Falhas do tipo CWE-284

7.088 resultados

Controle de acesso inadequado a recursos

A aplicação falha em validar ou aplica incorretamente as restrições de acesso, permitindo que usuários não autorizados acessem dados ou funcionalidades que deveriam estar protegidas. É uma das fragilidades mais comuns em segurança: o código não verifica corretamente quem está pedindo acesso e simplesmente concede.

Exemplo

Um e-commerce que permite acessar o perfil de qualquer cliente substituindo o ID na URL (ex: /usuario/123 → /usuario/124), sem validar se o usuário autenticado é o dono daquele perfil. Um atacante consegue ver dados pessoais, histórico de compras e endereços de outras pessoas.

Como mitigar

Implemente verificações explícitas em cada acesso a recurso: autentique o usuário, identifique qual recurso ele quer acessar, e valide se as permissões dele cobrem aquele recurso específico. Use listas de controle de acesso (ACLs) ou papéis (RBAC/ABAC) consistentemente em toda a API ou aplicação, nunca deixando a segurança implícita.

CVE-2025-31698HIGHApache Traffic Server: Client IP address from PROXY protocol is not used for ACLEPSS 0.6%CVE-2025-59500HIGHAzure Notification Service Elevation of Privilege VulnerabilityEPSS 0.6%CVE-2022-32834MEDIUMAn access issue was addressed with improvements to the sandbox. This issue is fixed in macOS Monterey 12.5, macOS Big Sur 11.6.8, Security UEPSS 0.6%CVE-2023-51070HIGHAn access control issue in QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 allows unauthenticated attackers to arbitrarily adjusEPSS 0.6%CVE-2025-1834MEDIUMzj1983 zz resolve unrestricted uploadEPSS 0.6%CVE-2025-0346MEDIUMcode-projects Content Management System Publish News Page publishnews.php unrestricted uploadEPSS 0.6%CVE-2023-21905MEDIUMVulnerability in the Oracle Banking Virtual Account Management product of Oracle Financial Services Applications (component: Routing Hub). EPSS 0.6%CVE-2024-45122MEDIUMAdobe Commerce | Improper Access Control (CWE-284)EPSS 0.6%CVE-2026-2666MEDIUMmingSoft MCMS Template Archive uploadTemplate.do unrestricted uploadEPSS 0.6%CVE-2024-36080CRITICALWestermo EDW-100 devices through 2024-05-03 have a hidden root user account with a hardcoded password that cannot be changed. NOTE: this is EPSS 0.6%CVE-2026-28699HIGHGitea Basic Auth bypasses OAuth2 access token scopesEPSS 0.6%CVE-2025-66430CRITICALPlesk 18.0 has Incorrect Access Control.EPSS 0.6%CVE-2024-42559CRITICALAn issue in the login component (process_login.php) of Hotel Management System commit 79d688 allows attackers to authenticate without providEPSS 0.6%CVE-2024-38873MEDIUMAn issue was discovered in the friendlycaptcha_official (aka Integration of Friendly Captcha) extension before 0.1.4 for TYPO3. The extensioEPSS 0.5%CVE-2022-21586MEDIUMVulnerability in the Oracle Banking Trade Finance product of Oracle Financial Services Applications (component: Infrastructure). The supportEPSS 0.5%CVE-2022-46676MEDIUM Wyse Management Suite 3.8 and below contain an improper access control vulnerability. A malicious admin user can disable or delete users unEPSS 0.5%CVE-2022-47037HIGHSiklu TG Terragraph devices before 2.1.1 allow attackers to discover valid, randomly generated credentials via GetCredentials.EPSS 0.5%CVE-2026-86284MEDIUMjaychouchannel Tourism-Management-System CommonController.java getOption information disclosureEPSS 0.5%CVE-2022-46677MEDIUM Wyse Management Suite 3.8 and below contain an improper access control vulnerability with which an custom group admin can create a subgroupEPSS 0.5%CVE-2026-44774MEDIUMTraefik: Gateway API TraefikService backend accepts rest@internal, allowing unauthorized exposure of the REST provider despite providers.rest.insecure=falseEPSS 0.5%