Falhas do tipo CWE-285

1.609 resultados

Falha na verificação de autorização

A aplicação não valida (ou valida incorretamente) se um usuário tem permissão para acessar um recurso ou executar uma ação. Um atacante contorna controles de acesso acessando dados, executando operações ou alterando funcionalidades que deveria estar restrito à sua role ou nível de privilégio.

Exemplo

Uma API de admin que exclui usuários verifica se o token é válido, mas nunca confirma se quem faz a requisição é realmente administrador. Um usuário comum envia a mesma requisição e consegue deletar contas — porque a autorização não foi checada.

Como mitigar

Implemente verificações de autorização em todo ponto de acesso sensível: valide permissões não só na camada de apresentação, mas no backend, consulte ACLs/roles antes de cada operação crítica e use frameworks de autorização testados. Nunca confie em verificações do lado do cliente.

CVE-2025-67603MEDIUMLack of client authorization allows arbitrary users to influence the firewall configurationEPSS 0.2%CVE-2026-20661MEDIUMAn authorization issue was addressed with improved state management. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOEPSS 0.2%CVE-2025-9988MEDIUMBroadstreet <= 1.53.1 - Missing Authorization to Authenticated (Subscriber+) Advertiser CreationEPSS 0.2%CVE-2026-43756MEDIUMA logic issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. AnEPSS 0.2%CVE-2025-40830HIGHA vulnerability has been identified in SINEC Security Monitor (All versions < V4.10.0). The affected application does not have proper authorEPSS 0.2%CVE-2022-45128MEDIUMImproper authorization in the Intel(R) EMA software before version 1.9.0.0 may allow an authenticated user to potentially enable denial of sEPSS 0.2%CVE-2022-43465MEDIUMImproper authorization in the Intel(R) SCS software all versions may allow an authenticated user to potentially enable denial of service viaEPSS 0.2%CVE-2022-41610MEDIUMImproper authorization in Intel(R) EMA Configuration Tool before version 1.0.4 and Intel(R) MC before version 2.4 software may allow an authEPSS 0.2%CVE-2023-21429MEDIUMImproper usage of implict intent in ePDG prior to SMR JAN-2023 Release 1 allows attacker to access SSID.EPSS 0.2%CVE-2025-65107MEDIUMLangfuse SSO Account Takeover via CSRF or phishing attackEPSS 0.2%CVE-2023-21432MEDIUMImproper access control vulnerabilities in Smart Things prior to 1.7.93 allows to attacker to invite others without authorization of the ownEPSS 0.2%CVE-2026-43775MEDIUMAn authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.8, macOS Tahoe 26.6. An app mEPSS 0.2%CVE-2026-64711MEDIUMThis issue was addressed with additional entitlement checks. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS SoEPSS 0.2%CVE-2023-21424MEDIUMImproper Handling of Insufficient Permissions or Privileges vulnerability in SemChameleonHelper prior to SMR Jan-2023 Release 1 allows attacEPSS 0.2%CVE-2023-21422MEDIUMImproper authorization vulnerability in semAddPublicDnsAddr in WifiSevice prior to SMR Jan-2023 Release 1 allows attackers to set custom DNSEPSS 0.1%CVE-2023-21423MEDIUMImproper authorization vulnerability in ChnFileShareKit prior to SMR Jan-2023 Release 1 allows attacker to control BLE advertising without pEPSS 0.1%CVE-2023-21436LOWImproper usage of implicit intent in Contacts prior to SMR Feb-2023 Release 1 allows attacker to get account ID.EPSS 0.1%CVE-2026-17483MEDIUMIBM Db2 Mirror for i is affected by multiple vulnerabilities [, , ]EPSS 0.1%CVE-2023-21452LOWImproper usage of implicit intent in Bluetooth prior to SMR Mar-2023 Release 1 allows attacker to get MAC address of connected device.EPSS 0.1%CVE-2023-28973HIGHJunos OS Evolved: The 'sysmanctl' shell command allows a local user to gain access to some administrative actions EPSS 0.1%