Falhas do tipo CWE-639

2.498 resultados

Manipulação de identificadores para contornar controle de acesso

A aplicação não valida adequadamente se o usuário autenticado tem permissão para acessar o recurso identificado pelo parâmetro fornecido (ID de registro, número de documento, etc.). Um atacante modifica esse parâmetro para acessar dados de outros usuários — por exemplo, mudando `user_id=123` para `user_id=124` na URL e obtendo informações alheias sem autenticação adicional.

Exemplo

Um banco permite visualizar extrato em `/api/extrato?conta=1001`. Um cliente autenticado como `user_123` descobre que pode acessar `/api/extrato?conta=1002` e ver o extrato completo de outra pessoa, porque o servidor apenas verifica se há uma sessão válida, não se aquele usuário é dono da conta 1002.

Como mitigar

Implemente validação de propriedade em cada requisição: antes de retornar dados, confirme que o ID do recurso pertence ao usuário autenticado. Use referências indiretas (tokens opacos) em vez de IDs sequenciais previsíveis, e aplique testes automatizados que tentam acessar recursos de outros usuários.

CVE-2025-12997LOWInsecure Direct Object Reference vulnerability in Medtronic CareLink Network which allows an authenticated attacker with access to specific EPSS 0.2%CVE-2026-93513MEDIUMWordPress SiteSkite plugin <= 2.1.7 - Insecure Direct Object References (IDOR) vulnerabilityEPSS 0.2%CVE-2026-23638MEDIUMKiteworks Secure Data Forms is vulnerable to Authorization Bypass Through User-Controlled KeyEPSS 0.2%CVE-2026-86837MEDIUMBookly < 28.3 - Unauthenticated Customer PII Update via Verification BypassEPSS 0.2%CVE-2026-86867MEDIUMCinnamon's kotaemon contains improper authorization checks in multi‑user chat handlersEPSS 0.2%CVE-2025-53357MEDIUMGLPI permits reservation modification by unauthorized usersEPSS 0.2%CVE-2026-61589MEDIUMdjust: WebSocket/runtime reconstructed request omits the client Host, causing host/subdomain TenantResolvers to misresolve the tenant on the live pathEPSS 0.2%CVE-2026-73657MEDIUMTrigger.dev: Cross-tenant payload poisoning via packet write + replayEPSS 0.2%CVE-2026-100626MEDIUMcapgo through 12.128.2 IDOR via PUT /app icon endpointEPSS 0.2%CVE-2026-24753MEDIUMKiteworks Secure Data Forms is vulnerable to Authorization Bypass Through User-Controlled KeyEPSS 0.2%CVE-2021-4142—The Candlepin component of Red Hat Satellite was affected by an improper authentication flaw. Few factors could allow an attacker to use theEPSS 0.2%CVE-2026-72662MEDIUMAuthorization Bypass Through User-Controlled Key in Kibana Leading to Unauthorized Disclosure, Modification, and Deletion of DataEPSS 0.2%CVE-2025-8884MEDIUMIDOR in VHS Electronic Software's ACE CenterEPSS 0.2%CVE-2023-26237MEDIUMAn issue was discovered in WatchGuard EPDR 8.0.21.0002. It is possible to bypass the defensive capabilities by adding a registry key as SYSTEPSS 0.2%CVE-2025-14594LOWAuthorization Bypass Through User-Controlled Key in GitLabEPSS 0.2%CVE-2025-12881MEDIUMReturn Refund and Exchange For WooCommerce <= 4.5.5 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary Order Message ReadEPSS 0.2%CVE-2026-84150MEDIUMDirectorist < 8.9.5 - Subscriber+ Cross-User Favorites Read and Write via REST Favorites EndpointEPSS 0.2%CVE-2023-30059MEDIUMAn insecure direct object reference in MK-Auth 23.01K4.9 allows attackers to access and send support calls for other users via manipulation EPSS 0.2%CVE-2026-20219MEDIUMA vulnerability in the REST API of Cisco Slido could have allowed an authenticated, remote attacker to access the social profile data of othEPSS 0.2%CVE-2025-69752MEDIUMAn issue in the "My Details" user profile functionality of Ideagen Q-Pulse 7.1.0.32 allows an authenticated user to view other users' profilEPSS 0.2%