Falhas do tipo CWE-639

2.498 resultados

Manipulação de identificadores para contornar controle de acesso

A aplicação não valida adequadamente se o usuário autenticado tem permissão para acessar o recurso identificado pelo parâmetro fornecido (ID de registro, número de documento, etc.). Um atacante modifica esse parâmetro para acessar dados de outros usuários — por exemplo, mudando `user_id=123` para `user_id=124` na URL e obtendo informações alheias sem autenticação adicional.

Exemplo

Um banco permite visualizar extrato em `/api/extrato?conta=1001`. Um cliente autenticado como `user_123` descobre que pode acessar `/api/extrato?conta=1002` e ver o extrato completo de outra pessoa, porque o servidor apenas verifica se há uma sessão válida, não se aquele usuário é dono da conta 1002.

Como mitigar

Implemente validação de propriedade em cada requisição: antes de retornar dados, confirme que o ID do recurso pertence ao usuário autenticado. Use referências indiretas (tokens opacos) em vez de IDs sequenciais previsíveis, e aplique testes automatizados que tentam acessar recursos de outros usuários.

CVE-2025-10570MEDIUMFlexible Refund and Return Order for WooCommerce <= 1.0.38 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Order RefundEPSS 0.2%CVE-2025-6833MEDIUMAll in One Time Clock Lite – Tracking Employee Time Has Never Been Easier <= 2.0 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary Clocking In/OutEPSS 0.2%CVE-2026-67358MEDIUMJoomla Extension - j2commerce.com - Download quota manipulation in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5EPSS 0.2%CVE-2026-16264MEDIUMNewsletters < 4.18.1 - Unauthenticated Subscriber Record Overwrite and PII Disclosure via IDOREPSS 0.2%CVE-2026-48073MEDIUMDocmost: Page export can include restricted same-space attachments through forged attachmentIdEPSS 0.2%CVE-2026-52850MEDIUMDocmost: Broken access control in transclusion lookup API leaks sync-block content across private spacesEPSS 0.2%CVE-2026-16567MEDIUMDocument Embedder < 2.3.1 - Unauthenticated Private Document Download via Token OracleEPSS 0.2%CVE-2026-13146LOWWP Travel < 12.0.2 - Unauthenticated Booking Payment State Tampering via IDOREPSS 0.2%CVE-2025-12766MEDIUMInsecure Direct Object Reference (IDOR) vulnerability in the Management Console of affected versions of BlackBerry AtHoc.EPSS 0.2%CVE-2025-65096MEDIUMRomM Insecure Direct Object Reference (IDOR) Allows Unauthorized Access to Private CollectionsEPSS 0.2%CVE-2026-1338MEDIUMAuthorization Bypass Through User-Controlled Key in GitLabEPSS 0.2%CVE-2024-1470HIGHElevation of Privilege attack on NetIQ Client login extensionEPSS 0.2%CVE-2026-93366MEDIUMBludit CMS 3.22.0 Authorization Bypass via list-images/delete-image AJAX EndpointsEPSS 0.2%CVE-2026-1228MEDIUMTimeline Block <= 1.3.3 - Insecure Direct Object Reference to Authenticated (Author+) Private Timeline Exposure via Shortcode AttributeEPSS 0.2%CVE-2026-16281HIGHClassified Listing < 6.1.1 - Subscriber+ Arbitrary Attachment Deletion and Listing Image Tampering via IDOREPSS 0.2%CVE-2025-61950MEDIUMIn GroupSession, a Circular notice can be created with its memo field non-editable, but the authorization check is improperly implemented. WEPSS 0.2%CVE-2026-88912MEDIUMrtMedia for WordPress, BuddyPress and bbPress < 4.7.12 - Subscriber+ Arbitrary Activity Privacy Modification via IDOREPSS 0.2%CVE-2025-12086MEDIUMReturn Refund and Exchange For WooCommerce <= 4.5.5 - Insecure Direct Object Reference to Authenticated (Subscriber+) Refund Request CancellationEPSS 0.2%CVE-2026-81653MEDIUMNextGEN Gallery < 4.5.0 - Authenticated Arbitrary Gallery Image Deletion via IDOREPSS 0.2%CVE-2025-12087MEDIUMWishlist and Save for later for Woocommerce <= 1.1.22 - Insecure Direct Object Reference to Authenticated (Subscriber+) Wishlist Item DeletionEPSS 0.2%