Falhas do tipo CWE-73
668 resultadosControle de acesso inadequado
A aplicação falha em validar ou enforçar corretamente quem pode acessar quais recursos ou funcionalidades. Isso permite que usuários não autorizados executem ações, visualizem dados sensíveis ou acessem áreas administrativas que deveriam estar restritas.
Exemplo
Um sistema bancário que valida se o usuário está logado, mas não verifica se ele tem permissão para acessar a conta de outro cliente — bastaria mudar o ID na URL (ex: `/conta/123` para `/conta/456`) para ver dados alheios.
Como mitigar
Implemente verificações de autorização em todas as operações sensíveis, não confie apenas em obscuridade de URLs ou IDs. Use listas de controle de acesso (ACL) ou papéis (RBAC) centralizados, e valide permissões no servidor antes de retornar qualquer dado ou executar ação.
CVE-2026-53508MEDIUMoasdiff does not enforce --allow-external-refs=false on the git-revision load path (SSRF / local file read)EPSS 0.3%CVE-2026-32204HIGHAzure Monitor Agent Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2025-14059MEDIUMEmailKit <= 1.6.1 - Authenticated (Author+) Arbitrary File Read via Path TraversalEPSS 0.3%CVE-2025-0898MEDIUMXpro Elementor Addons - Pro <= 1.4.7 - Authenticated (Contributor+) Arbitrary File Read via Draw SVGEPSS 0.3%CVE-2026-86995MEDIUMn8n: Git Node branch.<name>.remote Config Key Bypasses Sandbox Path Restriction, Enabling Local Git Repository ReadEPSS 0.3%CVE-2022-34669HIGHNVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular user can access or modiEPSS 0.3%CVE-2025-54780HIGHglpi-screenshot-plugin exposes local files in /ajax/screenshot.phpEPSS 0.3%CVE-2026-42597MEDIUMGotenberg: Chromium URL conversion routes read arbitrary files under /tmp via file:// schemeEPSS 0.3%CVE-2023-45588HIGHAn external control of file name or path vulnerability [CWE-73] in FortiClientMac version 7.2.3 and below, version 7.0.10 and below installEPSS 0.3%CVE-2026-53580HIGHTrilium arbitrary file read and denial of service via file:// URLs in the automatic image-download featureEPSS 0.3%CVE-2026-26228LOWVLC for Android < 3.7.0 Remote Access Path TraversalEPSS 0.3%CVE-2026-16054CRITICALDrag and Drop Multiple File Upload for WooCommerce < 1.1.8 - Unauthenticated File Deletion via Nonce OracleEPSS 0.3%CVE-2026-12513MEDIUMShared Files < 1.7.68 - Unauthenticated Arbitrary File Deletion via Path TraversalEPSS 0.3%CVE-2025-4674HIGHUnexpected command execution in untrusted VCS repositories in cmd/goEPSS 0.3%CVE-2025-61879HIGHIn Infoblox NIOS through 9.0.7, a High-Privileged User Can Trigger an Arbitrary File Write via the Account Creation Mechanism.EPSS 0.3%CVE-2026-45725HIGHcompliance-trestle Remote Fetching Mechanism has an Arbitrary File Write via Cache Path TraversalEPSS 0.3%CVE-2026-54584MEDIUMmport trusts environment-controlled temporary directories in privileged metadata extractionEPSS 0.3%CVE-2026-3602MEDIUMIBM App Connect Enterprise and IBM Integration Bus for z/OS toolkit is vulnerable to an sql injectionEPSS 0.3%CVE-2026-34492HIGHAirwall - Arbitrary file readEPSS 0.3%CVE-2026-30240CRITICALBudibase PWA ZIP Upload Path Traversal Allows Reading Arbitrary Server Files Including All Environment SecretsEPSS 0.3%