Falhas do tipo CWE-285

1.609 resultados

Falha na verificação de autorização

A aplicação não valida (ou valida incorretamente) se um usuário tem permissão para acessar um recurso ou executar uma ação. Um atacante contorna controles de acesso acessando dados, executando operações ou alterando funcionalidades que deveria estar restrito à sua role ou nível de privilégio.

Exemplo

Uma API de admin que exclui usuários verifica se o token é válido, mas nunca confirma se quem faz a requisição é realmente administrador. Um usuário comum envia a mesma requisição e consegue deletar contas — porque a autorização não foi checada.

Como mitigar

Implemente verificações de autorização em todo ponto de acesso sensível: valide permissões não só na camada de apresentação, mas no backend, consulte ACLs/roles antes de cada operação crítica e use frameworks de autorização testados. Nunca confie em verificações do lado do cliente.

CVE-2020-9081LOWThere is an improper authorization vulnerability in some Huawei smartphones. An attacker could perform a series of operation in specific modEPSS 0.2%CVE-2026-2209MEDIUMWeKan Custom Translation translationBody.js setCreateTranslation improper authorizationEPSS 0.2%CVE-2025-66291MEDIUMOrangeHRM is Vulnerable to Improper Authorization Allowing Unauthorized Access to Interview AttachmentsEPSS 0.2%CVE-2022-36837MEDIUMIntent redirection vulnerability using implicit intent in Samsung email prior to version 6.1.70.20 allows attacker to get sensitive informatEPSS 0.2%CVE-2021-44204—Local privilege escalation via named pipe due to improper access control checksEPSS 0.2%CVE-2023-28378MEDIUMImproper authorization in some Intel(R) QAT drivers for Windows - HW Version 2.0 before version 2.0.4 may allow an authenticated user to potEPSS 0.2%CVE-2026-18175HIGHIBM i is Affected By Improper Authorization and Authentication Vulnerabilities in DDM / DRDA [, ]EPSS 0.2%CVE-2025-22171MEDIUMJira Align is vulnerable to an authorization issue. A low-privilege user is able to alter the private checklists of other users.EPSS 0.2%CVE-2024-36438HIGHeLinkSmart Hidden Smart Cabinet Lock 2024-05-22 has Incorrect Access Control and fails to perform an authorization check which can lead to cEPSS 0.2%CVE-2026-2294MEDIUMUiPress lite | Effortless custom dashboards, admin themes and pages <= 3.5.09 - Missing Authorization to Authenticated (Subscriber+) Plugin Settings UpdateEPSS 0.2%CVE-2025-66290MEDIUMOrangeHRM is Vulnerable to Improper Authorization Allowing Unauthorized Access to Candidate AttachmentsEPSS 0.2%CVE-2026-61082MEDIUMVulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 9.7.0-9.7.EPSS 0.2%CVE-2023-42973MEDIUMPrivate Browsing tabs may be accessed without authentication. This issue is fixed in iOS 17 and iPadOS 17. The issue was addressed with imprEPSS 0.2%CVE-2022-34434MEDIUMCloud Mobility for Dell Storage versions 1.3.0 and earlier contains an Improper Access Control vulnerability within the Postgres database. AEPSS 0.2%CVE-2026-13514LOWChess Play and Learn App com.chess AndroidManifest.xml backupEPSS 0.2%CVE-2025-22239HIGHCVE-2025-22239 salt advisoryEPSS 0.2%CVE-2025-65963MEDIUMCFiles Unauthorized Folder/ZIP Access in Public SpacesEPSS 0.2%CVE-2023-28385HIGHImproper authorization in the Intel(R) NUC Pro Software Suite for Windows before version 2.0.0.9 may allow a privileged user to potentially EPSS 0.2%CVE-2025-43403MEDIUMAn authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOSEPSS 0.2%CVE-2026-44362MEDIUMOP-TEE's subkey rollback protection can be bypassed with older subkey versionsEPSS 0.2%