Falhas do tipo CWE-863

3.101 resultados

Falha em verificação de autorização

O software realiza uma verificação de autorização, mas a implementação está incorreta ou incompleta, permitindo que um atacante contorne as restrições de acesso pretendidas. O erro típico é lógica falha na verificação (condições mal formuladas, casos não tratados) ou confiança em dados do usuário para validar permissões.

Exemplo

Uma aplicação web valida se o usuário está autenticado, mas esquece de checar se ele tem permissão para acessar o recurso específico. Um atacante muda o ID do objeto na URL e acessa dados de outro usuário porque a aplicação não verifica propriedade ou role antes de retornar o conteúdo.

Como mitigar

Implemente verificações de autorização explícitas em todo ponto de acesso a recurso sensível, verificando não apenas quem é o usuário, mas se ele tem permissão específica para aquela ação. Use um modelo de controle de acesso bem definido (RBAC, ABAC) e teste sistematicamente casos de bypass (usuários não autorizados, escalação de privilégio, alteração de parâmetros).

CVE-2025-26330HIGHDell PowerScale OneFS, versions 9.4.0.0 through 9.10.0.1, contains an incorrect authorization vulnerability. An unauthenticated attacker witEPSS 0.1%CVE-2026-78609MEDIUMIncorrect Authorization in Elastic Cloud on Kubernetes Leading to Unauthorized Modification of DataEPSS 0.1%CVE-2024-0043HIGHIn multiple locations, there is a possible notification listener grant to an app running in the work profile due to a logic error in the codEPSS 0.1%CVE-2026-65404MEDIUMAn authorization issue was addressed with improved state management. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 27 and iPadOEPSS 0.1%CVE-2026-60087MEDIUMPraisonAI before 1.6.78 Tool Approval Cache BypassEPSS 0.1%CVE-2026-40191MEDIUMClearanceKit has a policy bypass via dual-path Endpoint Security events checking only source pathEPSS 0.1%CVE-2026-24029MEDIUMDNS over HTTPS ACL bypassEPSS 0.1%CVE-2026-22545LOWPassword Change Bypass via Auth Switch EndpointEPSS 0.1%CVE-2025-23256HIGHNVIDIA BlueField contains a vulnerability in the management interface, where an attacker with local access could cause incorrect authorizatiEPSS 0.1%CVE-2026-1553MEDIUMDrupal Canvas - Moderately critical - Access bypass - SA-CONTRIB-2026-006EPSS 0.1%CVE-2026-84540MEDIUMAn authorization issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS EPSS 0.1%CVE-2026-40599HIGHClearanceKit: Ad-hoc signed binaries can spoof Apple process identities in the global allowlistEPSS 0.1%CVE-2026-32918CRITICALOpenClaw < 2026.3.11 - Session Sandbox Escape via session_status ToolEPSS 0.1%CVE-2026-43785MEDIUMA permissions issue was addressed with additional restrictions. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS SeqEPSS 0.1%CVE-2021-26387LOWInsufficient access controls in ASP kernel may allow a privileged attacker with access to AMD signing keys and the BIOS menu or UEFI shell tEPSS 0.1%CVE-2026-28864LOWThis issue was addressed with improved permissions checking. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, EPSS 0.1%CVE-2024-47102MEDIUMIBM AIX denial of serviceEPSS 0.1%CVE-2026-84560MEDIUMAn authorization issue was addressed with improved state management. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOSEPSS 0.1%CVE-2025-0360HIGHDuring an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the VAPIX Device Configuration fraEPSS 0.1%CVE-2025-4975MEDIUMTapo privilege escalation on shared devices using notificationsEPSS 0.1%