Falhas do tipo CWE-862

8.721 resultados

Falha de verificação de autorização

A aplicação não valida se o usuário tem permissão para acessar um recurso ou executar uma ação específica. O código presume que quem chegou até ali já é confiável, pulando a checagem de privilégios. Qualquer atacante que consiga se autenticar (ou nem isso) pode fazer operações que deveria estar proibido.

Exemplo

Um admin painel que verifica login, mas depois deixa qualquer usuário logado deletar outros perfis acessando /admin/delete-user/123 diretamente. A autenticação existe, a autorização não.

Como mitigar

Implemente verificações de autorização (ACL, RBAC ou atributo-based) antes de cada operação sensível: confirme se o usuário tem a role ou permissão necessária. Não confie em autenticação alone — é login que prova quem você é, autorização que prova o que você pode fazer.

CVE-2024-32519MEDIUMWordPress GG Woo Feed for WooCommerce plugin <= 1.2.6 - Broken Access Control vulnerabilityEPSS 0.3%CVE-2024-37218MEDIUMWordPress Page Builder Sandwich <= 5.1.0 - Broken Access Control vulnerabilityEPSS 0.3%CVE-2024-12711MEDIUMRSVP and Event Management <= 2.7.13 - Missing AuthorizationEPSS 0.3%CVE-2026-4244MEDIUMPost Duplicator <= 3.0.11 - Missing Authorization to Authenticated (Contributor+) Post Duplication with Arbitrary Author AttributionEPSS 0.3%CVE-2024-7381MEDIUMGeo Controller <= 8.6.9 - Missing Authorization to Unauthenticated Shortcode ExecutionEPSS 0.3%CVE-2024-35659MEDIUMWordPress KiviCare plugin <= 3.6.6 - Insecure Direct Object References (IDOR) vulnerabilityEPSS 0.3%CVE-2025-26983MEDIUMWordPress Recipe Card Blocks for Gutenberg & Elementor plugin <= 3.4.3 - Broken Access Control vulnerabilityEPSS 0.3%CVE-2026-4063MEDIUMSocial Icons Widget & Block <= 4.5.8 - Missing Authorization to Authenticated (Subscriber+) Sharing Configuration CreationEPSS 0.3%CVE-2026-59709MEDIUMGhostfolio - Unauthorized Portfolio Holding Tag Modification via Missing Permission CheckEPSS 0.3%CVE-2025-3871MEDIUMBroken Access Control Leads to Limited Denial of Service in GoAnywhere MFT 7.8.0 and earlierEPSS 0.3%CVE-2026-33413HIGHetcd: Authorization bypasses in multiple APIsEPSS 0.3%CVE-2026-30842MEDIUMWallos: Authenticated Missing Authorization Allows Deletion of Other Users’ Uploaded AvatarsEPSS 0.3%CVE-2024-31246MEDIUMWordPress PostX plugin <= 3.2.3 - Author+ Post/Page Duplication vulnerabilityEPSS 0.3%CVE-2026-44571MEDIUMOpen WebUI: Improper Authorization in Standard Channels Allows Message Updates with Read PermissionEPSS 0.3%CVE-2026-45124MEDIUMMyBB: Mod CP report resolution missing authorizationEPSS 0.3%CVE-2025-0935MEDIUMMedia Library Folders <= 8.3.0 - Missing Authorization to Plugin Settings ChangeEPSS 0.3%CVE-2026-3226MEDIUMLearnPress <= 4.3.2.8 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Email Notification TriggeringEPSS 0.3%CVE-2026-3225MEDIUMLearnPress <= 4.3.2.8 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Quiz Answer DeletionEPSS 0.3%CVE-2026-11359MEDIUMMemberships and User Profiles for WooCommerce <= 3.4 - Missing Authorization to Authenticated (Subscriber+) ProfileGrid Plugin Installation and ActivationEPSS 0.3%CVE-2024-12618MEDIUMNewsletter2Go <= 4.0.14 - Missing Authorization to Authenticated (Subscriber+) Style ResetEPSS 0.3%