Falhas do tipo CWE-863

3.086 resultados

Falha em verificação de autorização

O software realiza uma verificação de autorização, mas a implementação está incorreta ou incompleta, permitindo que um atacante contorne as restrições de acesso pretendidas. O erro típico é lógica falha na verificação (condições mal formuladas, casos não tratados) ou confiança em dados do usuário para validar permissões.

Exemplo

Uma aplicação web valida se o usuário está autenticado, mas esquece de checar se ele tem permissão para acessar o recurso específico. Um atacante muda o ID do objeto na URL e acessa dados de outro usuário porque a aplicação não verifica propriedade ou role antes de retornar o conteúdo.

Como mitigar

Implemente verificações de autorização explícitas em todo ponto de acesso a recurso sensível, verificando não apenas quem é o usuário, mas se ele tem permissão específica para aquela ação. Use um modelo de controle de acesso bem definido (RBAC, ABAC) e teste sistematicamente casos de bypass (usuários não autorizados, escalação de privilégio, alteração de parâmetros).

CVE-2026-73571LOWAn authorization bypass vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.17 due to improper authorization validation in delegaEPSS 0.3%CVE-2024-49209MEDIUMArcher Platform 2024.03 before version 2024.09 is affected by an API authorization bypass vulnerability related to supporting application fiEPSS 0.3%CVE-2026-100538HIGHOpenClaw before 2026.8.1 Local File Read via Outbound AttachmentsEPSS 0.3%CVE-2026-59689HIGHProgress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF Improper Authorization Allows Privilege Escalation to RootEPSS 0.3%CVE-2026-78946MEDIUMIncorrect authorization in Select in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafteEPSS 0.3%CVE-2026-79077MEDIUMIncorrect authorization in WebProtect in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass system access restrictionsEPSS 0.3%CVE-2024-57969MEDIUMapp/Model/Attribute.php in MISP before 2.4.198 ignores an ACL during a GUI attribute search.EPSS 0.3%CVE-2026-79213MEDIUMIncorrect authorization in WebAppInstalls in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to bypass system aEPSS 0.3%CVE-2025-13480MEDIUMIncorrect authorization in Fudo EnterpriseEPSS 0.3%CVE-2026-79261MEDIUMIncorrect authorization in Controls in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafEPSS 0.3%CVE-2026-45316LOWOpen WebUI: Read-Only Users Can Toggle Note Pin Status via Incorrect Permission Check (Write via Read-Only Access)EPSS 0.3%CVE-2026-28720MEDIUMUnauthorized modification of settings due to insufficient authorization checks. The following products are affected: Acronis Cyber Protect 1EPSS 0.3%CVE-2025-43784MEDIUMImproper Access Control vulnerability in Liferay Portal 7.4.0 through 7.4.3.124, and Liferay DXP 2024.Q2.0 through 2024.Q2.8, 2024.Q1.1 thrEPSS 0.3%CVE-2026-28709MEDIUMUnauthorized resource manipulation due to improper authorization checks. The following products are affected: Acronis Cyber Protect 17 (LinuEPSS 0.3%CVE-2026-28719MEDIUMUnauthorized resource manipulation due to improper authorization checks. The following products are affected: Acronis Cyber Protect 17 (LinuEPSS 0.3%CVE-2026-28723MEDIUMUnauthorized report deletion due to insufficient access control. The following products are affected: Acronis Cyber Protect 17 (Linux, WindoEPSS 0.3%CVE-2024-49208MEDIUMArcher Platform 2024.03 before version 2024.08 is affected by an authorization bypass vulnerability related to supporting application files.EPSS 0.3%CVE-2024-44114LOWMissing Authorization check in SAP NetWeaver Application Server for ABAP and ABAP PlatformEPSS 0.3%CVE-2026-33343NONEetcd: Nested etcd transactions bypass RBAC authorization checksEPSS 0.3%CVE-2026-22170MEDIUMOpenClaw < 2026.2.22 BlueBubbles - Access Control Bypass via Empty allowFrom ConfigurationEPSS 0.3%