Falhas do tipo CWE-639

2.497 resultados

Manipulação de identificadores para contornar controle de acesso

A aplicação não valida adequadamente se o usuário autenticado tem permissão para acessar o recurso identificado pelo parâmetro fornecido (ID de registro, número de documento, etc.). Um atacante modifica esse parâmetro para acessar dados de outros usuários — por exemplo, mudando `user_id=123` para `user_id=124` na URL e obtendo informações alheias sem autenticação adicional.

Exemplo

Um banco permite visualizar extrato em `/api/extrato?conta=1001`. Um cliente autenticado como `user_123` descobre que pode acessar `/api/extrato?conta=1002` e ver o extrato completo de outra pessoa, porque o servidor apenas verifica se há uma sessão válida, não se aquele usuário é dono da conta 1002.

Como mitigar

Implemente validação de propriedade em cada requisição: antes de retornar dados, confirme que o ID do recurso pertence ao usuário autenticado. Use referências indiretas (tokens opacos) em vez de IDs sequenciais previsíveis, e aplique testes automatizados que tentam acessar recursos de outros usuários.

CVE-2026-80342MEDIUMPayment Plugins for PayPal WooCommerce < 2.0.27 - Unauthenticated Payment Hijacking via Unvalidated PayPal Order IDEPSS 0.2%CVE-2025-67594MEDIUMWordPress Thim Elementor Kit plugin <= 1.3.3 - Insecure Direct Object References (IDOR) vulnerabilityEPSS 0.2%CVE-2026-24776MEDIUMOpenProject has an IDOR on MeetingAgendaItems allows cross-project meeting agenda item transferEPSS 0.2%CVE-2025-61876MEDIUMInsecure Direct Object Reference (IDOR) in /tenants/{id} API endpoint in Inforcer Platform version 2.0.153 allows an authenticated user withEPSS 0.2%CVE-2026-48783MEDIUMPostiz has an unauthenticated billing-enforcement bypass via /public/modify-subscriptionEPSS 0.2%CVE-2026-11142MEDIUMInsufficient policy enforcement in Paint in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass same origin policy via EPSS 0.2%CVE-2024-22439MEDIUMCertain HPE FlexNetwork and FlexFabric Switches, Remote Authentication BypassEPSS 0.2%CVE-2025-10912MEDIUMIDOR in saastech.io's TemizlikYoldaEPSS 0.2%CVE-2026-17627MEDIUMLangflow is affected by improper authorization due to missing access control on the voice-mode WebSocket endpointEPSS 0.2%CVE-2025-7733MEDIUMWP JobHunt <= 7.7 - Authenticated (Candidate+) Insecure Direct Object ReferenceEPSS 0.2%CVE-2026-55411MEDIUMToolJet: Cross-tenant credential decryption (IDOR) in POST /api/data-sources/decrypt — any authenticated user can decrypt any organization's data-source secretsEPSS 0.2%CVE-2025-12126MEDIUMThe Total Book Project <= 1.0 - Insecure Direct Object Reference to Authenticated (Contributor+) Book ManipulationEPSS 0.2%CVE-2022-48313MEDIUMThe Bluetooth module has a vulnerability of bypassing the user confirmation in the pairing process. Successful exploitation of this vulnerabEPSS 0.2%CVE-2026-81339MEDIUMMasterStudy LMS < 3.7.50 - Subscriber+ Quiz Attempt Grade Disclosure via IDOREPSS 0.2%CVE-2026-77766MEDIUMDirectorist 8.5 - 8.9.4 - Subscriber+ Order and Financial Record Disclosure via REST Orders EndpointEPSS 0.2%CVE-2026-1753MEDIUMGutena Forms < 1.6.1 - Contributor+ Arbitrary Limited Options UpdateEPSS 0.2%CVE-2026-22489MEDIUMWordPress Image Slider Slideshow plugin <= 1.8 - Insecure Direct Object References (IDOR) vulnerabilityEPSS 0.2%CVE-2026-2230MEDIUMBooking Calendar <= 10.14.14 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary User Settings ModificationEPSS 0.2%CVE-2025-40773MEDIUMA vulnerability has been identified in SiPass integrated (All versions < V3.0). Affected server applications contains a broken access controEPSS 0.2%CVE-2025-12063MEDIUMAn insecure direct object reference allowed a non-admin user to modify or remove certain data objects without having the appropriate permissEPSS 0.2%