Falhas do tipo CWE-807

109 resultados

Decisão de segurança baseada em entrada não confiável

A aplicação toma decisões críticas de segurança (autenticação, autorização, acesso a recursos) usando dados que vêm do usuário ou de fontes externas sem validação adequada. Um atacante pode manipular essa entrada para contornar controles de segurança e ganhar acesso não autorizado.

Exemplo

Um sistema de login aceita um parâmetro 'admin=true' enviado pelo cliente para decidir se mostra a tela de administração, ou usa o IP do cliente (que pode vir de headers HTTP manipuláveis) para validar a procedência de uma requisição sensível.

Como mitigar

Nunca confie em dados do lado do cliente para decisões de segurança. Valide e verifique todas as decisões críticas no servidor usando fontes de dados íntegras (banco de dados, sessão segura, serviços de autenticação confiáveis). Mantenha a lógica de segurança no backend, fora do alcance do usuário.

CVE-2026-27707HIGHPlex-configured Seerr instances vulnerable to unauthenticated account registration via Jellyfin authentication endpointEPSS 0.5%CVE-2024-7005HIGHInsufficient validation of untrusted input in Safe Browsing in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced EPSS 0.5%CVE-2026-31892HIGHWorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference ModeEPSS 0.5%CVE-2025-59152HIGHX-Forwarded-For Header Spoofing Bypasses Litestar Rate LimitingEPSS 0.5%CVE-2026-64827CRITICALTelenia TVox 26.5.3 Authentication Bypass via set_env.phpEPSS 0.5%CVE-2024-52327MEDIUMECOVACS lawnmower and vacuum cloud service live video PIN bypassEPSS 0.5%CVE-2025-66507HIGH1Panel – CAPTCHA Bypass via Client-Controlled FlagEPSS 0.5%CVE-2024-21510MEDIUMVersions of the package sinatra from 0.0.0 are vulnerable to Reliance on Untrusted Inputs in a Security Decision via the X-Forwarded-Host (XEPSS 0.5%CVE-2026-59157MEDIUMwebhookd: Unrestricted HTTP Header to Shell Variable InjectionEPSS 0.5%CVE-2026-39807MEDIUMClient-supplied URI scheme trusted without transport verification in banditEPSS 0.5%CVE-2025-13926CRITICALContemporary Controls BASC 20T Reliance on Untrusted Inputs in a Security DecisionEPSS 0.4%CVE-2025-24369LOWAnubis has a bot protection bypass when a sophisticated attacker asks to pass a challenge of difficulty 0EPSS 0.4%CVE-2026-16093MEDIUMKeycloak-services: keycloak-services: required signed-jwt assertion policy can be bypassed with unsigned assertion headersEPSS 0.4%CVE-2026-13059HIGHImproper Validation of Client-Supplied Command Parameters Allowing Role-Based Access Control BypassEPSS 0.4%CVE-2026-54730HIGHauthentik: Authentication Flow Bypass via Unguarded challenge_valid() in AuthenticatorEndpointGDTCStage and GoogleChromeStageViewEPSS 0.4%CVE-2020-5252MEDIUMMalicious package may avoid detection in python auditingEPSS 0.4%CVE-2026-23848MEDIUMMyTube has Rate Limiting Bypass via X-Forwarded-For Header SpoofingEPSS 0.4%CVE-2026-25958HIGHCube privilege escalation via a specially crafted requestEPSS 0.4%CVE-2026-86863CRITICALpgAdmin 4: Authentication bypass via a client-controlled identity header in Webserver authentication modeEPSS 0.4%CVE-2024-45654MEDIUMIBM Security ReaQta improper input validationEPSS 0.4%