Falhas do tipo CWE-863

3.089 resultados

Falha em verificação de autorização

O software realiza uma verificação de autorização, mas a implementação está incorreta ou incompleta, permitindo que um atacante contorne as restrições de acesso pretendidas. O erro típico é lógica falha na verificação (condições mal formuladas, casos não tratados) ou confiança em dados do usuário para validar permissões.

Exemplo

Uma aplicação web valida se o usuário está autenticado, mas esquece de checar se ele tem permissão para acessar o recurso específico. Um atacante muda o ID do objeto na URL e acessa dados de outro usuário porque a aplicação não verifica propriedade ou role antes de retornar o conteúdo.

Como mitigar

Implemente verificações de autorização explícitas em todo ponto de acesso a recurso sensível, verificando não apenas quem é o usuário, mas se ele tem permissão específica para aquela ação. Use um modelo de controle de acesso bem definido (RBAC, ABAC) e teste sistematicamente casos de bypass (usuários não autorizados, escalação de privilégio, alteração de parâmetros).

CVE-2025-27512LOWZincati allows unprivileged access to rpm-ostree D-Bus `Deploy()` and `FinalizeDeployment()` methodsEPSS 0.2%CVE-2025-15691MEDIUMWPFunnels < 3.13.0 - Unauthenticated User Registration via Opt-in FormsEPSS 0.2%CVE-2025-12038MEDIUMFolderly <= 0.3 - Incorrect Authorization to Authenticated (Author+) Term DeletionEPSS 0.2%CVE-2025-12756MEDIUMInsecure Direct Object Reference in Mattermost Boards Plugin Enables Unauthorised Comment DeletionEPSS 0.2%CVE-2026-54096HIGHFile Browser: Improper Access Control Occurs via Pre-Created Public Share for a Non-existent PathEPSS 0.2%CVE-2025-13432MEDIUMTerraform Enterprise state versions can be created by users with specific permissions without sufficient write accessEPSS 0.2%CVE-2025-3272MEDIUMIncorrect user authorization vulnerability has been identified in Open Text Operations Bridge Manager.EPSS 0.2%CVE-2026-100704HIGHKyverno before 1.19.1 ImageValidatingPolicy Exception BypassEPSS 0.2%CVE-2023-29819MEDIUMAn issue found in Webroot SecureAnywhere Endpoint Protection CE 23.1 v.9.0.33.39 and before allows a local attacker to bypass protections viEPSS 0.2%CVE-2024-49501MEDIUMSysmac Studio provided by OMRON Corporation contains an incorrect authorization vulnerability. If this vulnerability is exploited, an attackEPSS 0.2%CVE-2025-14774HIGHCommunication analysis between the Card Reader and TP2CardReaderService daemonEPSS 0.2%CVE-2025-25251HIGHAn Incorrect Authorization vulnerability [CWE-863] in FortiClient Mac 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14 may allEPSS 0.2%CVE-2026-77454MEDIUMexists/2 predicate silently dropped on limited relationships with a parent() filter in AshSqlEPSS 0.2%CVE-2023-2257MEDIUMAuthentication Bypass in Hub Business integration in Devolutions Workspace Desktop 2023.1.1.3 and earlier on Windows and macOS allows an attEPSS 0.2%CVE-2023-28714HIGHImproper access control in firmware for some Intel(R) PROSet/Wireless WiFi software for Windows before version 22.220 HF (Hot Fix) may allowEPSS 0.2%CVE-2026-41048HIGHCaching of Authentication allows Authentication Bypass in qSnapperEPSS 0.2%CVE-2026-100590MEDIUMOpenClaw before 2026.7.1 Authorization Bypass via voice setEPSS 0.2%CVE-2026-5379LOWrunZero Platform MCP certification information leakEPSS 0.2%CVE-2026-91161MEDIUMOpenWA: VIEWER API keys can read WhatsApp group invite codesEPSS 0.2%CVE-2026-1242MEDIUMBlockSpare - Gutenberg Site Builder Blocks & Starter Sites <= 4.2.6 - Incorrect Authorization to Authenticated (Subscriber+) Arbitrary Post CreationEPSS 0.2%