Falhas do tipo CWE-284

7.078 resultados

Controle de acesso inadequado a recursos

A aplicação falha em validar ou aplica incorretamente as restrições de acesso, permitindo que usuários não autorizados acessem dados ou funcionalidades que deveriam estar protegidas. É uma das fragilidades mais comuns em segurança: o código não verifica corretamente quem está pedindo acesso e simplesmente concede.

Exemplo

Um e-commerce que permite acessar o perfil de qualquer cliente substituindo o ID na URL (ex: /usuario/123 → /usuario/124), sem validar se o usuário autenticado é o dono daquele perfil. Um atacante consegue ver dados pessoais, histórico de compras e endereços de outras pessoas.

Como mitigar

Implemente verificações explícitas em cada acesso a recurso: autentique o usuário, identifique qual recurso ele quer acessar, e valide se as permissões dele cobrem aquele recurso específico. Use listas de controle de acesso (ACLs) ou papéis (RBAC/ABAC) consistentemente em toda a API ou aplicação, nunca deixando a segurança implícita.

CVE-2025-28411CRITICALAn issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the editSave method in /tool/gen/editSaveEPSS 0.6%CVE-2025-28412CRITICALAn issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the /editSave method in SysNoticeControllerEPSS 0.6%CVE-2025-28410CRITICALAn issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the cancelAuthUserAll method does not properly validate whetheEPSS 0.6%CVE-2025-28405CRITICALAn issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the changeStatus methodEPSS 0.6%CVE-2024-23663HIGHAn improper access control in Fortinet FortiExtender 4.1.1 - 4.1.9, 4.2.0 - 4.2.6, 5.3.2, 7.0.0 - 7.0.4, 7.2.0 - 7.2.4 and 7.4.0 - 7.4.2 allEPSS 0.6%CVE-2025-28408CRITICALAn issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the selectDeptTree method of the /selectDeptTree/{deptId} endpEPSS 0.6%CVE-2022-0143CRITICALLDAP Connector: When startTLS is used then LDAP connector ignores the wrong passwordEPSS 0.6%CVE-2025-28402CRITICALAn issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the jobId parameterEPSS 0.6%CVE-2025-43198CRITICALThis issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7. An app may be ableEPSS 0.6%CVE-2026-39386HIGHNeko has Self-service Privilege Escalation for Authenticated UsersEPSS 0.6%CVE-2024-43716MEDIUMAdobe Experience Manager | Improper Access Control (CWE-284)EPSS 0.6%CVE-2024-41249HIGHAn Incorrect Access Control vulnerability was found in /smsa/view_subject.php in Kashipara Responsive School Management System v3.2.0, whichEPSS 0.6%CVE-2024-1011MEDIUMSourceCodester Employee Management System Leave delete-leave.php access controlEPSS 0.6%CVE-2024-24568MEDIUMSuricata http2: header handling evasionEPSS 0.6%CVE-2024-43717MEDIUMAdobe Experience Manager | Improper Access Control (CWE-284)EPSS 0.6%CVE-2025-2991MEDIUMTenda FH1202 Web Management Interface AdvSetWrlmacfilter access controlEPSS 0.6%CVE-2023-26473MEDIUMXWiki Platform allows unprivileged users to make arbitrary select queries using DatabaseListProperty and suggest.vmEPSS 0.6%CVE-2025-3666MEDIUMTOTOLINK A3700R cstecgi.cgi setDdnsCfg access controlEPSS 0.6%CVE-2025-47884CRITICALIn Jenkins OpenID Connect Provider Plugin 96.vee8ed882ec4d and earlier the generation of build ID Tokens uses potentially overridden values EPSS 0.6%CVE-2026-2667MEDIUMRongzhitong Visual Integrated Command and Dispatch Platform api access controlEPSS 0.6%