Falhas do tipo CWE-863

3.100 resultados

Falha em verificação de autorização

O software realiza uma verificação de autorização, mas a implementação está incorreta ou incompleta, permitindo que um atacante contorne as restrições de acesso pretendidas. O erro típico é lógica falha na verificação (condições mal formuladas, casos não tratados) ou confiança em dados do usuário para validar permissões.

Exemplo

Uma aplicação web valida se o usuário está autenticado, mas esquece de checar se ele tem permissão para acessar o recurso específico. Um atacante muda o ID do objeto na URL e acessa dados de outro usuário porque a aplicação não verifica propriedade ou role antes de retornar o conteúdo.

Como mitigar

Implemente verificações de autorização explícitas em todo ponto de acesso a recurso sensível, verificando não apenas quem é o usuário, mas se ele tem permissão específica para aquela ação. Use um modelo de controle de acesso bem definido (RBAC, ABAC) e teste sistematicamente casos de bypass (usuários não autorizados, escalação de privilégio, alteração de parâmetros).

CVE-2026-24692MEDIUMGuest users can bypass read permissions via search APIEPSS 0.2%CVE-2025-43917HIGHIn Pritunl Client before 1.3.4220.57, an administrator with access to /Applications can escalate privileges after uninstalling the product. EPSS 0.2%CVE-2026-2725MEDIUMImproper Authorization in Gerrit allowing Code Review Bypass via "Submitted Together"EPSS 0.2%CVE-2026-84173HIGHIn Eclipse Ankaios versions v0.5.1 through v1.0.1, the agent-side Control Interface authorizer incorrectly evaluates multi-segment allow rulEPSS 0.2%CVE-2026-43672HIGHAn authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOSEPSS 0.2%CVE-2024-12831MEDIUMArista NG Firewall uvm_login Incorrect Authorization Privilege Escalation VulnerabilityEPSS 0.2%CVE-2024-7457HIGHmacOS Stash network-management utility: Unauthorized Manipulation of System Network PreferencesEPSS 0.2%CVE-2025-8886MEDIUMAuthorization Bypass in Usta Information Systems' Aybs InteraktifEPSS 0.2%CVE-2026-64650MEDIUMAI SDK Codex Harness Tool Relay Authorization BypassEPSS 0.2%CVE-2026-64651MEDIUMAI SDK OpenCode Harness Tool Relay Authorization BypassEPSS 0.2%CVE-2026-32915CRITICALOpenClaw < 2026.3.11 - Sandbox Boundary Bypass via Subagent Control SurfaceEPSS 0.2%CVE-2025-43387HIGHA permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.2, macOS Tahoe 26.1. A malicious aEPSS 0.2%CVE-2025-68933MEDIUMDiscourse non-admin moderators can exfiltrate private content via post ownership transferEPSS 0.2%CVE-2026-0997MEDIUMMattermost Zoom Plugin channel preference API lacks authorization checksEPSS 0.2%CVE-2026-90508MEDIUMChengdu Qilu Technology Ludashi Message Dispatch ProtectFilter64.sys MessageNotifyCallback authorizationEPSS 0.2%CVE-2026-59678HIGHportprotonqt allows any users to mount and unmount arbitrary file systems and modify the network configuration via NetworkManagerEPSS 0.2%CVE-2026-18954MEDIUMIncorrect authorization in the aggregation pipeline tool in Amazon AWS Labs DocumentDB MCP ServerEPSS 0.2%CVE-2026-65393MEDIUMA permissions issue was addressed with improved validation. This issue is fixed in Xcode 27, macOS Golden Gate 27. An app may be able to accEPSS 0.2%CVE-2022-22307MEDIUMIBM Security Guardium privilege escalationEPSS 0.2%CVE-2026-84618MEDIUMA permissions issue was addressed with improved validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.EPSS 0.2%