Falhas do tipo CWE-284

7.070 resultados

Controle de acesso inadequado a recursos

A aplicação falha em validar ou aplica incorretamente as restrições de acesso, permitindo que usuários não autorizados acessem dados ou funcionalidades que deveriam estar protegidas. É uma das fragilidades mais comuns em segurança: o código não verifica corretamente quem está pedindo acesso e simplesmente concede.

Exemplo

Um e-commerce que permite acessar o perfil de qualquer cliente substituindo o ID na URL (ex: /usuario/123 → /usuario/124), sem validar se o usuário autenticado é o dono daquele perfil. Um atacante consegue ver dados pessoais, histórico de compras e endereços de outras pessoas.

Como mitigar

Implemente verificações explícitas em cada acesso a recurso: autentique o usuário, identifique qual recurso ele quer acessar, e valide se as permissões dele cobrem aquele recurso específico. Use listas de controle de acesso (ACLs) ou papéis (RBAC/ABAC) consistentemente em toda a API ou aplicação, nunca deixando a segurança implícita.

CVE-2023-41772HIGHWin32k Elevation of Privilege VulnerabilityEPSS 11.8%CVE-2025-3663MEDIUMTOTOLINK A3700R Password cstecgi.cgi setWiFiEasyGuestCfg access controlEPSS 11.3%CVE-2026-33478CRITICALAVideo Multi-Chain Attack: Unauthenticated Remote Code Execution via Clone Key Disclosure, Database Dump, and Command InjectionEPSS 11.2%CVE-2022-20780CRITICALCisco Enterprise NFV Infrastructure Software VulnerabilitiesEPSS 11.2%CVE-2022-20777CRITICALCisco Enterprise NFV Infrastructure Software VulnerabilitiesEPSS 11.1%CVE-2025-2993MEDIUMTenda FH1202 default.cfg access controlEPSS 10.9%CVE-2018-10630—For Crestron TSW-X60 version prior to 2.001.0037.001 and MC3 version prior to 1.502.0047.001, The devices are shipped with authentication diEPSS 10.9%CVE-2025-2546MEDIUMD-Link DIR-618/DIR-605L Firewall Service formAdvFirewall access controlEPSS 10.8%CVE-2024-1675HIGHInsufficient policy enforcement in Download in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass filesystem restrictiEPSS 10.6%CVE-2022-20779CRITICALCisco Enterprise NFV Infrastructure Software VulnerabilitiesEPSS 10.5%CVE-2023-28810MEDIUMSome access control/intercom products have unauthorized modification of device network configuration vulnerabilities. Attackers can modify dEPSS 10.4%CVE-2018-7364HIGHAll versions up to ZXINOS-RESV1.01.43 of the ZTE ZXIN10 product European region are impacted by improper access control vulnerability. Due tEPSS 10.3%CVE-2023-26347HIGHCVE-2023-38205 issues | ColdFusion Admin Panel AccessEPSS 10.1%CVE-2025-48999MEDIUMDataease Redshift Data Source JDBC Connection Parameters Not Verified Leads to RCE VulnerabilityEPSS 10.0%CVE-2021-24215—Controlled Admin Access < 1.5.2 - Improper Access Control & Privilege EscalationEPSS 9.7%CVE-2026-35616CRITICALA improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attacker to execute unauEPSS 9.1%KEVCVE-2022-1631MEDIUMUsers Account Pre-Takeover or Users Account Takeover. in microweber/microweberEPSS 8.8%CVE-2017-12171MEDIUMA regression was found in the Red Hat Enterprise Linux 6.9 version of httpd 2.2.15-60, causing comments in the "Allow" and "Deny" configuratEPSS 8.1%CVE-2019-11634CRITICALCitrix Workspace App before 1904 for Windows has Incorrect Access Control.EPSS 8.0%KEVCVE-2018-15640HIGHImproper access control in the Helpdesk App of Odoo Enterprise 10.0 through 12.0 allows remote authenticated attackers to obtain elevated prEPSS 7.8%