Falhas do tipo CWE-863

3.088 resultados

Falha em verificação de autorização

O software realiza uma verificação de autorização, mas a implementação está incorreta ou incompleta, permitindo que um atacante contorne as restrições de acesso pretendidas. O erro típico é lógica falha na verificação (condições mal formuladas, casos não tratados) ou confiança em dados do usuário para validar permissões.

Exemplo

Uma aplicação web valida se o usuário está autenticado, mas esquece de checar se ele tem permissão para acessar o recurso específico. Um atacante muda o ID do objeto na URL e acessa dados de outro usuário porque a aplicação não verifica propriedade ou role antes de retornar o conteúdo.

Como mitigar

Implemente verificações de autorização explícitas em todo ponto de acesso a recurso sensível, verificando não apenas quem é o usuário, mas se ele tem permissão específica para aquela ação. Use um modelo de controle de acesso bem definido (RBAC, ABAC) e teste sistematicamente casos de bypass (usuários não autorizados, escalação de privilégio, alteração de parâmetros).

CVE-2026-78606MEDIUMIncorrect Authorization in Kibana Leading to Unauthorized Disclosure, Modification, and Deletion of DataEPSS 0.2%CVE-2025-24920MEDIUMUnauthorized Bookmark Creation and Modification in Archived ChannelsEPSS 0.2%CVE-2023-27899HIGHJenkins 2.393 and earlier, LTS 2.375.3 and earlier creates a temporary file in the default temporary directory with the default permissions EPSS 0.2%CVE-2025-41078HIGHMultiple vulnerabilities in Viafirma productsEPSS 0.2%CVE-2026-100540HIGHOpenClaw Feishu before 2026.8.1 Authentication Bypass via Disabled AccountEPSS 0.2%CVE-2026-59815MEDIUMJoplin: Pending share recipients can write items into shared folders before accepting invitationsEPSS 0.2%CVE-2025-68153HIGHJuju: Resource poisoningEPSS 0.2%CVE-2025-30750LOWVulnerability in the Unified Audit component of Oracle Database Server. Supported versions that are affected are 19.3-19.27, 21.3-21.18 andEPSS 0.2%CVE-2022-31644HIGHPotential vulnerabilities have been identified in the system BIOS of certain HP PC products, which might allow arbitrary code execution, escEPSS 0.2%CVE-2022-31646HIGHPotential vulnerabilities have been identified in the system BIOS of certain HP PC products, which might allow arbitrary code execution, escEPSS 0.2%CVE-2026-79002LOWIncorrect authorization in SiteIsolation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer EPSS 0.2%CVE-2021-4275MEDIUMkatlings pyambic-pentameter cross-site request forgeryEPSS 0.2%CVE-2026-53860LOWOpenClaw < 2026.5.7 - Sender Policy Bypass via Mutable Conversation Identifiers in BlueBubblesEPSS 0.2%CVE-2026-84743LOWThe Events Calendar 6.15.16.1 - 6.17.4.1 - Contributor+ Event/Venue/Organizer Update, Trash and Ownership Takeover via by-slug REST RoutesEPSS 0.2%CVE-2026-79186LOWIncorrect authorization in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer procesEPSS 0.2%CVE-2026-89151LOWForgejo before 16.0.4 allows use of restricted API tokens for unintended access to the "allow maintainer edit" feature.EPSS 0.2%CVE-2026-79191LOWIncorrect authorization in SiteIsolation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer EPSS 0.2%CVE-2023-6400HIGHIncorrect user authorization vulnerability on OpenText ZENworks Configuration Management (ZCM) product.EPSS 0.2%CVE-2025-10908HIGHAccount Lock Bypass via Magic Link or Pass Key Authentication in WSO2 Identity Server Allows Unauthorized AccessEPSS 0.2%CVE-2026-16064MEDIUMEvent Booking Manager for WooCommerce < 5.3.7 - Contributor+ Arbitrary Post Modification via mpwem_quick_edit_eventEPSS 0.2%