Falhas do tipo CWE-285

1.589 resultados

Falha na verificação de autorização

A aplicação não valida (ou valida incorretamente) se um usuário tem permissão para acessar um recurso ou executar uma ação. Um atacante contorna controles de acesso acessando dados, executando operações ou alterando funcionalidades que deveria estar restrito à sua role ou nível de privilégio.

Exemplo

Uma API de admin que exclui usuários verifica se o token é válido, mas nunca confirma se quem faz a requisição é realmente administrador. Um usuário comum envia a mesma requisição e consegue deletar contas — porque a autorização não foi checada.

Como mitigar

Implemente verificações de autorização em todo ponto de acesso sensível: valide permissões não só na camada de apresentação, mas no backend, consulte ACLs/roles antes de cada operação crítica e use frameworks de autorização testados. Nunca confie em verificações do lado do cliente.

CVE-2025-53795CRITICALMicrosoft PC Manager Elevation of Privilege VulnerabilityEPSS 0.6%CVE-2024-20393HIGHCisco RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers Privilege Escalation VulnerabilityEPSS 0.6%CVE-2026-15622MEDIUMpoco-ai poco-claw Workspace API workspace.py get_workspace_file authorizationEPSS 0.6%CVE-2022-4804HIGHImproper Authorization in usememos/memosEPSS 0.6%CVE-2024-29033HIGHGoogleOAuthenticator.hosted_domain incorrectly verifies membership of an Google organization/workspaceEPSS 0.6%CVE-2023-20186HIGHA vulnerability in the Authentication, Authorization, and Accounting (AAA) feature of Cisco IOS Software and Cisco IOS XE Software could allEPSS 0.6%CVE-2024-8509HIGHMigration toolkit for virtualization: forklift-controller: empty bearer token may perform authenticationEPSS 0.6%CVE-2024-38371HIGHInsufficient access control for OAuth2 Device Code flow in authentikEPSS 0.6%CVE-2025-53106HIGHGraylog vulnerable to privilege escalation through API tokensEPSS 0.6%CVE-2026-70200CRITICALAzure Logic Apps Elevation of Privilege VulnerabilityEPSS 0.6%CVE-2026-56160CRITICALAzure Red Hat OpenShift (ARO) Elevation of Privilege VulnerabilityEPSS 0.6%CVE-2025-0928HIGHArbitrary executable upload via authenticated endpointEPSS 0.6%CVE-2021-23136MEDIUMImproper Authorization vulnerability in Gallagher Command Centre Server allows macro overrides to be performed by an unprivileged Command CeEPSS 0.6%CVE-2022-32169MEDIUMbytebase - Improper AuthorizationEPSS 0.6%CVE-2022-32170MEDIUMbytebase - Improper AuthorizationEPSS 0.6%CVE-2024-52287MEDIUMauthentik performs insufficient validation of OAuth scopesEPSS 0.6%CVE-2026-28312CRITICALSolarWinds Serv-U Privilege Escalation VulnerabilityEPSS 0.6%CVE-2024-20381HIGHCisco Network Services Orchestrator Configuration Update Authorization Bypass VulnerabilityEPSS 0.6%CVE-2026-66422HIGHApache Tomcat: Servlet role references can bypass declarative role constraintsEPSS 0.6%CVE-2024-52528CRITICALAuth Token can be passed dummy or wrong the middleware response is 200 OKEPSS 0.6%