Falhas do tipo CWE-288

675 resultados

Controle de acesso inadequado

Ocorre quando o software falha em validar ou aplicar corretamente permissões e autorizações, permitindo que usuários acessem recursos ou executem ações que não deveriam ter permissão. A falha pode estar na autenticação (verificar quem é o usuário), autorização (verificar o que ele pode fazer) ou em ambas, expondo dados sensíveis ou permitindo operações não autorizadas.

Exemplo

Um sistema de gestão de documentos onde a aplicação valida se o usuário está logado, mas não verifica se ele realmente tem permissão para acessar o arquivo solicitado. Um atacante logado consegue alternar o ID do documento na URL e ler ou deletar arquivos de outros usuários.

Como mitigar

Implemente verificações de autorização em todo ponto onde dados sensíveis são acessados ou ações críticas ocorrem — nunca confie apenas no front-end ou em obscuridade de IDs. Use um modelo de controle de acesso bem definido (RBAC, ABAC), validando permissões no servidor antes de retornar dados ou executar operações, e auditando acessos sensíveis.

CVE-2025-5397CRITICALJobmonster - Job Board WordPress Theme <= 4.8.1 - Authentication BypassEPSS 1.0%CVE-2026-18574CRITICALAuthentication Bypass in Check Point Security Management ServerEPSS 1.0%CVE-2021-27453HIGHMesa Labs AmegaView authentication bypassEPSS 1.0%CVE-2023-2027CRITICALZM Ajax Login & Register <= 2.0.2 - Authentication BypassEPSS 1.0%CVE-2024-7781HIGHJupiter X Core <= 4.7.5 - Limited Unauthenticated Authentication Bypass to Account TakeoverEPSS 1.0%CVE-2026-27546CRITICALAuthentication Bypass in _account_logEPSS 1.0%CVE-2022-47578HIGHAn issue was discovered in the endpoint protection agent in Zoho ManageEngine Device Control Plus 10.1.2228.15. Despite configuring completeEPSS 1.0%CVE-2022-23767HIGHSecureGate authentication bypass vulnerabilityEPSS 0.9%CVE-2025-44957HIGHRuckus SmartZone (SZ) before 6.1.2p3 Refresh Build allows authentication bypass via a valid API key and crafted HTTP headers.EPSS 0.9%CVE-2024-36042CRITICALSilverpeas before 6.3.5 allows authentication bypass by omitting the Password field to AuthenticationServlet, often providing an unauthenticEPSS 0.9%CVE-2024-9822CRITICALPedalo Connector <= 2.0.5 - Authentication Bypass to AdministratorEPSS 0.9%CVE-2024-2055CRITICALArtica Proxy Unauthenticated File Manager VulnerabilityEPSS 0.9%CVE-2024-33939MEDIUMWordPress LMS by Masteriyo plugin <= 1.7.3 - Broken Authentication vulnerabilityEPSS 0.9%CVE-2024-50488HIGHWordPress Token Login plugin <= 1.0.3 - Broken Authentication vulnerabilityEPSS 0.9%CVE-2023-41256CRITICALDover Fueling Solutions MAGLINK LX Console Authentication BypassEPSS 0.9%CVE-2023-37057CRITICALAn issue in JLINK Unionman Technology Co. Ltd Jlink AX1800 v.1.0 allows a remote attacker to execute arbitrary code via the router's authentEPSS 0.9%CVE-2024-4186CRITICALEdwiser Bridge <= 3.0.5 - Authentication Bypass due to Missing Empty Value CheckEPSS 0.9%CVE-2025-27658CRITICALVasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Authentication Bypass OVE-20230524-EPSS 0.9%CVE-2022-1067MEDIUMICSMA-22-095-01 LifePoint Informatics Patient PortalEPSS 0.9%CVE-2022-23723HIGHPingFederate PingOneMFA Integration Kit MFA BypassEPSS 0.9%