Falhas do tipo CWE-285

1.605 resultados

Falha na verificação de autorização

A aplicação não valida (ou valida incorretamente) se um usuário tem permissão para acessar um recurso ou executar uma ação. Um atacante contorna controles de acesso acessando dados, executando operações ou alterando funcionalidades que deveria estar restrito à sua role ou nível de privilégio.

Exemplo

Uma API de admin que exclui usuários verifica se o token é válido, mas nunca confirma se quem faz a requisição é realmente administrador. Um usuário comum envia a mesma requisição e consegue deletar contas — porque a autorização não foi checada.

Como mitigar

Implemente verificações de autorização em todo ponto de acesso sensível: valide permissões não só na camada de apresentação, mas no backend, consulte ACLs/roles antes de cada operação crítica e use frameworks de autorização testados. Nunca confie em verificações do lado do cliente.

CVE-2025-43289MEDIUMA logic issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26. A maliciEPSS 0.1%CVE-2026-2974LOWAliasVault App Backup aliasvault.xml backupEPSS 0.1%CVE-2026-47053MEDIUMVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.EPSS 0.1%CVE-2025-68712MEDIUMSpSoft AppLock (com.sp.protector.free) 7.9.40 for Android allows a local attacker with physical access to bypass fingerprint or PIN authentiEPSS 0.1%CVE-2026-60842MEDIUMVulnerability in the Oracle Knowledge Management product of Oracle E-Business Suite (component: Search). Supported versions that are affectEPSS 0.1%CVE-2023-44123MEDIUMBluetooth - Theft and (over-)write of arbitrary files with system privilege via PendingIntent hijackingEPSS 0.1%CVE-2023-24476LOWPTC Vuforia Studio Improper AuthorizationEPSS 0.1%CVE-2025-8532MEDIUMIDOR in Bimser's eBA Document and Workflow Management SystemEPSS 0.1%CVE-2023-44125MEDIUMPersonalized service - Theft and (over-)write of arbitrary files with system privilege via PendingIntent hijackingEPSS 0.1%CVE-2026-21097MEDIUMImproper authentication in ActivityTaskManagerService prior to SMR Sep-2026 Release 1 allows local privileged attackers to launch arbitrary EPSS 0.1%CVE-2023-28556HIGHImproper Authorization in HLOSEPSS 0.1%CVE-2026-0072CRITICALIn addInputMethodListener of com.android.server.inputmethod.InputMethodManagerService, there is a missing permission check. This could lead EPSS 0.1%CVE-2026-60957MEDIUMVulnerability in the Oracle Transportation Execution product of Oracle E-Business Suite (component: Internal Operations). Supported versionEPSS 0.1%CVE-2026-60911MEDIUMVulnerability in the Oracle Property Manager product of Oracle E-Business Suite (component: Internal Operations). Supported versions that aEPSS 0.1%CVE-2026-20656LOWA logic issue was addressed with improved validation. This issue is fixed in Safari 26.3, iOS 18.7.5 and iPadOS 18.7.5, macOS Tahoe 26.3. AnEPSS 0.1%CVE-2026-62563MEDIUMVulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). Supported versions that arEPSS 0.1%CVE-2022-39905MEDIUMImplicit intent hijacking vulnerability in Telecom application prior to SMR Dec-2022 Release 1 allows attacker to access sensitive informatiEPSS 0.1%CVE-2021-25459MEDIUMAn improper access control vulnerability in sspInit() in BlockchainTZService prior to SMR Sep-2021 Release 1 allows attackers to start BlockEPSS 0.1%CVE-2026-20666MEDIUMAn authorization issue was addressed with improved state management. This issue is fixed in macOS Tahoe 26.3. An app may be able to access sEPSS 0.1%CVE-2024-51525MEDIUMPermission control vulnerability in the clipboard module Impact: Successful exploitation of this vulnerability may affect service confidentiEPSS 0.1%