Falhas do tipo CWE-862

8.497 resultados

Falha de verificação de autorização

A aplicação não valida se o usuário tem permissão para acessar um recurso ou executar uma ação específica. O código presume que quem chegou até ali já é confiável, pulando a checagem de privilégios. Qualquer atacante que consiga se autenticar (ou nem isso) pode fazer operações que deveria estar proibido.

Exemplo

Um admin painel que verifica login, mas depois deixa qualquer usuário logado deletar outros perfis acessando /admin/delete-user/123 diretamente. A autenticação existe, a autorização não.

Como mitigar

Implemente verificações de autorização (ACL, RBAC ou atributo-based) antes de cada operação sensível: confirme se o usuário tem a role ou permissão necessária. Não confie em autenticação alone — é login que prova quem você é, autorização que prova o que você pode fazer.

CVE-2021-4366MEDIUMPWA for WP & AMP < = 1.7.32 - Missing AuthorizationEPSS 0.6%CVE-2025-5288CRITICALREST API | Custom API Generator For Cross Platform And Import Export In WP 1.0.0 - 2.0.3 - Missing Authorization to Unauthenticated Privilege Escalation via process_handler FunctionEPSS 0.6%CVE-2024-10008HIGHMasteriyo LMS – eLearning and Online Course Builder for WordPress <= 1.13.3 - Authenticated (Student+) Missing Authorization to Privilege EscalationEPSS 0.6%CVE-2024-6069HIGHPie Register - Basic <= 3.8.3.4 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin InstallationEPSS 0.6%CVE-2024-10802MEDIUMHash Elements <= 1.4.7 - Missing Authorization to Unauthenticated Draft Post Title ExposureEPSS 0.6%CVE-2024-35686MEDIUMWordPress Sensei LMS plugin <= 4.23.1 - Broken Access Control vulnerabilityEPSS 0.6%CVE-2026-25242MEDIUMGogs allows unauthenticated file uploadsEPSS 0.6%CVE-2023-1843MEDIUMMetform Elementor Contact Form Builder <= 3.3.0 - Missing AuthorizationEPSS 0.6%CVE-2023-43700HIGHMissing Authorization in RDT400 in SICK APU allows an unprivileged remote attacker to modify data via HTTP requests that no not require authEPSS 0.6%CVE-2024-2035MEDIUMImproper Authorization in zenml-io/zenmlEPSS 0.6%CVE-2026-38329CRITICALBludit CMS before version 3.18.4 allows Remote Code Execution (RCE) via the API Plugin. The POST /api/files/{key} endpoint in bl-plugins/apiEPSS 0.6%CVE-2024-44265HIGHThe issue was addressed by restricting options offered on a locked device. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, mEPSS 0.6%CVE-2025-46348CRITICALYesWiki Vulnerable to Unauthenticated Site Backup Creation and DownloadEPSS 0.6%CVE-2025-5894HIGHHonding Technology Smart Parking Management System - Missing AuthorizationEPSS 0.6%CVE-2023-35777MEDIUMWordPress The Events Calendar plugin <= 6.1.2.2 - Broken Access Control vulnerabilityEPSS 0.6%CVE-2024-53473HIGHWeGIA 3.2.0 before 3998672 does not verify permission to change a password.EPSS 0.6%CVE-2026-62328HIGH9Router 0.4.41 - Unauthenticated Information Disclosure via API Usage EndpointsEPSS 0.6%CVE-2024-3897MEDIUMPopup Box – Best WordPress Popup Plugin <= 4.3.6 - Missing Authorization to Information ExposureEPSS 0.6%CVE-2026-43643HIGHSoftaculous Virtualizor Authorization Bypass via Billing Module HandlerEPSS 0.6%CVE-2026-67443CRITICALFUXA: Unauthenticated guest JWT bypasses Node-RED secure-mode authorization gate (Remote Script Execution)EPSS 0.6%