Falhas do tipo CWE-862

8.493 resultados

Falha de verificação de autorização

A aplicação não valida se o usuário tem permissão para acessar um recurso ou executar uma ação específica. O código presume que quem chegou até ali já é confiável, pulando a checagem de privilégios. Qualquer atacante que consiga se autenticar (ou nem isso) pode fazer operações que deveria estar proibido.

Exemplo

Um admin painel que verifica login, mas depois deixa qualquer usuário logado deletar outros perfis acessando /admin/delete-user/123 diretamente. A autenticação existe, a autorização não.

Como mitigar

Implemente verificações de autorização (ACL, RBAC ou atributo-based) antes de cada operação sensível: confirme se o usuário tem a role ou permissão necessária. Não confie em autenticação alone — é login que prova quem você é, autorização que prova o que você pode fazer.

CVE-2023-45828MEDIUMWordPress RumbleTalk Live Group Chat plugin <= 6.2.5 - Broken Access Control vulnerabilityEPSS 0.8%CVE-2018-25105CRITICALFile Manager <= 3.0 - Unauthenticated Arbitrary File Upload/DownloadEPSS 0.8%CVE-2024-3213MEDIUMRelevanssi – A Better Search <= 4.22.1 - Missing Authorization to Unauthenticated Count Option UpdateEPSS 0.8%CVE-2024-5637HIGHMarket Exporter <= 2.0.19 - Missing Authorization to Arbitrary File DeletionEPSS 0.8%CVE-2023-27963HIGHThe issue was addressed with additional permissions checks. This issue is fixed in macOS Ventura 13.3, iOS 16.4 and iPadOS 16.4, iOS 15.7.4 EPSS 0.8%CVE-2022-38651CRITICALA security filter misconfiguration exists in VMware Hyperic Server 5.8.6. Exploitation of this vulnerability enables a malicious party to byEPSS 0.8%CVE-2023-6394HIGHQuarkus: graphql operations over websockets bypassEPSS 0.8%CVE-2022-41254MEDIUMMissing permission checks in Jenkins CONS3RT Plugin 1.0.0 and earlier allow attackers with Overall/Read permission to connect to an attackerEPSS 0.8%CVE-2021-4355HIGHWelcart e-Commerce < 2.2.8 - Missing Capabilities Check to Information DisclosureEPSS 0.8%CVE-2023-37860HIGHPHOENIX CONTACT: Missing Authorization in WP 6xxx Web panelsEPSS 0.8%CVE-2022-31167HIGHXWiki Platform Security Parent POM vulnerable to overwriting of security rules of a page with a final page having the same referenceEPSS 0.8%CVE-2023-3713HIGHProfileGrid <= 5.5.1 - Authenticated (Subscriber+) Arbitrary Option UpdateEPSS 0.8%CVE-2022-0745Like Button Rating < 2.6.45 - Arbitrary e-mail SendingEPSS 0.8%CVE-2021-44233SAP GRC Access Control - versions V1100_700, V1100_731, V1200_750, does not perform necessary authorization checks for an authenticated userEPSS 0.8%CVE-2026-34048CRITICALCoolify: Missing authorization on terminal websocket bootstrap routes allows low-privileged members to execute commands on team serversEPSS 0.8%CVE-2023-41875MEDIUMWordPress WP Directory Kit plugin <= 1.2.6 - Broken Access Control vulnerabilityEPSS 0.8%CVE-2024-29228HIGHMissing authorization vulnerability in GetStmUrlPath webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allEPSS 0.8%CVE-2021-4369MEDIUMFrontend File Manager <= 18.2 - Unauthenticated Content InjectionEPSS 0.8%CVE-2024-29229HIGHMissing authorization vulnerability in GetLiveViewPath webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 aEPSS 0.8%CVE-2025-11669HIGHBroken Access ControlEPSS 0.8%