Falhas do tipo CWE-862

8.721 resultados

Falha de verificação de autorização

A aplicação não valida se o usuário tem permissão para acessar um recurso ou executar uma ação específica. O código presume que quem chegou até ali já é confiável, pulando a checagem de privilégios. Qualquer atacante que consiga se autenticar (ou nem isso) pode fazer operações que deveria estar proibido.

Exemplo

Um admin painel que verifica login, mas depois deixa qualquer usuário logado deletar outros perfis acessando /admin/delete-user/123 diretamente. A autenticação existe, a autorização não.

Como mitigar

Implemente verificações de autorização (ACL, RBAC ou atributo-based) antes de cada operação sensível: confirme se o usuário tem a role ou permissão necessária. Não confie em autenticação alone — é login que prova quem você é, autorização que prova o que você pode fazer.

CVE-2026-87031LOWMissing authorization in the REST API user creation endpoint in Concrete CMS 9.2.0 through 9.5.3 allows arbitrary account creationEPSS 0.3%CVE-2024-7381MEDIUMGeo Controller <= 8.6.9 - Missing Authorization to Unauthenticated Shortcode ExecutionEPSS 0.3%CVE-2026-11359MEDIUMMemberships and User Profiles for WooCommerce <= 3.4 - Missing Authorization to Authenticated (Subscriber+) ProfileGrid Plugin Installation and ActivationEPSS 0.3%CVE-2024-31274MEDIUMWordPress EmbedPress plugin <= 3.9.11 - Broken Access Control vulnerabilityEPSS 0.3%CVE-2026-8238MEDIUMConcrete CMS 9.5.0 and below is vulnerable to IDOR in '/ccm/frontend/conversations/message_page' allowing unauthenticated read of any conversation messageEPSS 0.3%CVE-2025-26983MEDIUMWordPress Recipe Card Blocks for Gutenberg & Elementor plugin <= 3.4.3 - Broken Access Control vulnerabilityEPSS 0.3%CVE-2026-9240MEDIUMColissimo Officiel : Méthodes de livraison pour WooCommerce <= 2.9.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Order Shipment Modification via lpc_order_affect AJAX actionEPSS 0.3%CVE-2026-55476MEDIUMSnipe-IT: Unauthorized Asset Request Cancellation via Unguarded cancel_by_admin ParameterEPSS 0.3%CVE-2024-7390MEDIUMWP Testimonial Widget <= 3.1 - Missing AuthorizationEPSS 0.3%CVE-2024-31246MEDIUMWordPress PostX plugin <= 3.2.3 - Author+ Post/Page Duplication vulnerabilityEPSS 0.3%CVE-2024-12158MEDIUMPopup – MailChimp, GetResponse and ActiveCampaign Intergrations <= 3.2.6 - Missing Authorization to Unauthenticated DB Table TruncationEPSS 0.3%CVE-2026-12471MEDIUMSpexo <= 2.0.11 - Missing Authorization to Authenticated (Subscriber+) Limited Plugin ActivationEPSS 0.3%CVE-2026-4063MEDIUMSocial Icons Widget & Block <= 4.5.8 - Missing Authorization to Authenticated (Subscriber+) Sharing Configuration CreationEPSS 0.3%CVE-2026-30842MEDIUMWallos: Authenticated Missing Authorization Allows Deletion of Other Users’ Uploaded AvatarsEPSS 0.3%CVE-2026-12955MEDIUMCookie Banner for GDPR / CCPA <= 4.3.6 - Missing Authorization to Authenticated (Subscriber+) Scan Schedule Modification via gcc_save_schedule_scan AJAX ActionEPSS 0.3%CVE-2025-3871MEDIUMBroken Access Control Leads to Limited Denial of Service in GoAnywhere MFT 7.8.0 and earlierEPSS 0.3%CVE-2026-4244MEDIUMPost Duplicator <= 3.0.11 - Missing Authorization to Authenticated (Contributor+) Post Duplication with Arbitrary Author AttributionEPSS 0.3%CVE-2026-3225MEDIUMLearnPress <= 4.3.2.8 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Quiz Answer DeletionEPSS 0.3%CVE-2024-35729MEDIUMWordPress Tickera plugin <= 3.5.2.6 - Broken Access Control vulnerabilityEPSS 0.3%CVE-2026-90533MEDIUMFlowise before 3.1.4 Broken Access Control via organizationuserEPSS 0.3%