Falhas do tipo CWE-284

7.078 resultados

Controle de acesso inadequado a recursos

A aplicação falha em validar ou aplica incorretamente as restrições de acesso, permitindo que usuários não autorizados acessem dados ou funcionalidades que deveriam estar protegidas. É uma das fragilidades mais comuns em segurança: o código não verifica corretamente quem está pedindo acesso e simplesmente concede.

Exemplo

Um e-commerce que permite acessar o perfil de qualquer cliente substituindo o ID na URL (ex: /usuario/123 → /usuario/124), sem validar se o usuário autenticado é o dono daquele perfil. Um atacante consegue ver dados pessoais, histórico de compras e endereços de outras pessoas.

Como mitigar

Implemente verificações explícitas em cada acesso a recurso: autentique o usuário, identifique qual recurso ele quer acessar, e valide se as permissões dele cobrem aquele recurso específico. Use listas de controle de acesso (ACLs) ou papéis (RBAC/ABAC) consistentemente em toda a API ou aplicação, nunca deixando a segurança implícita.

CVE-2024-57190CRITICALErxes <1.6.1 is vulnerable to Incorrect Access Control. An attacker can bypass authentication by providing a "User" HTTP header that containEPSS 0.6%CVE-2026-81941HIGHLangflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guardsEPSS 0.6%CVE-2025-24968HIGHBusiness Logic And Unrestricted Project Deletion Lead To Take Over the System in reNgineEPSS 0.6%CVE-2025-4977MEDIUMNetgear DGND3700 BRS_top.html information disclosureEPSS 0.6%CVE-2024-0631MEDIUMDuitku Payment Gateway <= 2.11.6 - Missing Authorization via check_duitku_responseEPSS 0.6%CVE-2022-44211HIGHIn GL.iNet Goodcloud 1.1 Incorrect access control allows a remote attacker to access/change devices' settings.EPSS 0.6%CVE-2025-4980MEDIUMNetgear DGND3700 mini_http currentsetting.htm information disclosureEPSS 0.6%CVE-2023-5240—Improper access control in PAM propagation scripts in Devolutions Server 2023.2.8.0 and ealier allows an attack with permission to manage PAEPSS 0.6%CVE-2025-4271MEDIUMTOTOLINK A720R cstecgi.cgi information disclosureEPSS 0.6%CVE-2022-41970LOWNextcloud Server's disabled download shares still allow download through preview imagesEPSS 0.6%CVE-2022-4567HIGHImproper Access Control in openemr/openemrEPSS 0.6%CVE-2025-48986HIGHAuthorization bypass in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes an logged in attacker to change other users' email addreEPSS 0.6%CVE-2026-51679CRITICALIncorrect access control in the setPasswordCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to change the EPSS 0.6%CVE-2023-40170MEDIUMcross-site inclusion (XSSI) of files in jupyter-serverEPSS 0.6%CVE-2022-28173CRITICALThe web server of some Hikvision wireless bridge products have an access control vulnerability which can be used to obtain the admin permissEPSS 0.6%CVE-2024-31964HIGHA vulnerability on Mitel 6800 Series and 6900 Series SIP Phones through 6.3 SP3 HF4, 6900w Series SIP Phone through 6.3.3, and 6970 ConferenEPSS 0.6%CVE-2024-21074HIGHVulnerability in the Oracle Trade Management product of Oracle E-Business Suite (component: Finance LOV). Supported versions that are affecEPSS 0.6%CVE-2025-30710MEDIUMVulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: NDBCluster Plugin). Supported versions that are affected arEPSS 0.6%CVE-2024-42480HIGHKamaji's RBAC Roles for `etcd` are not disjunctEPSS 0.6%CVE-2026-90898CRITICALBifrost unauthenticated remote code execution via MCP stdio client registrationEPSS 0.6%