonationEPSS 0.7%CVE-2022-23241HIGHClustered Data ONTAP versions 9.11.1 through 9.11.1P2 with SnapLock configured FlexGroups are susceptible to a vulnerability which could allEPSS 0.7%CVE-2022-41652MEDIUMWordPress Quiz And Survey Master plugin <= 7.3.10 - Bypass vulnerabilityEPSS 0.7%CVE-2022-24924LOWAn improper access control in LiveWallpaperService prior to versions 3.0.9.0 allows to create a specific named system directory without a prEPSS 0.7%CVE-2021-41543—A vulnerability has been identified in Climatix POL909 (AWB module) (All versions < V11.44), Climatix POL909 (AWM module) (All versions < V1EPSS 0.7%CVE-2022-44014MEDIUMAn issue was discovered in Simmeth Lieferantenmanager before 5.6. In the design of the API, a user is inherently able to fetch arbitrary SQLEPSS 0.7%CVE-2023-30587HIGHA vulnerability in Node.js version 20 allows for bypassing restrictions set by the --experimental-permission flag using the built-in inspectEPSS 0.7%CVE-2018-15372—Cisco IOS XE Software MACsec MKA Using EAP-TLS Authentication Bypass VulnerabilityEPSS 0.7%CVE-2026-75465HIGHThe /api.php/user/get_list endpoint in Maccms v10 v2026.1000.4055 is vulnerable to an Incorrect Access Control issue. The interface fails toEPSS 0.7%CVE-2023-2903MEDIUMNFine Rapid Development Platform access controlEPSS 0.7%CVE-2023-28645MEDIUMSecure view can be bypassed by using internal API endpoint in Nextcloud richdocumentsEPSS 0.7%