Falhas do tipo CWE-73
668 resultadosControle de acesso inadequado
A aplicação falha em validar ou enforçar corretamente quem pode acessar quais recursos ou funcionalidades. Isso permite que usuários não autorizados executem ações, visualizem dados sensíveis ou acessem áreas administrativas que deveriam estar restritas.
Exemplo
Um sistema bancário que valida se o usuário está logado, mas não verifica se ele tem permissão para acessar a conta de outro cliente — bastaria mudar o ID na URL (ex: `/conta/123` para `/conta/456`) para ver dados alheios.
Como mitigar
Implemente verificações de autorização em todas as operações sensíveis, não confie apenas em obscuridade de URLs ou IDs. Use listas de controle de acesso (ACL) ou papéis (RBAC) centralizados, e valide permissões no servidor antes de retornar qualquer dado ou executar ação.
CVE-2026-2351MEDIUMTask Manager <= 3.0.2 - Authenticated (Subscriber+) Arbitrary File ReadEPSS 0.3%CVE-2026-45088HIGHDalfox: Unauthenticated Arbitrary File Read with Out-of-Band Exfiltration via `custom-payload-file` in Dalfox Server ModeEPSS 0.3%CVE-2021-3626HIGHWindows version of Multipass unauthenticated localhost tcp control socket can perform mountsEPSS 0.2%CVE-2026-69383HIGHWindows Shell Elevation of Privilege VulnerabilityEPSS 0.2%CVE-2026-78620MEDIUMImproper Path Validation in Okta Access Gateway Kerberos Configuration HandlingEPSS 0.2%CVE-2026-86741HIGHSnipe-IT before 8.7.0 Arbitrary File Read and SSRF via Category EULAEPSS 0.2%CVE-2026-18048HIGHWP Photo Album Plus < 9.2.07.002 - Unauthenticated Arbitrary ZIP File Deletion via delmyzip Path TraversalEPSS 0.2%CVE-2026-45089HIGHDalfox: Unauthenticated Arbitrary File Create/Append via `output` Option in Dalfox Server ModeEPSS 0.2%CVE-2026-54200HIGHTeamDavid: Local File Inclusion via the form field 'scjob'EPSS 0.2%CVE-2026-19353LOWDedeCMS Installation Wizard index.php _4_Setup file inclusionEPSS 0.2%CVE-2026-53956MEDIUMRattler vulnerable to package cache path traversal via conda package build stringEPSS 0.2%CVE-2026-77016CRITICALWorkeera Remote Tech Job Board < 1.0.6 - Subscriber+ Arbitrary File Deletion via Candidate Profile Mass AssignmentEPSS 0.2%CVE-2026-78679HIGHGitPython before 3.1.59 Arbitrary File Read via TagReference.createEPSS 0.2%CVE-2023-26282MEDIUMIBM Watson CP4D Data Stores file modificiationEPSS 0.2%CVE-2026-82637MEDIUMbrowser-use web-ui 2.0.0 through 3.0.0 Arbitrary Directory CreationEPSS 0.2%CVE-2026-76796MEDIUMNewell Brands DYMO Connect Desktop improper file path validationEPSS 0.2%CVE-2025-1056MEDIUMGee-netics, member of AXIS Camera Station Pro Bug Bounty Program, has identified an issue with a specific file that the server is using. A nEPSS 0.2%CVE-2026-34967MEDIUMAdminer sql-log Plugin 5.3.0 through 5.4.2 Arbitrary File WriteEPSS 0.2%CVE-2026-26361MEDIUMDell Unisphere for PowerMax, version(s) 10.2, contain(s) an External Control of File Name or Path vulnerability. A low privileged attacker wEPSS 0.2%CVE-2026-12070HIGHTeamDavid: Arbitrary File Deletion via form field 'scjob'EPSS 0.2%