Falhas do tipo CWE-288

675 resultados

Controle de acesso inadequado

Ocorre quando o software falha em validar ou aplicar corretamente permissões e autorizações, permitindo que usuários acessem recursos ou executem ações que não deveriam ter permissão. A falha pode estar na autenticação (verificar quem é o usuário), autorização (verificar o que ele pode fazer) ou em ambas, expondo dados sensíveis ou permitindo operações não autorizadas.

Exemplo

Um sistema de gestão de documentos onde a aplicação valida se o usuário está logado, mas não verifica se ele realmente tem permissão para acessar o arquivo solicitado. Um atacante logado consegue alternar o ID do documento na URL e ler ou deletar arquivos de outros usuários.

Como mitigar

Implemente verificações de autorização em todo ponto onde dados sensíveis são acessados ou ações críticas ocorrem — nunca confie apenas no front-end ou em obscuridade de IDs. Use um modelo de controle de acesso bem definido (RBAC, ABAC), validando permissões no servidor antes de retornar dados ou executar operações, e auditando acessos sensíveis.

CVE-2025-1638CRITICALAlloggio Membership <= 1.1 - Authentication Bypass via Social Login Account TakeoverEPSS 0.6%CVE-2026-40022HIGHApache Camel Platform HTTP Main: Authentication Bypass on Non-Root Context Paths in camel main runtimeEPSS 0.6%CVE-2025-69101CRITICALWordPress Workreap Core plugin <= 3.4.1 - Broken Authentication vulnerabilityEPSS 0.6%CVE-2025-0181CRITICALWP Foodbakery <= 4.8 - Authentication Bypass in foodbakery_parse_requestEPSS 0.6%CVE-2025-30026MEDIUMThe AXIS Camera Station Server had a flaw that allowed to bypass authentication that is normally required.EPSS 0.6%CVE-2024-47406CRITICALSharp and Toshiba Tec MFPs improperly process HTTP authentication requests, resulting in an authentication bypass vulnerability.EPSS 0.6%CVE-2024-12402CRITICALThemes Coder – Create Android & iOS Apps For Your Woocommerce Site <= 1.3.4 - Insecure Direct Object Reference to Password Change/Account Takeover/Privilege EscalationEPSS 0.6%CVE-2026-35422MEDIUMWindows TCP/IP Driver Security Feature Bypass VulnerabilityEPSS 0.6%CVE-2023-50272HIGHA potential security vulnerability has been identified in HPE Integrated Lights-Out 5 (iLO 5) and Integrated Lights-Out 6 (iLO 6). The vulneEPSS 0.6%CVE-2023-20018HIGHA vulnerability in the web-based management interface of Cisco IP Phone 7800 and 8800 Series Phones could allow an unauthenticated, remote aEPSS 0.6%CVE-2022-23722—PingFederate Password Reset via Authentication API MishandlingEPSS 0.6%CVE-2024-7503CRITICALWooCommerce - Social Login <= 2.7.5 - Authentication Bypass to Account TakeoverEPSS 0.6%CVE-2024-6684CRITICALAuthentication Bypass in GST Electronics' inohom Nova Panel N7EPSS 0.6%CVE-2025-3844CRITICALPeproDev Ultimate Profile Solutions 1.9.1 - 7.5.2 - Authentication Bypass to Account TakeoverEPSS 0.6%CVE-2024-2012CRITICALvulnerability exists in the FOXMAN-UN/UNEM server / API Gateway that if exploited an attacker could use to allow unintended commands or codEPSS 0.6%CVE-2026-57867HIGHMicroRealEstate allows adversaries to bypass authentication due to a lack of token state management. This would permit adversaries targetingEPSS 0.6%CVE-2026-62916CRITICALMicrosoft Entra ID Elevation of Privilege VulnerabilityEPSS 0.6%CVE-2025-24000HIGHWordPress Post SMTP plugin <= 3.2.0 - Account Takeover VulnerabilityEPSS 0.6%CVE-2024-37893MEDIUMMFA bypass in oauth flow in Firefly IIIEPSS 0.6%CVE-2025-53187CRITICALUnauthenticated RCEEPSS 0.6%