Falhas do tipo CWE-610

96 resultados

Controle de acesso inadequado

É quando o software falha em validar corretamente quem pode acessar um recurso, função ou dado. O código não verifica permissões de forma robusta, permitindo que usuários não autorizados façam operações que não deveriam poder fazer.

Exemplo

Uma API que lista pedidos de um cliente usando apenas o ID do pedido na URL (exemplo.com/pedidos/123) sem verificar se o usuário logado é dono daquele pedido. Um atacante muda o ID para 124 e acessa dados de outro cliente.

Como mitigar

Implemente verificações de autorização em todas as operações sensíveis — valide não apenas se o usuário está autenticado, mas se ele tem permissão específica para aquele recurso. Use listas de controle de acesso (ACL) ou políticas de autorização centralizadas e revise-as regularmente.

CVE-2025-2365MEDIUMcrmeb_java WeChatMessageController.java webHook xml external entity referenceEPSS 0.4%CVE-2026-3404LOWthinkgem JeeSite Endpoint CasOutHandler.java xml external entity referenceEPSS 0.4%CVE-2024-7625MEDIUMNomad Vulnerable to Allocation Directory Escape On Non-Existing File Paths Through Archive UnpackingEPSS 0.3%CVE-2026-76572MEDIUMpkp pkp-lib XSLTransformer.php _transformPHP xml external entity referenceEPSS 0.3%CVE-2023-33188MEDIUM Uncontrolled data used in content resolution EPSS 0.3%CVE-2025-15251MEDIUMbeecue FastBee SIP Message ReqAbstractHandler.java getRootElement xml external entity referenceEPSS 0.3%CVE-2026-45760HIGHApache Camel K: Camel K Cross-Namespace Build Deputy AttackEPSS 0.3%CVE-2025-26417MEDIUMIn checkWhetherCallingAppHasAccess of DownloadProvider.java, there is a possible bypass of user consent when opening files in shared storageEPSS 0.3%CVE-2026-2536MEDIUMopencc JFlow Workflow WF_Admin_AttrFlow.java Imp_Done xml external entity referenceEPSS 0.3%CVE-2026-12879MEDIUMCross-Tenant Data Exfiltration in Apigee via BigQuery Confused DeputyEPSS 0.3%CVE-2025-13209MEDIUMbestfeng oa_git_free WorkflowPredefineController.java updateWriteBack xml external entity referenceEPSS 0.3%CVE-2025-8057MEDIUMIDOR in Patika Global Technologies' HumanSuiteEPSS 0.3%CVE-2026-2074MEDIUMO2OA HTTP POST Request check xml external entity referenceEPSS 0.3%CVE-2026-1218MEDIUMBjskzy Zhiyou ERP com.artery.richclient.RichClientService RichClientService.class initRCForm xml external entity referenceEPSS 0.3%CVE-2024-23639MEDIUMmicronaut-core management endpoints vulnerable to drive-by localhost attackEPSS 0.3%CVE-2023-44209MEDIUMLocal privilege escalation due to improper soft link handling. The following products are affected: Acronis Cyber Protect Cloud Agent (LinuxEPSS 0.2%CVE-2022-46869HIGHLocal privilege escalation during installation due to improper soft link handling. The following products are affected: Acronis Cyber ProtecEPSS 0.2%CVE-2024-29069MEDIUMsnapd will follow archived symlinks when unpacking a filesystemEPSS 0.2%CVE-2026-68562MEDIUMAnsible-collection-redhat-leapp: ansible-collection-redhat-leapp: information disclosure via leapp report tamperingEPSS 0.2%CVE-2024-6079MEDIUMDLL Hijacking Vulnerability Exists in Rockwell Automation Emulate3D™EPSS 0.2%