Falhas do tipo CWE-288

678 resultados

Controle de acesso inadequado

Ocorre quando o software falha em validar ou aplicar corretamente permissões e autorizações, permitindo que usuários acessem recursos ou executem ações que não deveriam ter permissão. A falha pode estar na autenticação (verificar quem é o usuário), autorização (verificar o que ele pode fazer) ou em ambas, expondo dados sensíveis ou permitindo operações não autorizadas.

Exemplo

Um sistema de gestão de documentos onde a aplicação valida se o usuário está logado, mas não verifica se ele realmente tem permissão para acessar o arquivo solicitado. Um atacante logado consegue alternar o ID do documento na URL e ler ou deletar arquivos de outros usuários.

Como mitigar

Implemente verificações de autorização em todo ponto onde dados sensíveis são acessados ou ações críticas ocorrem — nunca confie apenas no front-end ou em obscuridade de IDs. Use um modelo de controle de acesso bem definido (RBAC, ABAC), validando permissões no servidor antes de retornar dados ou executar operações, e auditando acessos sensíveis.

CVE-2022-23720HIGHPingID Windows Login prior to 2.8 does not alert or halt operation if it has been provisioned with the full permissions PingID properties fileEPSS 0.2%CVE-2026-0602MEDIUMAuthentication Bypass Using an Alternate Path or Channel in GitLabEPSS 0.2%CVE-2025-40743HIGHA vulnerability has been identified in SINUMERIK 828D PPU.4 (All versions < V4.95 SP5), SINUMERIK 828D PPU.5 (All versions < V5.25 SP1), SINEPSS 0.2%CVE-2026-81796HIGHWordPress WP Travel plugin <= 12.0.3 - Broken Authentication vulnerabilityEPSS 0.2%CVE-2026-84777HIGHWordPress Really Simple SSL plugin <= 9.8.0 - 2FA Bypass vulnerabilityEPSS 0.2%CVE-2026-82225HIGHWordPress RegistrationMagic plugin <= 6.0.9.8 - Broken Authentication vulnerabilityEPSS 0.2%CVE-2026-50194HIGHSteeltoe vulnerable to management-port isolation bypass via spoofed Host headerEPSS 0.2%CVE-2026-42745HIGHWordPress Smart Online Order for Clover plugin <= 1.6.0 - Broken Authentication vulnerabilityEPSS 0.2%CVE-2025-40761HIGHA vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions), RUGGEDCOM ROX MX5000RE (All versions), RUGGEDCOM ROX RX1400 (AllEPSS 0.2%CVE-2026-18636MEDIUMVelociraptor VFSGetBuffer API path deny list bypassEPSS 0.2%CVE-2026-12703HIGHBypass of 2FA for Connections via Unattended Access in TeamViewer for macOSEPSS 0.2%CVE-2020-11005MEDIUMInternal NCryptDecrypt method could be used externally from WindowsHello library.EPSS 0.2%CVE-2022-22189HIGHContrail Service Orchestration: An authenticated local user may have their permissions elevated via the device via management interface without authenticationEPSS 0.2%CVE-2026-81783HIGHWordPress MailMunch – Grow your Email List plugin <= 3.2.5 - Broken Authentication vulnerabilityEPSS 0.2%CVE-2026-47200MEDIUMNuxt: Route middleware not enforced when rendering `.server.vue` pages via `/__nuxt_island/page_*`EPSS 0.2%CVE-2026-1747MEDIUMAuthentication Bypass Using an Alternate Path or Channel in GitLabEPSS 0.2%CVE-2025-13986MEDIUMDisable Login Page - Critical - Access bypass - SA-CONTRIB-2025-124EPSS 0.2%CVE-2026-3035MEDIUMAuthentication Bypass Using an Alternate Path or Channel in GitLabEPSS 0.2%CVE-2025-3652MEDIUMPetlibro Smart Pet Feeder Platform through 1.7.31 Audio Information Disclosure via API endpointEPSS 0.2%CVE-2026-35654MEDIUMOpenClaw < 2026.3.25 - Authorization Bypass in Microsoft Teams Feedback InvokeEPSS 0.2%