Falhas do tipo CWE-863

3.104 resultados

Falha em verificação de autorização

O software realiza uma verificação de autorização, mas a implementação está incorreta ou incompleta, permitindo que um atacante contorne as restrições de acesso pretendidas. O erro típico é lógica falha na verificação (condições mal formuladas, casos não tratados) ou confiança em dados do usuário para validar permissões.

Exemplo

Uma aplicação web valida se o usuário está autenticado, mas esquece de checar se ele tem permissão para acessar o recurso específico. Um atacante muda o ID do objeto na URL e acessa dados de outro usuário porque a aplicação não verifica propriedade ou role antes de retornar o conteúdo.

Como mitigar

Implemente verificações de autorização explícitas em todo ponto de acesso a recurso sensível, verificando não apenas quem é o usuário, mas se ele tem permissão específica para aquela ação. Use um modelo de controle de acesso bem definido (RBAC, ABAC) e teste sistematicamente casos de bypass (usuários não autorizados, escalação de privilégio, alteração de parâmetros).

CVE-2023-21390HIGHIn Sim, there is a possible way to evade mobile preference restrictions due to a permission bypass. This could lead to local escalation of pEPSS 0.1%CVE-2023-20800—In imgsys, there is a possible system crash due to a mssing ptr check. This could lead to local escalation of privilege with System executioEPSS 0.1%CVE-2026-13067HIGHtlsCATrusts Role Restriction Not Enforced via PROXY Protocol v2 on Unix Domain SocketEPSS 0.1%CVE-2023-21254—In getCurrentState of OneTimePermissionUserManager.java, there is a possible way to hold one-time permissions after the app is being killed EPSS 0.1%CVE-2023-20975HIGHIn getAvailabilityStatus of EnableContentCapturePreferenceController.java, there is a possible way to bypass DISALLOW_CONTENT_CAPTURE due toEPSS 0.1%CVE-2023-21245HIGHIn showNextSecurityScreenOrFinish of KeyguardSecurityContainerController.java, there is a possible way to access the lock screen during deviEPSS 0.1%CVE-2025-48523HIGHIn onCreate of SelectAccountActivity.java, there is a possible way to add contacts without permission due to a logic error in the code. ThisEPSS 0.1%CVE-2023-21116MEDIUMIn verifyReplacingVersionCode of InstallPackageHelper.java, there is a possible way to downgrade system apps below system image version due EPSS 0.1%CVE-2025-32333HIGHIn startSpaActivityForApp of SpaActivity.kt, there is a possible cross-user permission bypass due to a logic error in the code. This could lEPSS 0.1%CVE-2025-26436HIGHIn clearAllowBgActivityStarts of PendingIntentRecord.java, there is a possible way for an application to launch an activity from the backgroEPSS 0.1%CVE-2026-28663HIGHIn buildIntentSenderForUser of LauncherAppsService.java, there is a possible way to launch an activity from the background due to BAL BypassEPSS 0.1%CVE-2026-28620HIGHIn multiple locations, there is a possible unauthorized URI access due to a permissions bypass. This could lead to local escalation of priviEPSS 0.1%CVE-2022-33718MEDIUMAn improper access control vulnerability in Wi-Fi Service prior to SMR AUG-2022 Release 1 allows untrusted applications to manipulate the liEPSS 0.1%CVE-2025-47382HIGHIncorrect Authorization in BootEPSS 0.1%CVE-2023-20950HIGHIn AlarmManagerActivity of AlarmManagerActivity.java, there is a possible way to bypass background activity launch restrictions via a pendinEPSS 0.1%CVE-2023-21117HIGHIn registerReceiverWithFeature of ActivityManagerService.java, there is a possible way for isolated processes to register a broadcast receivEPSS 0.1%CVE-2025-26442MEDIUMIn onCreate of NotificationAccessConfirmationActivity.java, there is a possible incorrect verification of proper intent filters in NLS due tEPSS 0.1%CVE-2025-22428HIGHIn hasInteractAcrossUsersFullPermission of AppInfoBase.java, there is a possible way to grant permissions to an app on the secondary user frEPSS 0.1%CVE-2018-9374HIGHIn installPackageLI of PackageManagerService.java, there is a possible permissions bypass. This could lead to local escalation of privilege EPSS 0.1%CVE-2024-44099MEDIUMThere is a possible Local bypass of user interaction due to an insecure default value. This could lead to local information disclosure with EPSS 0.1%