Falhas do tipo CWE-73
668 resultadosControle de acesso inadequado
A aplicação falha em validar ou enforçar corretamente quem pode acessar quais recursos ou funcionalidades. Isso permite que usuários não autorizados executem ações, visualizem dados sensíveis ou acessem áreas administrativas que deveriam estar restritas.
Exemplo
Um sistema bancário que valida se o usuário está logado, mas não verifica se ele tem permissão para acessar a conta de outro cliente — bastaria mudar o ID na URL (ex: `/conta/123` para `/conta/456`) para ver dados alheios.
Como mitigar
Implemente verificações de autorização em todas as operações sensíveis, não confie apenas em obscuridade de URLs ou IDs. Use listas de controle de acesso (ACL) ou papéis (RBAC) centralizados, e valide permissões no servidor antes de retornar qualquer dado ou executar ação.
CVE-2026-63343CRITICALArbitrary File Read/Write: metadata.yaml symlink in image allows host filesystem access as rootEPSS 0.3%CVE-2026-74884HIGHopenssl_encrypt before 1.4.0 Path Traversal via plugin_idEPSS 0.3%CVE-2026-45008HIGHphpMyFAQ - Path Traversal in Client::deleteClientFolder via URL ParameterEPSS 0.3%CVE-2026-87815HIGHSiYuan before v3.8.2 Path Traversal via removeRiffDeckEPSS 0.3%CVE-2026-64816HIGHRapidRAW < 1.6.0 NTLMv2 Credential Leak via UNC Path in lutPathEPSS 0.3%CVE-2026-39377MEDIUMnbconvert has an Arbitrary File Write via Path Traversal in Cell Attachment FilenamesEPSS 0.3%CVE-2026-3892HIGHMotors – Car Dealer, Classifieds & Listing <= 1.4.107 - Authenticated (Subscriber+) Arbitrary File Deletion via 'stm_dealer_logo_path' ParameterEPSS 0.3%CVE-2025-2982MEDIUMLegrand SMS PowerView file inclusionEPSS 0.3%CVE-2026-41389MEDIUMOpenClaw 2026.4.7 < 2026.4.15 - Arbitrary File Read via Unvalidated Tool-Result Media PathsEPSS 0.3%CVE-2024-6714HIGHAn issue was discovered in provd before version 0.1.5 with a setuid binary, which allows a local attacker to escalate their privilege.EPSS 0.3%CVE-2023-5247HIGHMalicious Code Execution Vulnerability due to External Control of File Name or Path in multiple Mitsubishi Electric FA Engineering Software EPSS 0.3%CVE-2025-62842HIGHHBS 3 Hybrid Backup SyncEPSS 0.3%CVE-2026-81726HIGHNLTK through 3.10.3 Path Traversal via Model-Artifact APIsEPSS 0.3%CVE-2026-16444HIGHImproper Validation of File Paths in TeamViewer Desktop ClientsEPSS 0.3%CVE-2026-65939MEDIUMWhatsUp Gold versions prior to 26.0.2 contain an arbitrary file write vulnerability in the LogToFile action handler.EPSS 0.3%CVE-2026-26360HIGHDell Unisphere for PowerMax, version(s) 10.2, contain(s) an External Control of File Name or Path vulnerability. A low privileged attacker wEPSS 0.3%CVE-2026-86751HIGHSnipe-IT before 8.7.0 Arbitrary File Read and SSRF via MarkdownEPSS 0.3%CVE-2026-79692HIGHDell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an External Control EPSS 0.3%CVE-2026-82659HIGHnodemailer before 9.0.1 File Read and SSRF via raw optionEPSS 0.3%CVE-2026-33354HIGHAVideo has an authenticated arbitrary local file read via `chunkFile` path injection in `aVideoEncoder.json.php`EPSS 0.3%