Falhas do tipo CWE-862

8.836 resultados

Falha de verificação de autorização

A aplicação não valida se o usuário tem permissão para acessar um recurso ou executar uma ação específica. O código presume que quem chegou até ali já é confiável, pulando a checagem de privilégios. Qualquer atacante que consiga se autenticar (ou nem isso) pode fazer operações que deveria estar proibido.

Exemplo

Um admin painel que verifica login, mas depois deixa qualquer usuário logado deletar outros perfis acessando /admin/delete-user/123 diretamente. A autenticação existe, a autorização não.

Como mitigar

Implemente verificações de autorização (ACL, RBAC ou atributo-based) antes de cada operação sensível: confirme se o usuário tem a role ou permissão necessária. Não confie em autenticação alone — é login que prova quem você é, autorização que prova o que você pode fazer.

CVE-2025-67563MEDIUMWordPress Post SMTP plugin <= 3.6.1 - Broken Access Control vulnerabilityEPSS 0.3%CVE-2026-81923LOWConcrete CMS below 9.5.3 is missing authorization in the SEO Bulk Update Meta Tags editorEPSS 0.3%CVE-2025-22291MEDIUMWordPress LTL Freight Quotes – Worldwide Express Edition plugin <= 5.0.20 - Arbitrary Content Deletion vulnerabilityEPSS 0.3%CVE-2026-81922LOW"In Concrete CMS below 9.5.3, there is Missing authorization in the sitemap page reorder allowing low-privilege users to reorder arbitrary pages "EPSS 0.3%CVE-2026-39688MEDIUMWordPress WP Frontend Profile plugin <= 1.3.9 - Broken Access Control vulnerabilityEPSS 0.3%CVE-2026-75861MEDIUMUltimate Gift Cards for WooCommerce < 3.2.10 - Subscriber+ Gift Card Theft and Destruction via Unauthorized RedemptionEPSS 0.3%CVE-2026-81762MEDIUMWordPress Booking and Rental Manager plugin <= 2.7.6 - Broken Access Control vulnerabilityEPSS 0.3%CVE-2026-13389MEDIUMWebToffee Cookie Consent < 3.5.3 - Consent Log Disclosure/Deletion, Page Creation & License Deactivation via Unprotected REST RoutesEPSS 0.3%CVE-2026-76368LOWMissing Authorization through Playbooks in Splunk SOAREPSS 0.3%CVE-2024-13415MEDIUMFood Menu – Restaurant Menu & Online Ordering for WooCommerce <= 5.1.4 - Missing Authorization to Authenticated (Subscriber+) Settings UpdateEPSS 0.3%CVE-2026-57921MEDIUMIn JetBrains YouTrack before 2026.2.16593 improper access control allowed reading users' private data via the comment templates endpointEPSS 0.3%CVE-2024-13769MEDIUMPuzzles | WP Magazine / Review with Store WordPress Theme + RTL <= 4.2.4 - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site ScriptingEPSS 0.3%CVE-2025-48096MEDIUMWordPress Custom CSS plugin <= 1.4.0 - Broken Access Control vulnerabilityEPSS 0.3%CVE-2024-13652MEDIUMECPay Ecommerce for WooCommerce <= 1.1.2411060 - Missing Authorization to Authenticated (Subscriber+) Log DeletionEPSS 0.3%CVE-2026-28380MEDIUMBAC in Snapshot API allows deletion of unauthorized dashboard snapshotsEPSS 0.3%CVE-2026-18603MEDIUMCancel Order & Request Woocommerce < 1.3.4.34 - Unauthenticated Order Content Disclosure via Reorder AJAX ActionsEPSS 0.3%CVE-2026-49385MEDIUMIn JetBrains YouTrack before 2026.1.13570 improper access control allowed low-privileged users to modify service accountsEPSS 0.3%CVE-2025-11816MEDIUMPrivacy Policy Generator, Terms & Conditions Generator WordPress Plugin : WP Legal Pages <= 3.5.1 - Missing Authorization to Unauthenticated API DisconnectEPSS 0.3%CVE-2024-13703MEDIUMCRM and Lead Management by vcita <= 2.7.5 - Missing Authorization to Authenticated (Susbcriber+) Widget ToggleEPSS 0.3%CVE-2026-48969MEDIUMWordPress Really Simple SSL plugin <= 9.5.9 - Broken Access Control vulnerabilityEPSS 0.3%