Falhas do tipo CWE-285

1.605 resultados

Falha na verificação de autorização

A aplicação não valida (ou valida incorretamente) se um usuário tem permissão para acessar um recurso ou executar uma ação. Um atacante contorna controles de acesso acessando dados, executando operações ou alterando funcionalidades que deveria estar restrito à sua role ou nível de privilégio.

Exemplo

Uma API de admin que exclui usuários verifica se o token é válido, mas nunca confirma se quem faz a requisição é realmente administrador. Um usuário comum envia a mesma requisição e consegue deletar contas — porque a autorização não foi checada.

Como mitigar

Implemente verificações de autorização em todo ponto de acesso sensível: valide permissões não só na camada de apresentação, mas no backend, consulte ACLs/roles antes de cada operação crítica e use frameworks de autorização testados. Nunca confie em verificações do lado do cliente.

CVE-2026-49278MEDIUMRocket.Chat: Livechat Visitor Profile Disclosure Leaks Bearer Token and Enables Visitor ImpersonationEPSS 0.4%CVE-2025-5182MEDIUMSummer Pearl Group Vacation Rental Management Platform Listing authorizationEPSS 0.4%CVE-2026-73644CRITICALOpenDJ: Authorization bypass in SASL PLAIN allowing a `proxied-auth` holder to impersonate any resolvable non-root user without an ACI proxy grantEPSS 0.4%CVE-2026-95805MEDIUMMISP ACLComponent: Typo in previewEventAttributes ACL key bypasses intended access restrictionEPSS 0.4%CVE-2026-64743MEDIUMAn authorization issue was addressed with improved state management. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPaEPSS 0.4%CVE-2026-35407MEDIUMSaleor has Cross-Account Email Change via Unbound Confirmation TokenEPSS 0.4%CVE-2026-2109MEDIUMjsbroks COCO Annotator Delete Category undo improper authorizationEPSS 0.4%CVE-2024-39418MEDIUMAdobe Commerce | Improper Authorization (CWE-285)EPSS 0.4%CVE-2024-13821MEDIUMWP Booking Calendar <= 10.10 - Unauthenticated Post-Confirmation Booking ManipulationEPSS 0.4%CVE-2025-2600MEDIUMImproper authorization in the variable component in Devolutions Remote Desktop Manager on Windows allows an authenticated user to use the ELEPSS 0.4%CVE-2026-19838MEDIUMWebkul Bagisto Backend Reporting Endpoint sales authorizationEPSS 0.4%CVE-2026-19836MEDIUMWebkul Bagisto Backend Customer Detail Feature view authorizationEPSS 0.4%CVE-2022-31669MEDIUMHarbor fails to validate the user permissions when updating tag immutability policiesEPSS 0.4%CVE-2026-44715HIGHOpenMRS has Broken Access Control in HL7 ConfigurationEPSS 0.4%CVE-2026-30847CRITICALWekan Credential Leak via notificationUsers Publication Exposes Password Hashes and Session TokensEPSS 0.4%CVE-2026-84076HIGHIBM Guardium Data Protection is affected by multiple vulnerabilities.EPSS 0.4%CVE-2026-47663HIGHPathling: Typed CRUD/search/batch providers can lead to server-wide PHI exfiltration and cross-resource mutationEPSS 0.4%CVE-2026-55428HIGHCoder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinatorEPSS 0.4%CVE-2026-6584MEDIUMTransformerOptimus SuperAGI User Update Endpoint user.py update_user authorizationEPSS 0.4%CVE-2026-6585MEDIUMTransformerOptimus SuperAGI Organisation Update Endpoint organisation.py update_organisation authorizationEPSS 0.4%