Falhas do tipo CWE-862

8.692 resultados

Falha de verificação de autorização

A aplicação não valida se o usuário tem permissão para acessar um recurso ou executar uma ação específica. O código presume que quem chegou até ali já é confiável, pulando a checagem de privilégios. Qualquer atacante que consiga se autenticar (ou nem isso) pode fazer operações que deveria estar proibido.

Exemplo

Um admin painel que verifica login, mas depois deixa qualquer usuário logado deletar outros perfis acessando /admin/delete-user/123 diretamente. A autenticação existe, a autorização não.

Como mitigar

Implemente verificações de autorização (ACL, RBAC ou atributo-based) antes de cada operação sensível: confirme se o usuário tem a role ou permissão necessária. Não confie em autenticação alone — é login que prova quem você é, autorização que prova o que você pode fazer.

CVE-2026-72796MEDIUMSiYuan before v3.7.4 Access Control Bypass via Static RoutesEPSS 0.4%CVE-2026-23806HIGHWordPress Jobs for WordPress plugin <= 2.8 - Broken Access Control vulnerabilityEPSS 0.4%CVE-2024-12266MEDIUMELEX WooCommerce Dynamic Pricing and Discounts <= 2.1.7 - Missing AuthorizationEPSS 0.4%CVE-2023-2786MEDIUMChannel commands execution doesn't properly verify permissionsEPSS 0.4%CVE-2026-3581MEDIUMBasic Google Maps Placemarks <= 1.10.7 - Missing Authorization to Unauthenticated Default Map Coordinate UpdateEPSS 0.4%CVE-2024-49698MEDIUMWordPress Great Restaurant Menu WP plugin <= 1.4.2 - Broken Access Control vulnerabilityEPSS 0.4%CVE-2026-13039MEDIUMEventin 4.0.26 - 4.1.15 - Missing Authorization to Unauthenticated Payment Bypass via REST APIEPSS 0.4%CVE-2026-12557MEDIUMNinja Forms - File Uploads <= 3.3.29 - Missing Authorization to Unauthenticated Log Disclosure and Deletion via debug-log/delete-all and debug-log/get-all REST EndpointsEPSS 0.4%CVE-2023-38514MEDIUMWordPress Social Share Icons & Social Share Buttons plugin <= 3.5.7 - Broken Access Control vulnerabilityEPSS 0.4%CVE-2023-52541HIGHAuthentication vulnerability in the API for app pre-loading. Impact: Successful exploitation of this vulnerability may affect service confidEPSS 0.4%CVE-2025-15330HIGHTanium addressed an improper input validation vulnerability in Deploy.EPSS 0.4%CVE-2024-10326MEDIUMRomethemeKit For Elementor <= 1.5.3 - Missing Authorization in save_options and reset_widgetsEPSS 0.4%CVE-2025-11439MEDIUMJhumanJ OpnForm integrations authorizationEPSS 0.4%CVE-2026-54356HIGHBudibase authenticated arbitrary S3 signed upload URL issuance via `/api/attachments/:datasourceId/url`EPSS 0.4%CVE-2026-4162HIGHGravity SMTP <= 2.1.4 - Missing Authorization to Authenticated (Subscriber+) Plugin UninstallEPSS 0.4%CVE-2024-52549MEDIUMJenkins Script Security Plugin 1367.vdf2fc45f229c and earlier, except 1365.1367.va_3b_b_89f8a_95b_ and 1362.1364.v4cf2dc5d8776, does not perEPSS 0.4%CVE-2026-45085MEDIUMDiscourse: Chat misauthorization and information disclosureEPSS 0.4%CVE-2026-44751HIGHMissing Authorization check in Application Server ABAP of SAP NetWeaver and ABAP PlatformEPSS 0.4%CVE-2026-84794HIGHCraft CMS 5.0.0 through 5.10.10 Authorization Bypass via assets/move-assetEPSS 0.4%CVE-2026-91929HIGHFlowise before 3.1.4 Cross-Tenant Authorization BypassEPSS 0.4%