Falhas do tipo CWE-285

1.587 resultados

Falha na verificação de autorização

A aplicação não valida (ou valida incorretamente) se um usuário tem permissão para acessar um recurso ou executar uma ação. Um atacante contorna controles de acesso acessando dados, executando operações ou alterando funcionalidades que deveria estar restrito à sua role ou nível de privilégio.

Exemplo

Uma API de admin que exclui usuários verifica se o token é válido, mas nunca confirma se quem faz a requisição é realmente administrador. Um usuário comum envia a mesma requisição e consegue deletar contas — porque a autorização não foi checada.

Como mitigar

Implemente verificações de autorização em todo ponto de acesso sensível: valide permissões não só na camada de apresentação, mas no backend, consulte ACLs/roles antes de cada operação crítica e use frameworks de autorização testados. Nunca confie em verificações do lado do cliente.

CVE-2019-13416—Search Guard versions before 24.3 had an issue when Cross Cluster Search (CCS) was enabled, authenticated users are always authorized on theEPSS 1.0%CVE-2021-21432HIGHReject unauthorized access with GitHub PATsEPSS 1.0%CVE-2017-0892—Nextcloud Server before 11.0.3 is vulnerable to an improper session handling allowed an application specific password without permission to EPSS 1.0%CVE-2025-23042HIGHGradio Blocked Path ACL Bypass VulnerabilityEPSS 1.0%CVE-2021-42330HIGHShinHer Information Co., LTD. ShinHer StudyOnline System - Improper Authorization-1EPSS 1.0%CVE-2020-5240HIGH2FA bypass through deleting devices in wagtail-2faEPSS 1.0%CVE-2022-31025LOWInvite bypasses user approval in DiscourseEPSS 1.0%CVE-2025-48063MEDIUMXWiki Platform Security Authorization Bridge allows users with just edit right can enforce required rights with programming rightEPSS 1.0%CVE-2019-13554—GE Mark VIe Controller has an unsecured Telnet protocol that may allow a user to create an authenticated session using generic default credeEPSS 1.0%CVE-2025-24418HIGHAdobe Commerce | Improper Authorization (CWE-285)EPSS 1.0%CVE-2022-31247CRITICALRancher: Downstream cluster privilege escalation through cluster and project role template binding (CRTB/PRTB)EPSS 1.0%CVE-2021-22861—Improper access control in GitHub Enterprise Server leading to unauthorized write access to forkable repositoriesEPSS 1.0%CVE-2022-26857CRITICALDell OpenManage Enterprise Versions 3.8.3 and prior contain an improper authorization vulnerability. A remote authenticated malicious user wEPSS 0.9%CVE-2023-3805HIGHXiamen Four Letter Video Surveillance Management System Login UserInfoAction.class improper authorizationEPSS 0.9%CVE-2026-58277HIGHMicrosoft SharePoint Elevation of Privilege VulnerabilityEPSS 0.9%CVE-2022-39341MEDIUMOpenFGA Authorization BypassEPSS 0.9%CVE-2022-39342MEDIUMOpenFGA Authorization BypassEPSS 0.9%CVE-2017-2589HIGHIt was discovered that the hawtio servlet 1.4 uses a single HttpClient instance to proxy requests with a persistent cookie store (cookies arEPSS 0.9%CVE-2018-0393—A Read-Only User Effect Change vulnerability in the Policy Builder interface of Cisco Policy Suite could allow an authenticated, remote attaEPSS 0.9%CVE-2021-3616CRITICALA vulnerability was reported in Lenovo Smart Camera X3, X5, and C2E that could allow an unauthorized user to view device information, alter EPSS 0.9%