Falhas do tipo CWE-862

8.667 resultados

Falha de verificação de autorização

A aplicação não valida se o usuário tem permissão para acessar um recurso ou executar uma ação específica. O código presume que quem chegou até ali já é confiável, pulando a checagem de privilégios. Qualquer atacante que consiga se autenticar (ou nem isso) pode fazer operações que deveria estar proibido.

Exemplo

Um admin painel que verifica login, mas depois deixa qualquer usuário logado deletar outros perfis acessando /admin/delete-user/123 diretamente. A autenticação existe, a autorização não.

Como mitigar

Implemente verificações de autorização (ACL, RBAC ou atributo-based) antes de cada operação sensível: confirme se o usuário tem a role ou permissão necessária. Não confie em autenticação alone — é login que prova quem você é, autorização que prova o que você pode fazer.

CVE-2026-58080HIGHIn Eclipse Milo versions 1.0.0 through 1.1.4, `OpcUaServerConfig.copy()` fails to preserve a configured `RoleMapper`. On servers that rely oEPSS 0.4%CVE-2025-13468MEDIUMSourceCodester Alumni Management System Delete admin_class.php delete_event authorizationEPSS 0.4%CVE-2026-28186HIGHWordPress Travelfic Toolkit plugin <= 1.5.1 - Broken Access Control vulnerabilityEPSS 0.4%CVE-2026-75044HIGHIn JetBrains YouTrack before 2025.3.156085, 2026.1.13914, 2026.2.18095 missing authorisation allowed an authenticated user to delete arbitEPSS 0.4%CVE-2026-87036HIGHTanium addressed an improper access controls vulnerability in Comply.EPSS 0.4%CVE-2026-81801HIGHWordPress WP-Stateless plugin <= 4.4.1 - Settings Change vulnerabilityEPSS 0.4%CVE-2026-59829MEDIUMDiscourse: Review queue exposes flag-related private message excerpts to category group moderatorsEPSS 0.4%CVE-2024-20463MEDIUMCisco ATA 190 Series Analog Telephone Adapter Firmware Command Injection and Denial of Service VulnerabilityEPSS 0.4%CVE-2024-50424MEDIUMWordPress Templately plugin <= 3.1.5 - Broken Access Control vulnerabilityEPSS 0.4%CVE-2024-48902MEDIUMIn JetBrains YouTrack before 2024.3.46677 improper access control allowed users with project update permission to delete applications via APEPSS 0.4%CVE-2024-56009MEDIUMWordPress Spreadr Woocommerce plugin <= 1.0.4 - Broken Access Control vulnerabilityEPSS 0.4%CVE-2024-5703MEDIUMIcegram Express - Email Subscribers, Newsletters and Marketing Automation Plugin <= 5.7.26 - Missing AuthorizationEPSS 0.4%CVE-2025-8807MEDIUMxujeff tianti 天梯 save authorizationEPSS 0.4%CVE-2024-2619MEDIUMElementor Header & Footer Builder <= 1.6.26 - Authenticated (Author+) HTML InjectionEPSS 0.4%CVE-2026-48151HIGHBudibase: Webhook schema endpoint authorization bypass allows unauthenticated mutation of webhook and automation schemaEPSS 0.4%CVE-2026-72812MEDIUMSiYuan before v3.7.4 Missing Authorization via refreshBacklinkEPSS 0.4%CVE-2025-30915MEDIUMWordPress Small Package Quotes – Worldwide Express Edition plugin <= 5.2.19 - Broken Access Control vulnerabilityEPSS 0.4%CVE-2025-31721MEDIUMA missing permission check in Jenkins 2.503 and earlier, LTS 2.492.2 and earlier allows attackers with Computer/Create permission but withouEPSS 0.4%CVE-2025-58753MEDIUMcopyparty: Sharing a single file does not fully restrict access to other files in source folderEPSS 0.4%CVE-2023-46632HIGHWordPress My Shortcodes plugin <= 2.3 - Broken Access Control vulnerabilityEPSS 0.4%