Falhas do tipo CWE-285

1.607 resultados

Falha na verificação de autorização

A aplicação não valida (ou valida incorretamente) se um usuário tem permissão para acessar um recurso ou executar uma ação. Um atacante contorna controles de acesso acessando dados, executando operações ou alterando funcionalidades que deveria estar restrito à sua role ou nível de privilégio.

Exemplo

Uma API de admin que exclui usuários verifica se o token é válido, mas nunca confirma se quem faz a requisição é realmente administrador. Um usuário comum envia a mesma requisição e consegue deletar contas — porque a autorização não foi checada.

Como mitigar

Implemente verificações de autorização em todo ponto de acesso sensível: valide permissões não só na camada de apresentação, mas no backend, consulte ACLs/roles antes de cada operação crítica e use frameworks de autorização testados. Nunca confie em verificações do lado do cliente.

CVE-2026-43983HIGHPocket ID: OIDC refresh token flow bypasses authorization revocation, account disabling, and group restrictionsEPSS 0.4%CVE-2026-54551MEDIUMWireGuard Portal: Authenticated WebSocket /api/v0/ws broadcasts all peers' and interfaces' traffic stats to every user (missing per-user authorization)EPSS 0.4%CVE-2025-60784MEDIUMA vulnerability in the XiaozhangBang Voluntary Like System V8.8 allows remote attackers to manipulate the zhekou parameter in the /topfirst.EPSS 0.4%CVE-2025-10374MEDIUMShenzhen Sixun Business Management System OperatorStop improper authorizationEPSS 0.4%CVE-2023-22938MEDIUMPermissions Validation Failure in the ‘sendemail’ REST API Endpoint in Splunk EnterpriseEPSS 0.4%CVE-2025-14546MEDIUMVersions of the package fastapi-sso before 0.19.0 are vulnerable to Cross-site Request Forgery (CSRF) due to the improper validation of the EPSS 0.4%CVE-2024-58367HIGHSurrealDB before 2.0.4 Improper Authorization via SELECT PermissionsEPSS 0.4%CVE-2025-63691CRITICALIn pig-mesh In Pig version 3.8.2 and below, within the Token Management function under the System Management module, the token query interfaEPSS 0.4%CVE-2026-28839MEDIUMThe issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app mayEPSS 0.4%CVE-2026-20285MEDIUMCisco Identity Services Engine Authorization Bypass VulnerabilityEPSS 0.4%CVE-2026-20286MEDIUMCisco Identity Services Engine Authorization Bypass VulnerabilityEPSS 0.4%CVE-2025-27399MEDIUMMastodon's domain blocks & rationales ignore user approval when visibility set as "users"EPSS 0.4%CVE-2026-75792MEDIUMIBM Sterling Secure Proxy is vulnerable to multiple issuesEPSS 0.4%CVE-2025-6713HIGHMongoDB Server may be susceptible to privilege escalation due to $mergeCursors stageEPSS 0.4%CVE-2024-38370MEDIUMGLPI allows API document download without rightsEPSS 0.4%CVE-2025-54585HIGHGitProxy is vulnerable to a new branch approval exploitEPSS 0.4%CVE-2025-20264MEDIUMCisco Identity Services Engine Authorization Bypass VulnerabilityEPSS 0.4%CVE-2026-49977MEDIUMtarteaucitron.js: data-cookie attribute can be used to delete arbitrary cookiesEPSS 0.4%CVE-2023-28584HIGHImproper Authorization in WLAN HostEPSS 0.4%CVE-2022-40521HIGHImproper authorization in ModemEPSS 0.4%