Falhas do tipo CWE-73

668 resultados

Controle de acesso inadequado

A aplicação falha em validar ou enforçar corretamente quem pode acessar quais recursos ou funcionalidades. Isso permite que usuários não autorizados executem ações, visualizem dados sensíveis ou acessem áreas administrativas que deveriam estar restritas.

Exemplo

Um sistema bancário que valida se o usuário está logado, mas não verifica se ele tem permissão para acessar a conta de outro cliente — bastaria mudar o ID na URL (ex: `/conta/123` para `/conta/456`) para ver dados alheios.

Como mitigar

Implemente verificações de autorização em todas as operações sensíveis, não confie apenas em obscuridade de URLs ou IDs. Use listas de controle de acesso (ACL) ou papéis (RBAC) centralizados, e valide permissões no servidor antes de retornar qualquer dado ou executar ação.

CVE-2026-43989HIGHJunoClaw: upload_wasm accepted arbitrary filesystem paths without validationEPSS 0.1%CVE-2026-42866MEDIUMTookie: Arbitrary file write via path traversal in -u username / -U userfile output filenameEPSS 0.1%CVE-2025-67461MEDIUMZoom Rooms for macOS - External Control of File Name or PathEPSS 0.1%CVE-2026-30292HIGHAn arbitrary file overwrite vulnerability in Docudepot PDF Reader: PDF Viewer APP v1.0.34 allows attackers to overwrite critical internal fiEPSS 0.1%CVE-2025-20614MEDIUMExternal control of file name or path for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001 within Ring 3: User Applications mayEPSS 0.1%CVE-2026-30291HIGHAn arbitrary file overwrite vulnerability in Ora Tools PDF Reader ' Reader & Editor APPv4.3.5 allows attackers to overwrite critical internaEPSS 0.1%CVE-2026-14551HIGHLocal Privilege Escalation in servereye client (sensorhub)EPSS 0.1%CVE-2026-55062HIGHuniget: Path Traversal in Hook Files - Directory Escape VulnerabilityEPSS 0.1%CVE-2019-25618MEDIUMAdminExpress 1.2.5 Denial of Service via System CompareEPSS 0.1%CVE-2026-56390MEDIUMArbitrary Output Location Change in GNU BisonEPSS 0.1%CVE-2026-80119HIGHPassMark PerformanceTest, BurnInTest, and OSForensics Physical Memory Disclosure via DirectIo64.sys IOCTLEPSS 0.1%CVE-2026-25605MEDIUMA vulnerability has been identified in SICAM SIAPP SDK (All versions < V2.1.7). The affected application performs file deletion without propEPSS 0.1%CVE-2026-78675HIGHGitPython before 3.1.59 Local File Content Disclosure via .gitmodulesEPSS 0.1%CVE-2025-66003HIGHLocal users can perform a local root exploit via smb4k mounthelperEPSS 0.1%CVE-2026-30905HIGHExternal Control of File Name or Path in the Zoom Workplace VDI Plugin Windows Universal Installer before version 6.6.11 may allow an authenEPSS 0.1%CVE-2026-55609HIGHsublinear-time-solver: Arbitrary file write in consciousness-explorer / sublinear-time-solver MCP export_stateEPSS 0.1%CVE-2026-80118HIGHPassMark PerformanceTest, BurnInTest, and OSForensics Kernel Null Pointer Dereference via DirectIo64.sys IOCTLEPSS 0.1%CVE-2026-16987HIGHIBM i is Affected By An Improper Validation Vulnerability in PASE []EPSS 0.1%CVE-2026-8920HIGHImproper Restriction of Communication Channel to Intended Endpoints and External Control of File Name or Path in Aura Wallpaper Service alloEPSS 0.1%CVE-2026-16898HIGHIBM i is Affected By Multiple Vulnerabilities in Network Authentication ServiceEPSS 0.1%