Falhas do tipo CWE-284

7.088 resultados

Controle de acesso inadequado a recursos

A aplicação falha em validar ou aplica incorretamente as restrições de acesso, permitindo que usuários não autorizados acessem dados ou funcionalidades que deveriam estar protegidas. É uma das fragilidades mais comuns em segurança: o código não verifica corretamente quem está pedindo acesso e simplesmente concede.

Exemplo

Um e-commerce que permite acessar o perfil de qualquer cliente substituindo o ID na URL (ex: /usuario/123 → /usuario/124), sem validar se o usuário autenticado é o dono daquele perfil. Um atacante consegue ver dados pessoais, histórico de compras e endereços de outras pessoas.

Como mitigar

Implemente verificações explícitas em cada acesso a recurso: autentique o usuário, identifique qual recurso ele quer acessar, e valide se as permissões dele cobrem aquele recurso específico. Use listas de controle de acesso (ACLs) ou papéis (RBAC/ABAC) consistentemente em toda a API ou aplicação, nunca deixando a segurança implícita.

CVE-2022-46755MEDIUM Wyse Management Suite 3.8 and below contain an improper access control vulnerability. A authenticated malicious admin user can edit generalEPSS 0.5%CVE-2025-15597MEDIUMDataease SQLBot API Endpoint assistant.py access controlEPSS 0.5%CVE-2022-21586MEDIUMVulnerability in the Oracle Banking Trade Finance product of Oracle Financial Services Applications (component: Infrastructure). The supportEPSS 0.5%CVE-2026-81046CRITICALDell ThinOS 10, versions prior to 2605_10.2616, contain a Protection Mechanism Failure vulnerability. An unauthenticated attacker with remotEPSS 0.5%CVE-2022-46677MEDIUM Wyse Management Suite 3.8 and below contain an improper access control vulnerability with which an custom group admin can create a subgroupEPSS 0.5%CVE-2024-24485HIGHAn issue discovered in silex technology DS-600 Firmware v.1.4.1 allows a remote attacker to obtain sensitive information via the GET EEP_DATEPSS 0.5%CVE-2019-10168HIGHThe virConnectBaselineHypervisorCPU() and virConnectCompareHypervisorCPU() libvirt APIs, 4.x.x before 4.10.1 and 5.x.x before 5.4.1, accept EPSS 0.5%CVE-2024-41245HIGHAn Incorrect Access Control vulnerability was found in /smsa/view_teachers.php in Kashipara Responsive School Management System v3.2.0, whicEPSS 0.5%CVE-2024-8164MEDIUMChengdu Everbrite Network Technology BeikeShop FileManagerController.php rename unrestricted uploadEPSS 0.5%CVE-2024-25120MEDIUMImproper Access Control of Resources Referenced by t3:// URI Scheme in TYPO3EPSS 0.5%CVE-2026-77557CRITICALA malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Protect AI Key to escalatEPSS 0.5%CVE-2026-60372CRITICALVulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). SupporEPSS 0.5%CVE-2026-8147HIGHAuthorization Bypass in mlflow/mlflowEPSS 0.5%CVE-2026-60366CRITICALVulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). SupporEPSS 0.5%CVE-2023-35167MEDIUMWhen setting EntityOptions.apiPrefilter to a function, the filter is not applied to API requests for a resource by IdEPSS 0.5%CVE-2022-43494HIGH An unauthorized user could be able to read any file on the system, potentially exposing sensitive information. EPSS 0.5%CVE-2020-27831—A flaw was found in Red Hat Quay, where it does not properly protect the authorization token when authorizing email addresses for repositoryEPSS 0.5%CVE-2024-0687MEDIUMRestrict User Access – Ultimate Membership & Content Protection <= 2.5 - Information ExposureEPSS 0.5%CVE-2022-39835MEDIUMAn issue was discovered in Gajim through 1.4.7. The vulnerability allows attackers, via crafted XML stanzas, to correct messages that were nEPSS 0.5%CVE-2023-6785MEDIUMDownload Manager <= 3.2.84 - Missing AuthorizationEPSS 0.5%