Falhas do tipo CWE-862

8.626 resultados

Falha de verificação de autorização

A aplicação não valida se o usuário tem permissão para acessar um recurso ou executar uma ação específica. O código presume que quem chegou até ali já é confiável, pulando a checagem de privilégios. Qualquer atacante que consiga se autenticar (ou nem isso) pode fazer operações que deveria estar proibido.

Exemplo

Um admin painel que verifica login, mas depois deixa qualquer usuário logado deletar outros perfis acessando /admin/delete-user/123 diretamente. A autenticação existe, a autorização não.

Como mitigar

Implemente verificações de autorização (ACL, RBAC ou atributo-based) antes de cada operação sensível: confirme se o usuário tem a role ou permissão necessária. Não confie em autenticação alone — é login que prova quem você é, autorização que prova o que você pode fazer.

CVE-2026-74928HIGHWP Project Manager 2.1.0 - 4.0.6 - Unauthenticated Subscriber Account Creation via Trello Import RoutesEPSS 0.4%CVE-2026-90551MEDIUMWWBN AVideo Missing Authorization via video_from_program APIEPSS 0.4%CVE-2026-76074MEDIUMAutomatorWP <= 5.8.4 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Disclosure via automatorwp_campaign_monitor_get_lists AJAX ActionEPSS 0.4%CVE-2022-48350HIGHThe HUAWEI Messaging app has a vulnerability of unauthorized file access. Successful exploitation of this vulnerability may affect confidentEPSS 0.4%CVE-2024-0596MEDIUMAwesome Support – WordPress HelpDesk & Support Plugin <= 6.1.7 - Missing Authorization via editor_html()EPSS 0.4%CVE-2023-5506MEDIUMImageMapper <= 1.2.6 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Page/Post Deletion via imgmap_delete_area_ajaxEPSS 0.4%CVE-2025-1404MEDIUMSecure Copy Content Protection and Content Locking <= 4.4.7 - Missing Authorization to Unauthenticated User Email Retrieval via ays_sccp_reports_user_search FunctionEPSS 0.4%CVE-2023-5387MEDIUMFunnelforms Free <= 3.4 - Missing Authorization to Enable/Disable Dark ModeEPSS 0.4%CVE-2023-5415MEDIUMFunnelforms Free <= 3.4 - Missing Authorization to New Category CreationEPSS 0.4%CVE-2023-5416MEDIUMFunnelforms Free <= 3.4 - Missing Authorization to Category DeletionEPSS 0.4%CVE-2026-3117MEDIUMInstance and webhook GitLab plugin commands were able to be run by non-admin usersEPSS 0.4%CVE-2026-88802HIGHMDJM Event Management and Mobile Events Manager - Unauthenticated Arbitrary Post DeletionEPSS 0.4%CVE-2024-8431MEDIUMPhoto Gallery, Images, Slider in Rbs Image Gallery <= 3.2.21 - Missing Authorization to Authenticated (Subscriber+) Private Gallery Title DisclosureEPSS 0.4%CVE-2024-43296MEDIUMWordPress HTML5 Video Player plugin <= 2.5.30 - Broken Access Control vulnerabilityEPSS 0.4%CVE-2024-44208HIGHThis issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15. An app may be able to bypass certain PrEPSS 0.4%CVE-2025-49041MEDIUMWordPress Get Cash plugin <= 3.2.3 - Broken Access Control vulnerabilityEPSS 0.4%CVE-2026-25768HIGHLavinMQ is missing vhost access controlEPSS 0.4%CVE-2025-68019MEDIUMWordPress SEO Booster plugin <= 6.1.8 - Broken Access Control vulnerabilityEPSS 0.4%CVE-2023-48759HIGHWordPress JetElements For Elementor plugin <= 2.6.13 - Unauthenticated Arbitrary Attachment Download vulnerabilityEPSS 0.4%CVE-2023-47760MEDIUMWordPress Essential Blocks plugin <= 4.2.0 - Broken Access Control vulnerabilityEPSS 0.4%