Falhas do tipo CWE-288

675 resultados

Controle de acesso inadequado

Ocorre quando o software falha em validar ou aplicar corretamente permissões e autorizações, permitindo que usuários acessem recursos ou executem ações que não deveriam ter permissão. A falha pode estar na autenticação (verificar quem é o usuário), autorização (verificar o que ele pode fazer) ou em ambas, expondo dados sensíveis ou permitindo operações não autorizadas.

Exemplo

Um sistema de gestão de documentos onde a aplicação valida se o usuário está logado, mas não verifica se ele realmente tem permissão para acessar o arquivo solicitado. Um atacante logado consegue alternar o ID do documento na URL e ler ou deletar arquivos de outros usuários.

Como mitigar

Implemente verificações de autorização em todo ponto onde dados sensíveis são acessados ou ações críticas ocorrem — nunca confie apenas no front-end ou em obscuridade de IDs. Use um modelo de controle de acesso bem definido (RBAC, ABAC), validando permissões no servidor antes de retornar dados ou executar operações, e auditando acessos sensíveis.

CVE-2017-9944A vulnerability has been identified in Siemens 7KT PAC1200 data manager (7KT1260) in all versions < V2.03. The integrated web server (port 8EPSS 3.0%CVE-2022-0992CRITICALSiteGround Security <= 1.2.5 - Authentication Bypass via 2FA SetupEPSS 2.9%CVE-2023-3277CRITICALMStore API <= 4.10.7 - Unauthorized Account Access and Privilege EscalationEPSS 2.9%CVE-2020-15633HIGHThis vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-867, DIR-878, and DIR-EPSS 2.8%CVE-2018-4852A vulnerability has been identified in SICLOCK TC100 (All versions) and SICLOCK TC400 (All versions). An attacker with network access to theEPSS 2.7%CVE-2020-27865HIGHThis vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1860 firmware versionEPSS 2.6%CVE-2026-24207CRITICALNVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an authentication bypass. A successful exploit of thisEPSS 2.6%CVE-2020-14485OpenClinic GA versions 5.09.02 and 5.89.05b may allow an attacker to bypass client-side access controls or use a crafted request to initiateEPSS 2.5%CVE-2019-13526Datalogic AV7000 Linear barcode scanner all versions prior to 4.6.0.0 is vulnerable to authentication bypass, which may allow an attacker toEPSS 2.4%CVE-2026-28411CRITICALWeGIA Vulnerable to Authentication Bypass via `extract($_REQUEST)`EPSS 2.3%CVE-2020-6091CRITICALAn exploitable authentication bypass vulnerability exists in the ESPON Web Control functionality of Epson EB-1470Ui MAIN: 98009273ESWWV107 MEPSS 2.3%CVE-2016-9497Hughes high-performance broadband satellite modems, models HN7740S DW7000 HN7000S/SM, is vulnerable to an authentication bypass using an alternate path or channelEPSS 2.2%CVE-2019-5165HIGHAn exploitable authentication bypass vulnerability exists in the hostname processing of the Moxa AWK-3131A firmware version 1.13. A speciallEPSS 2.1%CVE-2025-22462CRITICALAn authentication bypass in Ivanti Neurons for ITSM (on-prem only) before 2023.4, 2024.2 and 2024.3 with the May 2025 Security Patch allows EPSS 2.1%CVE-2025-27129CRITICALAn authentication bypass vulnerability exists in the HTTP authentication functionality of Tenda AC6 V5.0 V02.03.01.110. A specially crafted EPSS 2.1%CVE-2024-9933CRITICALWatchTowerHQ <= 3.10.1 - Authentication Bypass to Administrator due to Missing Empty Value CheckEPSS 2.0%CVE-2024-28200CRITICALN-central Authentication BypassEPSS 1.9%CVE-2022-1681HIGHAuthentication Bypass Using an Alternate Path or Channel in requarks/wikiEPSS 1.9%CVE-2025-0364CRITICALBigAntSoft BigAnt Server Account Registration Bypass to File Upload RCEEPSS 1.9%CVE-2023-2834CRITICALBookIt <= 2.3.7 - Authentication BypassEPSS 1.9%