Falhas do tipo CWE-288

675 resultados

Controle de acesso inadequado

Ocorre quando o software falha em validar ou aplicar corretamente permissões e autorizações, permitindo que usuários acessem recursos ou executem ações que não deveriam ter permissão. A falha pode estar na autenticação (verificar quem é o usuário), autorização (verificar o que ele pode fazer) ou em ambas, expondo dados sensíveis ou permitindo operações não autorizadas.

Exemplo

Um sistema de gestão de documentos onde a aplicação valida se o usuário está logado, mas não verifica se ele realmente tem permissão para acessar o arquivo solicitado. Um atacante logado consegue alternar o ID do documento na URL e ler ou deletar arquivos de outros usuários.

Como mitigar

Implemente verificações de autorização em todo ponto onde dados sensíveis são acessados ou ações críticas ocorrem — nunca confie apenas no front-end ou em obscuridade de IDs. Use um modelo de controle de acesso bem definido (RBAC, ABAC), validando permissões no servidor antes de retornar dados ou executar operações, e auditando acessos sensíveis.

CVE-2022-2031—A flaw was found in Samba. The security vulnerability occurs when KDC and the kpasswd service share a single account and set of keys, allowiEPSS 1.2%CVE-2023-3162CRITICALStripe Payment Plugin for WooCommerce <= 3.7.7 - Authentication BypassEPSS 1.2%CVE-2023-2781HIGHUser Email Verification for WooCommerce <= 3.5.0 - Authentication BypassEPSS 1.2%CVE-2021-41292CRITICALECOA BAS controller - Broken AuthenticationEPSS 1.2%CVE-2023-22495CRITICALIzanami is vulnerable to Authorization BypassEPSS 1.1%CVE-2021-34977HIGHThis vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R7000 1.0.11.116_10.2.100EPSS 1.1%CVE-2021-32984CRITICALAutomation Direct CLICK PLC CPU Modules Authentication Bypass Using an Alternate Path or ChannelEPSS 1.1%CVE-2021-32986CRITICALAutomation Direct CLICK PLC CPU Modules Authentication Bypass Using an Alternate Path or ChannelEPSS 1.1%CVE-2021-32980CRITICALAutomation Direct CLICK PLC CPU Modules Authentication Bypass Using an Alternate Path or ChannelEPSS 1.1%CVE-2025-2492CRITICALAn improper authentication control vulnerability exists in AiCloud. This vulnerability can be triggered by a crafted request, potentially leEPSS 1.1%CVE-2024-9988CRITICALCrypto <= 2.19 - Authentication Bypass via registerEPSS 1.1%CVE-2023-3249CRITICALWeb3 – Crypto wallet Login & NFT token gating <= 2.6.0 - Authentication BypassEPSS 1.1%CVE-2024-2973CRITICALSession Smart Router(SSR): On redundant router deployments API authentication can be bypassedEPSS 1.1%CVE-2021-43935HIGHICSMA-21-343-01 Hillrom Welch Allyn Cardio ProductsEPSS 1.1%CVE-2022-27510CRITICALUnauthorized access to Gateway user capabilities EPSS 1.1%CVE-2024-9890HIGHUser Toolkit <= 1.2.3 - Authenticated (Subscriber+) Authentication BypassEPSS 1.1%CVE-2024-50334HIGHSemicolon Path Injection on API /api;/configEPSS 1.0%CVE-2020-27863MEDIUMThis vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of D-Link DVA-2800 and DSL-EPSS 1.0%CVE-2022-24813MEDIUMAuthentication Bypass Using an Alternate Path or Channel in CreateWikiEPSS 1.0%CVE-2020-13185—Certain web application pages in the authenticated section of the Teradici Cloud Access Connector prior to v18 were accessible without the nEPSS 1.0%