Falhas do tipo CWE-285

1.592 resultados

Falha na verificação de autorização

A aplicação não valida (ou valida incorretamente) se um usuário tem permissão para acessar um recurso ou executar uma ação. Um atacante contorna controles de acesso acessando dados, executando operações ou alterando funcionalidades que deveria estar restrito à sua role ou nível de privilégio.

Exemplo

Uma API de admin que exclui usuários verifica se o token é válido, mas nunca confirma se quem faz a requisição é realmente administrador. Um usuário comum envia a mesma requisição e consegue deletar contas — porque a autorização não foi checada.

Como mitigar

Implemente verificações de autorização em todo ponto de acesso sensível: valide permissões não só na camada de apresentação, mas no backend, consulte ACLs/roles antes de cada operação crítica e use frameworks de autorização testados. Nunca confie em verificações do lado do cliente.

CVE-2025-1847MEDIUMzj1983 zz improper authorizationEPSS 0.5%CVE-2023-1910MEDIUMGetwid – Gutenberg Blocks <= 1.8.3 - Improper Authorization via get_remote_templates REST endpointEPSS 0.5%CVE-2022-36454MEDIUMA vulnerability in the MiCollab Client API of Mitel MiCollab through 9.5.0.101 could allow an authenticated attacker to modify their profileEPSS 0.5%CVE-2025-4017MEDIUM20120630 Novel-Plus LogController.java list improper authorizationEPSS 0.5%CVE-2026-49877HIGHApache ActiveMQ: Authenticated web users retain admin access by default in the Web ConsoleEPSS 0.5%CVE-2026-45187MEDIUMApache OFBiz: Improper Authorization in Scheduled Job Creation Allows Low-Privileged Users to Submit System JobsEPSS 0.5%CVE-2025-1007MEDIUMImproper Authorization in /user/namespace/{namespace}/detailsEPSS 0.5%CVE-2026-16126MEDIUMzevorn rt-claw Swarm RPC Receiver swarm.c handle_rpc_request authorizationEPSS 0.5%CVE-2023-2345MEDIUMSourceCodester Service Provider Management System improper authorizationEPSS 0.5%CVE-2026-13549MEDIUMCodeAstro Complaint Management System Report Endpoint Report.php deletereport authorizationEPSS 0.5%CVE-2025-3587MEDIUMZeroWdd/code-projects studentmanager getTeacherList improper authorizationEPSS 0.5%CVE-2023-36611MEDIUM The affected TBox RTUs allow low privilege users to access software security tokens of higher privilege. This could allow an attacker with EPSS 0.5%CVE-2017-16726—Beckhoff TwinCAT supports communication over ADS. ADS is a protocol for industrial automation in protected environments. ADS has not been deEPSS 0.5%CVE-2026-3817MEDIUMSourceCodester Patients Waiting Area Queue Management System patient-search.php improper authorizationEPSS 0.5%CVE-2024-6000HIGHFooEvents for WooCommerce <= 1.19.20 - Improper Authorization to (Contributor+) Arbitrary File UploadEPSS 0.5%CVE-2024-23649HIGHAny authenticated user may obtain private message details from other users on the same instanceEPSS 0.5%CVE-2024-55954HIGHOpenObserve Improper Authorization Allows Admin User to Remove Root UserEPSS 0.5%CVE-2024-28285CRITICALA Fault Injection vulnerability in the SymmetricDecrypt function in cryptopp/elgamal.h of Cryptopp Crypto++ 8.9, allows an attacker to co-reEPSS 0.5%CVE-2024-0870MEDIUMYITH WooCommerce Gift Cards <= 4.12.0 - Missing Authorization to Unauthenticated WooCommerce Settings UpdateEPSS 0.5%CVE-2026-20190HIGHCisco Identity Services Engine Information Disclosure VulnerabilityEPSS 0.5%