Falhas do tipo CWE-284

7.078 resultados

Controle de acesso inadequado a recursos

A aplicação falha em validar ou aplica incorretamente as restrições de acesso, permitindo que usuários não autorizados acessem dados ou funcionalidades que deveriam estar protegidas. É uma das fragilidades mais comuns em segurança: o código não verifica corretamente quem está pedindo acesso e simplesmente concede.

Exemplo

Um e-commerce que permite acessar o perfil de qualquer cliente substituindo o ID na URL (ex: /usuario/123 → /usuario/124), sem validar se o usuário autenticado é o dono daquele perfil. Um atacante consegue ver dados pessoais, histórico de compras e endereços de outras pessoas.

Como mitigar

Implemente verificações explícitas em cada acesso a recurso: autentique o usuário, identifique qual recurso ele quer acessar, e valide se as permissões dele cobrem aquele recurso específico. Use listas de controle de acesso (ACLs) ou papéis (RBAC/ABAC) consistentemente em toda a API ou aplicação, nunca deixando a segurança implícita.

CVE-2017-8447—An error was found in the X-Pack Security 5.3.0 to 5.5.2 privilege enforcement. If a user has either 'delete' or 'index' permissions on an iEPSS 0.6%CVE-2023-32279HIGHImproper access control in user mode driver for some Intel(R) Connectivity Performance Suite before version 2.1123.214.2 may allow unauthentEPSS 0.6%CVE-2025-3664MEDIUMTOTOLINK A3700R cstecgi.cgi setWiFiEasyGuestCfg access controlEPSS 0.6%CVE-2019-1649MEDIUMCisco Secure Boot Hardware Tampering VulnerabilityEPSS 0.6%CVE-2024-9321MEDIUMSourceCodester Online Railway Reservation System view_details.php access controlEPSS 0.6%CVE-2025-3665MEDIUMTOTOLINK A3700R cstecgi.cgi setSmartQosCfg access controlEPSS 0.6%CVE-2026-9495MEDIUMVersions of the package @koa/router from 14.0.0 and before 15.0.0 are vulnerable to Access Control Bypass due to the middleware being silentEPSS 0.6%CVE-2026-52111CRITICALAn issue in fast-note-sync-service <=2.13.7 allows a remote attacker to escalate privileges via the admin configuration endpoint exposes autEPSS 0.6%CVE-2026-72600HIGHIdurar IDURAR ERP CRM - Broken Access ControlEPSS 0.6%CVE-2023-2674HIGHImproper Access Control in openemr/openemrEPSS 0.6%CVE-2024-36443HIGHSwissphone DiCal-RED 4009 devices allow a remote attacker to gain read access to almost the whole file system via anonymous FTP.EPSS 0.6%CVE-2022-27673HIGHInsufficient access controls in the AMD Link Android app may potentially result in information disclosure.EPSS 0.6%CVE-2026-72601HIGHCSZ CMS CSZ CMS - Broken Access ControlEPSS 0.6%CVE-2023-31138HIGHDHIS2 Core vulnerable to Improper Access Control with PATCH requestsEPSS 0.6%CVE-2025-62713HIGHKottster app reinitialization can be re-triggered allowing command injection in development modeEPSS 0.6%CVE-2023-49791MEDIUMWorkflows do not require password confirmation on API levelEPSS 0.6%CVE-2023-33947LOWThe Object module in Liferay Portal 7.4.3.4 through 7.4.3.60, and Liferay DXP 7.4 before update 61 does not segment object definition by virEPSS 0.6%CVE-2025-58752LOWVite's `server.fs` settings were not applied to HTML filesEPSS 0.6%CVE-2022-28759HIGHZoom On-Premise Deployments: Improper Access ControlEPSS 0.6%CVE-2024-30059MEDIUMMicrosoft Intune for Android Mobile Application Management Tampering VulnerabilityEPSS 0.6%