Falhas do tipo CWE-639

2.495 resultados

Manipulação de identificadores para contornar controle de acesso

A aplicação não valida adequadamente se o usuário autenticado tem permissão para acessar o recurso identificado pelo parâmetro fornecido (ID de registro, número de documento, etc.). Um atacante modifica esse parâmetro para acessar dados de outros usuários — por exemplo, mudando `user_id=123` para `user_id=124` na URL e obtendo informações alheias sem autenticação adicional.

Exemplo

Um banco permite visualizar extrato em `/api/extrato?conta=1001`. Um cliente autenticado como `user_123` descobre que pode acessar `/api/extrato?conta=1002` e ver o extrato completo de outra pessoa, porque o servidor apenas verifica se há uma sessão válida, não se aquele usuário é dono da conta 1002.

Como mitigar

Implemente validação de propriedade em cada requisição: antes de retornar dados, confirme que o ID do recurso pertence ao usuário autenticado. Use referências indiretas (tokens opacos) em vez de IDs sequenciais previsíveis, e aplique testes automatizados que tentam acessar recursos de outros usuários.

CVE-2026-18439MEDIUMTutor LMS <= 4.0.7 - Authenticated (Custom+) Insecure Direct Object Reference to Arbitrary Quiz Question/Answer Modification and Deletion via 'payload' ParameterEPSS 0.3%CVE-2026-1206MEDIUMElementor Website Builder <= 3.35.7 - Incorrect Authorization to Authenticated (Contributor+) Sensitive Information Exposure via Elementor TemplateEPSS 0.3%CVE-2026-76907MEDIUMLaSuite Doc: Public Documents EnumerationEPSS 0.3%CVE-2026-58580MEDIUMLobeChat 2.2.9 - Broken Object-Level Authorization in Message Sub-Resource WritesEPSS 0.3%CVE-2026-56823MEDIUMAutoGPT: IDOR in Webhook Ping Endpoint Allows Enumeration and Cross-User Ping TriggeringEPSS 0.3%CVE-2022-48505—This issue was addressed with improved data protection. This issue is fixed in macOS Ventura 13. An app may be able to modify protected partEPSS 0.3%CVE-2026-63745MEDIUMSurrealDB before 3.1.0 Authorization Bypass via Composite Record-idEPSS 0.2%CVE-2025-43732MEDIUMLiferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.10, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3EPSS 0.2%CVE-2025-14882LOWInsecure direct object referenceEPSS 0.2%CVE-2025-14881LOWInsecure direct object referenceEPSS 0.2%CVE-2026-3473MEDIUMImproper file ownership validation in the Boards API allows unauthorised file accessEPSS 0.2%CVE-2025-13452MEDIUMAdmin and Customer Messages After Order for WooCommerce: OrderConvo <= 14 - Missing Authorization to Unauthenticated User Impersonation in Order MessagesEPSS 0.2%CVE-2026-18423LOWConcrete CMS 9.0.0 through 9.5.2 is vulnerable to Insecure direct object reference (IDOR) in the Express saved search preset delete and edit dialogs allowing an authenticated user with permission on one Express entity to delete or rename saved search presEPSS 0.2%CVE-2025-41069MEDIUMInsecure Direct Object References (IDOR) in DeporSite of T-Innova DeporSiteEPSS 0.2%CVE-2025-49352MEDIUMWordPress Order Cancellation & Returns for WooCommerce plugin <= 1.1.10 - Insecure Direct Object References (IDOR) vulnerabilityEPSS 0.2%CVE-2026-25574MEDIUMPayload Affected by Cross-Collection IDOR in payload-preferences Access Control (Multi-Auth Environments)EPSS 0.2%CVE-2025-65670MEDIUMAn Insecure Direct Object Reference (IDOR) in classroomio 0.1.13 allows students to access sensitive admin/teacher endpoints by manipulatingEPSS 0.2%CVE-2025-65020MEDIUMRallly Has Unauthorized Poll Duplication via Insecure Direct Object Reference (IDOR)EPSS 0.2%CVE-2026-10597MEDIUMITPison|OMICARD EDM - Insecure Direct Object ReferenceEPSS 0.2%CVE-2026-84025LOWBEAR - Bulk Editor and Products Manager Professional for WooCommerce < 1.2.2 - Authenticated Product Download URL and Meta Disclosure via IDOREPSS 0.2%