Falhas do tipo CWE-862

8.470 resultados

Falha de verificação de autorização

A aplicação não valida se o usuário tem permissão para acessar um recurso ou executar uma ação específica. O código presume que quem chegou até ali já é confiável, pulando a checagem de privilégios. Qualquer atacante que consiga se autenticar (ou nem isso) pode fazer operações que deveria estar proibido.

Exemplo

Um admin painel que verifica login, mas depois deixa qualquer usuário logado deletar outros perfis acessando /admin/delete-user/123 diretamente. A autenticação existe, a autorização não.

Como mitigar

Implemente verificações de autorização (ACL, RBAC ou atributo-based) antes de cada operação sensível: confirme se o usuário tem a role ou permissão necessária. Não confie em autenticação alone — é login que prova quem você é, autorização que prova o que você pode fazer.

CVE-2024-0593MEDIUMSimple Job Board <= 2.10.8 - Missing Authorization to Unauthenticated Information DisclosureEPSS 0.9%CVE-2025-55141HIGHMissing authorization in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 2.EPSS 0.9%CVE-2026-48168CRITICALPraisonAI: GitHub Actions Claude workflow command injection via unquoted PR branch nameEPSS 0.9%CVE-2020-1996MEDIUMPAN-OS: Panorama management server log injectionEPSS 0.9%CVE-2026-32230MEDIUMUptime Kuma is Missing Authorization Checks on Ping Badge Endpoint, Leaks Ping times of monitors without needing to be on a status pageEPSS 0.9%CVE-2025-2807HIGHMotors – Car Dealership & Classified Listings Plugin <= 1.4.64 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin InstallationEPSS 0.9%CVE-2026-53633CRITICALVitest: Exposed Browser Mode API Can Proxy CDP and Overwrite Config Files, Leading to RCEEPSS 0.9%CVE-2026-27454MEDIUMDiscourse has check revision visibility on posts endpointEPSS 0.9%CVE-2026-74909HIGHKeycloak-services: keycloak-services: incomplete fix for cve-2026-15573 allows policy enforcer bypass via percent-encoded uri segmentsEPSS 0.9%CVE-2026-1314MEDIUM3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery <= 1.16.17 - Missing Authorization to Unauthenticated Private/Draft Flipbook Data ExposureEPSS 0.9%CVE-2025-13956MEDIUMLearnPress – WordPress LMS Plugin <= 4.3.1 - Missing Authorization to Unauthenticated Orders Statistics ExposureEPSS 0.9%CVE-2024-1991HIGHRegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login <= 5.3.0.0 - Authenticated (Subscriber+) Privilege EscalationEPSS 0.9%CVE-2026-4003CRITICALUsers manager – PN <= 1.1.15 - Unauthenticated Privilege Escalation via Account Takeover via 'userspn_form_save' AJAX ActionEPSS 0.9%CVE-2022-27658Under certain conditions, SAP Innovation management - version 2.0, allows an attacker to access information which could lead to information EPSS 0.9%CVE-2021-4331HIGHThe Plus Addons for Elementor PRO <= 4.1.9 & The Plus Addons for Elementor <= 2.0.6 - Authenticated (Contributor+) Privilege EscalationEPSS 0.9%CVE-2023-53740HIGHScreen SFT DAB 1.9.3 Authentication Bypass via Admin Password ChangeEPSS 0.9%CVE-2021-4359MEDIUMFrontend File Manager Plugin <= 18.2 - Unauthenticated Arbitrary Post DeletionEPSS 0.9%CVE-2024-0138CRITICALNVIDIA Base Command Manager contains a missing authentication vulnerability in the CMDaemon component. A successful exploit of this vulnerabEPSS 0.9%CVE-2023-3714HIGHProfileGrid <= 5.5.2 - Missing Authorization to Arbitrary Group Option Modification and Privilege EscalationEPSS 0.9%CVE-2026-4365CRITICALLearnPress <= 4.3.2.8 - Missing Authorization to Unauthenticated Arbitrary Quiz Answer DeletionEPSS 0.9%