Falhas do tipo CWE-862

8.596 resultados

Falha de verificação de autorização

A aplicação não valida se o usuário tem permissão para acessar um recurso ou executar uma ação específica. O código presume que quem chegou até ali já é confiável, pulando a checagem de privilégios. Qualquer atacante que consiga se autenticar (ou nem isso) pode fazer operações que deveria estar proibido.

Exemplo

Um admin painel que verifica login, mas depois deixa qualquer usuário logado deletar outros perfis acessando /admin/delete-user/123 diretamente. A autenticação existe, a autorização não.

Como mitigar

Implemente verificações de autorização (ACL, RBAC ou atributo-based) antes de cada operação sensível: confirme se o usuário tem a role ou permissão necessária. Não confie em autenticação alone — é login que prova quem você é, autorização que prova o que você pode fazer.

CVE-2025-27103HIGHDataease Mysql JDBC Connection Parameters Not Being Verified Leads to Arbitrary File Read Vulnerability​EPSS 0.4%CVE-2023-33215MEDIUMWordPress Taggbox plugin <= 3.3 - Broken Access Control vulnerabilityEPSS 0.4%CVE-2025-24697MEDIUMWordPress Image Gallery – Responsive Photo Gallery plugin <= 1.0.5 - Broken Access Control vulnerabilityEPSS 0.4%CVE-2024-37475MEDIUMWordPress Newspack Newsletters plugin <= 2.13.2 - Broken Access Control vulnerabilityEPSS 0.4%CVE-2026-3432CRITICALSim Studio AI - Unauthenticated OAuth Token TheftEPSS 0.4%CVE-2022-2350—Disable User Login <= 1.0.1 - Unauthenticated Settings UpdateEPSS 0.4%CVE-2021-3653—A flaw was found in the KVM's AMD code for supporting SVM nested virtualization. The flaw occurs when processing the VMCB (virtual machine cEPSS 0.4%CVE-2026-81892HIGHEasyAdmin custom-action dispatcher bypasses access_control on other routesEPSS 0.4%CVE-2023-30522MEDIUMA missing permission check in Jenkins Fogbugz Plugin 2.2.17 and earlier allows attackers with Item/Read permission to trigger builds of jobsEPSS 0.4%CVE-2026-82475HIGHiFlytek astron-agent through 1.1.1 Workflow Hijacking via Missing Ownership CheckEPSS 0.4%CVE-2024-33595MEDIUMWordPress Master Addons for Elementor plugin <= 2.0.5.4.1 - Broken Access Control on Duplicate Post vulnerabilityEPSS 0.4%CVE-2024-12071MEDIUMEvergreen Content Poster – Auto Post and Schedule Your Best Content to Social Media <= 1.4.4 - Missing Authorization to Unauthenticated Arbitrary Post DeletionEPSS 0.4%CVE-2024-5648MEDIUMLearnDash LMS - Reports Free <= 1.8.2.1 - Missing Authorization to Plugin Settings UpdateEPSS 0.4%CVE-2026-63330HIGHWarpgate: Missing Admin Authorization on Live Recording Stream WebSocket Allows Any Authenticated User to Eavesdrop on Terminal SessionsEPSS 0.4%CVE-2026-55518CRITICALAvo: Missing Authorization in Avo Association Attach Endpoint Allows Unauthorized Relationship Manipulation and Privilege EscalationEPSS 0.4%CVE-2025-30581MEDIUMWordPress Top Bar plugin <= 3.3 - Broken Access Control VulnerabilityEPSS 0.4%CVE-2025-26953HIGHWordPress JetMenu plugin <= 2.4.9 - Broken Access Control VulnerabilityEPSS 0.4%CVE-2026-62194HIGHOpenClaw 2026.5.20 < 2026.6.9 Privilege Escalation via Plugin InstallEPSS 0.4%CVE-2026-30968HIGHCoral Server has insufficient validation of agent identity for SSE connectionsEPSS 0.4%CVE-2024-43982HIGHWordPress Login As Users plugin <= 1.4.3 - Broken Access Control to Account Takeover vulnerabilityEPSS 0.4%