Falhas do tipo CWE-863

3.097 resultados

Falha em verificação de autorização

O software realiza uma verificação de autorização, mas a implementação está incorreta ou incompleta, permitindo que um atacante contorne as restrições de acesso pretendidas. O erro típico é lógica falha na verificação (condições mal formuladas, casos não tratados) ou confiança em dados do usuário para validar permissões.

Exemplo

Uma aplicação web valida se o usuário está autenticado, mas esquece de checar se ele tem permissão para acessar o recurso específico. Um atacante muda o ID do objeto na URL e acessa dados de outro usuário porque a aplicação não verifica propriedade ou role antes de retornar o conteúdo.

Como mitigar

Implemente verificações de autorização explícitas em todo ponto de acesso a recurso sensível, verificando não apenas quem é o usuário, mas se ele tem permissão específica para aquela ação. Use um modelo de controle de acesso bem definido (RBAC, ABAC) e teste sistematicamente casos de bypass (usuários não autorizados, escalação de privilégio, alteração de parâmetros).

CVE-2024-40771HIGHThe issue was addressed with improved memory handling. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS EPSS 0.2%CVE-2026-15829HIGHSQL Injection and Security Boundary Bypass in googleapis/mcp-toolboxEPSS 0.2%CVE-2025-64641MEDIUMMattermost Jira plugin crafted action leaks Jira issue detailsEPSS 0.2%CVE-2024-41979HIGHA vulnerability has been identified in SmartClient modules Opcenter QL Home (SC) (All versions >= V13.2 < V2506), SOA Audit (All versions >=EPSS 0.2%CVE-2026-2386MEDIUMThe Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.4.7 - Incorrect Authorization to Authenticated (Author+) Arbitrary Draft Post Creation via 'post_type'EPSS 0.2%CVE-2025-24479HIGHFactoryTalk® View Machine Edition - Local Code InjectionEPSS 0.2%CVE-2026-35491MEDIUMPi-hole FTL: CLI API sessions can import Teleporter archives and modify configurationEPSS 0.2%CVE-2025-6707MEDIUMRace condition in privilege cache invalidation cycleEPSS 0.2%CVE-2024-12247MEDIUMImproper propagation of permission scheme updates across cluster nodesEPSS 0.2%CVE-2023-46139MEDIUMKernelSU signature validation mismatchEPSS 0.2%CVE-2024-47560HIGHRevoWorks Cloud Client 3.0.91 and earlier contains an incorrect authorization vulnerability. If this vulnerability is exploited, unintended EPSS 0.2%CVE-2026-18712HIGHImproper Authorization in MongoDB Queryable Encryption Maintenance Operations Allows Unauthorized Modification of Other CollectionsEPSS 0.2%CVE-2023-29818MEDIUMAn issue found in Webroot SecureAnywhere Endpoint Protection CE 23.1 v.9.0.33.39 and before allows a local attacker to bypass protections viEPSS 0.2%CVE-2026-46730MEDIUMDell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1EPSS 0.2%CVE-2025-43397MEDIUMA permissions issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS TEPSS 0.2%CVE-2025-53391CRITICALThe Debian zuluPolkit/CMakeLists.txt file for zuluCrypt through the zulucrypt_6.2.0-1 package has insecure PolicyKit allow_any/allow_inactivEPSS 0.2%CVE-2025-66623HIGHStrimzi allows unrestricted access to all Secrets in the same Kubernetes namespace from Kafka Connect and MirrorMaker 2 operandsEPSS 0.2%CVE-2026-82748LOWAsh.Actions.Aggregate authorizes an aggregate under one action but computes it under anotherEPSS 0.2%CVE-2026-82749MEDIUMAsh relationship parent(...) filter degrades to an IS NULL match when the parent field is unresolved, leaking scoped recordsEPSS 0.2%CVE-2026-58494MEDIUMWasmtime: WASI hard links bypass wasmtime-wasi's FilePerms for destinationEPSS 0.2%