Falhas do tipo CWE-288

675 resultados

Controle de acesso inadequado

Ocorre quando o software falha em validar ou aplicar corretamente permissões e autorizações, permitindo que usuários acessem recursos ou executem ações que não deveriam ter permissão. A falha pode estar na autenticação (verificar quem é o usuário), autorização (verificar o que ele pode fazer) ou em ambas, expondo dados sensíveis ou permitindo operações não autorizadas.

Exemplo

Um sistema de gestão de documentos onde a aplicação valida se o usuário está logado, mas não verifica se ele realmente tem permissão para acessar o arquivo solicitado. Um atacante logado consegue alternar o ID do documento na URL e ler ou deletar arquivos de outros usuários.

Como mitigar

Implemente verificações de autorização em todo ponto onde dados sensíveis são acessados ou ações críticas ocorrem — nunca confie apenas no front-end ou em obscuridade de IDs. Use um modelo de controle de acesso bem definido (RBAC, ABAC), validando permissões no servidor antes de retornar dados ou executar operações, e auditando acessos sensíveis.

CVE-2026-18577HIGHIncomplete patch leads to administrative account takeoverEPSS 54.1%KEVCVE-2024-23917CRITICALIn JetBrains TeamCity before 2023.11.3 authentication bypass leading to RCE was possibleEPSS 54.0%CVE-2017-5174An Authentication Bypass issue was discovered in Geutebruck IP Camera G-Cam/EFD-2250 Version 1.11.0.12. An authentication bypass vulnerabiliEPSS 52.3%CVE-2026-10523CRITICALAn Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthentEPSS 51.9%CVE-2024-7314CRITICALanji-plus AJ-Report Authentication BypassEPSS 51.7%CVE-2024-33610CRITICAL"sessionlist.html" and "sys_trayentryreboot.html" are accessible with no authentication. "sessionlist.html" provides logged-in users' sessioEPSS 50.0%CVE-2023-2982CRITICALWordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) <= 7.6.4 - Authentication BypassEPSS 46.2%CVE-2023-2986CRITICALAbandoned Cart Lite for WooCommerce <= 5.15.1 - Authentication BypassEPSS 42.5%CVE-2026-18556HIGHUnauthenticated administrative account takeoverEPSS 40.2%KEVCVE-2022-25369CRITICALAn issue was discovered in Dynamicweb before 9.12.8. An attacker can add a new administrator user without authentication. This flaw exists dEPSS 40.0%CVE-2024-10081CRITICALCodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. Authentication bypasEPSS 39.9%CVE-2024-47010HIGHPath Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to bypass authentication.EPSS 37.8%CVE-2025-34143CRITICALETQ Reliance CG Authentication Bypass via Trailing Space RCEEPSS 32.7%CVE-2024-13181HIGHPath Traversal in Ivanti Avalanche before version 6.4.7 allows a remote unauthenticated attacker to bypass authentication. This CVE addresseEPSS 32.4%CVE-2023-20269MEDIUMA vulnerability in the remote access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTDEPSS 25.5%KEVCVE-2024-39309CRITICALZDI-CAN-23894: Parse Server literalizeRegexPart SQL Injection Authentication Bypass VulnerabilityEPSS 20.2%CVE-2024-2056CRITICALArtica Proxy Loopback Services Remotely Accessible UnauthenticatedEPSS 16.7%CVE-2026-7567CRITICALTemporary Login <= 1.0.0 - Authentication Bypass to Account TakeoverEPSS 9.2%CVE-2026-34040HIGHMoby: AuthZ plugin bypass with oversized request bodyEPSS 9.1%CVE-2018-19000LCDS Laquis SCADA prior to version 4.1.0.4150 allows an authentication bypass, which may allow an attacker access to sensitive data.EPSS 8.8%