Falhas do tipo CWE-610

96 resultados

Controle de acesso inadequado

É quando o software falha em validar corretamente quem pode acessar um recurso, função ou dado. O código não verifica permissões de forma robusta, permitindo que usuários não autorizados façam operações que não deveriam poder fazer.

Exemplo

Uma API que lista pedidos de um cliente usando apenas o ID do pedido na URL (exemplo.com/pedidos/123) sem verificar se o usuário logado é dono daquele pedido. Um atacante muda o ID para 124 e acessa dados de outro cliente.

Como mitigar

Implemente verificações de autorização em todas as operações sensíveis — valide não apenas se o usuário está autenticado, mas se ele tem permissão específica para aquele recurso. Use listas de controle de acesso (ACL) ou políticas de autorização centralizadas e revise-as regularmente.

CVE-2023-4089LOWWAGO: Multiple products vulnerable to local file inclusionEPSS 0.5%CVE-2025-9065HIGHRockwell Automation ThinManager® Server-Side Request Forgery VulnerabilityEPSS 0.5%CVE-2026-19032MEDIUMjackson-databind resolves attacker-controlled URI schemes when deserializing java.nio.file.PathEPSS 0.5%CVE-2023-38046MEDIUMPAN-OS: Read System Files and Resources During Configuration CommitEPSS 0.5%CVE-2026-78966MEDIUMExternally controlled reference in QUIC in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a EPSS 0.5%CVE-2022-23439MEDIUMA externally controlled reference to a resource in another sphere vulnerability in Fortinet allows attacker to poison web caches via crafteEPSS 0.4%CVE-2026-79256HIGHExternally controlled reference in WebView in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker who had compromisEPSS 0.4%CVE-2026-55389HIGHdatamodel-code-generator vulnerable to arbitrary local file read via JSON-Schema `$ref` (`file://` and `../` traversal), bypassing `--no-allow-remote-refs`EPSS 0.4%CVE-2025-5877MEDIUMFengoffice Feng Office Document Upload ApplicationDataObject.class.php xml external entity referenceEPSS 0.4%CVE-2025-2875HIGHCWE-610: Externally Controlled Reference to a Resource in Another Sphere vulnerability exists that could cause a loss of confidentiality wheEPSS 0.4%CVE-2025-11035MEDIUMJinher OA text xml external entity referenceEPSS 0.4%CVE-2026-32008HIGHOpenClaw < 2026.2.21 - Arbitrary Local File Read via Browser Navigation GuardEPSS 0.4%CVE-2026-12788MEDIUMzhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform 应用开发者平台 XML Parser import xml external entity referenceEPSS 0.4%CVE-2024-6717HIGHNomad Vulnerable to Allocation Directory Path Escape Through Archive UnpackingEPSS 0.4%CVE-2025-1225MEDIUMywoa WXCallBack Interface XMLParse.java extract xml external entity referenceEPSS 0.4%CVE-2024-28962MEDIUMDell Command | Update, Dell Update, and Alienware Update UWP, versions prior to 5.4, contain an Exposed Dangerous Method or Function vulneraEPSS 0.4%CVE-2024-42168HIGHHCL MyXalytics is affected by out-of-band resource load (HTTP) vulnerabilityEPSS 0.4%CVE-2023-22616HIGHAn issue was discovered in Insyde InsydeH2O with kernel 5.2 through 5.5. The Save State register is not checked before use. The IhisiSmm driEPSS 0.4%CVE-2026-62960HIGHGit for Windows: Server-advertised bundle-uri can trigger outbound SMB callbacks via UNC and file:// paths on WindowsEPSS 0.4%CVE-2026-55390HIGHArbitrary local file read via XSD `schemaLocation` (`xs:include`/`xs:import`) path traversal, with no remote-ref gateEPSS 0.4%