Falhas do tipo CWE-294

213 resultados

Exposição de informações sensíveis a atores não autorizados

Fraqueza na qual dados sensíveis (credenciais, chaves, PII, tokens) são acessíveis por usuários ou processos que não deveriam ter acesso. Ocorre por falhas em controle de acesso, armazenamento inadequado ou transmissão desprotegida, permitindo vazamento ou roubo dessas informações.

Exemplo

Uma aplicação grava tokens de autenticação em logs em texto plano acessíveis via endpoint público, ou armazena senhas sem hash em banco de dados com permissões leitura aberta. Um atacante consegue ler essas credenciais e impersonar usuários legítimos.

Como mitigar

Implemente controle de acesso rigoroso baseado em papéis (RBAC/ABAC), criptografe dados sensíveis em repouso e em trânsito (TLS, AES), nunca registre credenciais em logs, e revise regularmente permissões de arquivos e endpoints para garantir que apenas atores autorizados acessem informações críticas.

CVE-2026-34021HIGHLack of cryptographic protection in Wertheim SafeController 5400 enables RS-485 message sniffing and replayEPSS 0.2%CVE-2026-54783HIGHCoreWCF: XML Signature Wrapping in WS-Security endorsing/supporting signature verification allows replay of captured signed messagesEPSS 0.2%CVE-2025-65553MEDIUMD3D Wi-Fi Home Security System ZX-G12 v2.1.17 is susceptible to RF jamming on the 433 MHz alarm sensor channel. An attacker within RF range EPSS 0.2%CVE-2026-82220MEDIUMWordPress Forminator plugin <= 1.57.1 - Other vulnerability Type vulnerabilityEPSS 0.2%CVE-2026-53636MEDIUMOpen edX LTI OAuth Replay AttackEPSS 0.2%CVE-2026-47133MEDIUMClearanceKit's signed policy tables lack monotonic counter, allowing replay of older legitimately-signed snapshotsEPSS 0.2%CVE-2026-18967MEDIUMKeycloak-services: keycloak-services: saml onetimeuse assertion replay in idp-initiated broker flowEPSS 0.1%CVE-2024-4009HIGHReplay Attack in KNX Secure DevicesEPSS 0.1%CVE-2025-61480HIGHAn issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.14.1 allows a physically proximate attacker to cause a denial ofEPSS 0.1%CVE-2026-45720HIGHOmni: TOCTOU race condition allows multiple concurrent uses of a single-use SAML session tokenEPSS 0.1%CVE-2026-49322MEDIUMIndian Scout Bobber 2025 Infotainment-to-WCM weak authentication allows recovery of user PIN from observed exchangeEPSS 0.1%CVE-2018-9477HIGHIn the development options section of the Settings app, there is a possible authentication bypass due to a missing permission check. This coEPSS 0.1%CVE-2026-87119HIGHmpp Tempo subscription key authorization is not bound to the issuing challenge, allowing a captured activation credential to be replayedEPSS