Falhas do tipo CWE-862

8.697 resultados

Falha de verificação de autorização

A aplicação não valida se o usuário tem permissão para acessar um recurso ou executar uma ação específica. O código presume que quem chegou até ali já é confiável, pulando a checagem de privilégios. Qualquer atacante que consiga se autenticar (ou nem isso) pode fazer operações que deveria estar proibido.

Exemplo

Um admin painel que verifica login, mas depois deixa qualquer usuário logado deletar outros perfis acessando /admin/delete-user/123 diretamente. A autenticação existe, a autorização não.

Como mitigar

Implemente verificações de autorização (ACL, RBAC ou atributo-based) antes de cada operação sensível: confirme se o usuário tem a role ou permissão necessária. Não confie em autenticação alone — é login que prova quem você é, autorização que prova o que você pode fazer.

CVE-2026-103239HIGHMISP Tag Collection Save Allows Privilege Escalation via Sibling Model InjectionEPSS 0.4%CVE-2024-35662MEDIUMWordPress Simple COD Fees for WooCommerce plugin <= 2.0.2 - Broken Access Control vulnerabilityEPSS 0.4%CVE-2026-48495HIGHTypeBot Google Sheets OAuth callback can create credentials in unauthorized workspaces and modify arbitrary typebotsEPSS 0.4%CVE-2026-90448HIGHA deployment mode intended to expose only read access to stored data proxies a set of application programming interface routes without restrEPSS 0.4%CVE-2026-91846HIGHMISP Collection Element Add Missing Authorization on Referenced Object UUIDEPSS 0.4%CVE-2025-47529MEDIUMWordPress Experto CTA Widget – Call To Action, Sticky CTA, Floating Button Plugin <= 1.1.1 - Settings Change VulnerabilityEPSS 0.4%CVE-2026-95685MEDIUMMISP Missing Authorization on replaceSuggestionInReport Event Report ActionEPSS 0.4%CVE-2026-76847HIGHact 0.2.81 through 0.2.89 Missing Authorization in the Artifacts V4 BackendEPSS 0.4%CVE-2023-41240MEDIUMWordPress Pricing Deals for WooCommercePricing Deals for WooCommerce plugin <= 2.0.3.2 - Broken Access Control vulnerabilityEPSS 0.4%CVE-2026-88915HIGHMISP Event Template Instantiation Bypasses Sharing Group and Tagging AuthorizationEPSS 0.4%CVE-2024-5453MEDIUMProfileGrid <= 5.8.6 - Missing AuthorizationEPSS 0.4%CVE-2026-90454MEDIUMA deployment mode intended to expose only read access to a bundled packet-analysis component's interface denies a list of write-capable routEPSS 0.4%CVE-2026-8593MEDIUMFix Business Intelligence API Pack permissionEPSS 0.4%CVE-2026-53640LOWFOSSBilling missing authorization checks on read-only admin API endpoints expose sensitive staff, client, and redirect dataEPSS 0.4%CVE-2024-32081MEDIUMWordPress Filter Custom Fields & Taxonomies Light plugin <= 1.05 - Broken Access Control vulnerabilityEPSS 0.4%CVE-2026-50282MEDIUMCraft CMS: Unauthorized Deletion of Destination Folders During Forced MovesEPSS 0.4%CVE-2026-77133MEDIUMBroken Access Control in extension "femanager" (femanager)EPSS 0.4%CVE-2026-73140MEDIUMcti-transmute Evaluation Report Exports Expose Private Comments and Author InformationEPSS 0.4%CVE-2026-42337MEDIUMMaxKB: Broken Access Control in MaxKB OSS URL Fetch APIEPSS 0.4%CVE-2025-11996MEDIUMFind Unused Images <= 1.0.7 - Missing Authorization to Unauthenticated Arbitrary Attachment DeletionEPSS 0.4%