Falhas do tipo CWE-863

3.042 resultados

Falha em verificação de autorização

O software realiza uma verificação de autorização, mas a implementação está incorreta ou incompleta, permitindo que um atacante contorne as restrições de acesso pretendidas. O erro típico é lógica falha na verificação (condições mal formuladas, casos não tratados) ou confiança em dados do usuário para validar permissões.

Exemplo

Uma aplicação web valida se o usuário está autenticado, mas esquece de checar se ele tem permissão para acessar o recurso específico. Um atacante muda o ID do objeto na URL e acessa dados de outro usuário porque a aplicação não verifica propriedade ou role antes de retornar o conteúdo.

Como mitigar

Implemente verificações de autorização explícitas em todo ponto de acesso a recurso sensível, verificando não apenas quem é o usuário, mas se ele tem permissão específica para aquela ação. Use um modelo de controle de acesso bem definido (RBAC, ABAC) e teste sistematicamente casos de bypass (usuários não autorizados, escalação de privilégio, alteração de parâmetros).

CVE-2026-40452HIGHApache IoTDB: Authorization bypass in /rest/v2/fastLastQuery exposes last-value data to unauthorized authenticated usersEPSS 0.4%CVE-2025-2003HIGHIncorrect authorization in PAM vaults in Devolutions Server 2024.3.12 and earlier allows an authenticated user to bypass the 'add in root' pEPSS 0.4%CVE-2026-42349HIGHClerk: Authorization bypass when combining organization, billing, or reverification checksEPSS 0.4%CVE-2026-57951HIGHMythic < 3.4.0.60 - Broken Permission Filter in payload_build_step TableEPSS 0.4%CVE-2024-28627HIGHAn issue in Flipsnack v.18/03/2024 allows a local attacker to obtain sensitive information via the reader.gz.js file.EPSS 0.4%CVE-2026-55672HIGHZITADEL: Missing client_id binding in OIDC authorization code exchange and refresh token flows (RFC 6749 Section 4.1.3 violation)EPSS 0.4%CVE-2022-39302MEDIUMRee6 may bypass webhook protectionEPSS 0.4%CVE-2025-21560MEDIUMVulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: SDK-Software Development Kit). The supported veEPSS 0.4%CVE-2026-67439MEDIUMOliveTin: StartActionAndWait Endpoints Bypass `logs` Permission and Return Action OutputEPSS 0.4%CVE-2023-3590LOWDeleted attachments in Boards remain accessibleEPSS 0.4%CVE-2024-54916MEDIUMAn issue in the SharedConfig class of Telegram Android APK v.11.7.0 allows a physically proximate attacker to bypass authentication and escaEPSS 0.4%CVE-2024-21275HIGHVulnerability in the Oracle Quoting product of Oracle E-Business Suite (component: User Interface). Supported versions that are affected arEPSS 0.4%CVE-2024-45586CRITICALAccount Take Over VulnerabilityEPSS 0.4%CVE-2026-60663CRITICALVulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions tEPSS 0.4%CVE-2024-21277HIGHVulnerability in the Oracle MES for Process Manufacturing product of Oracle E-Business Suite (component: Device Integration). Supported verEPSS 0.4%CVE-2026-33576MEDIUMOpenClaw < 2026.3.28 - Unauthorized Media Download via Zalo ChannelEPSS 0.4%CVE-2026-54357MEDIUMMISP improper authorization allows organization administrators to modify site administrator user settingsEPSS 0.4%CVE-2026-46366HIGHphpMyFAQ - Unauthenticated Information Disclosure via getIdFromSolutionId Permission BypassEPSS 0.4%CVE-2025-4646HIGHA high privilege user is able to create and use a valid admin API token in centreon-webEPSS 0.4%CVE-2026-35442HIGHDirectus: Authenticated Users Can Extract Concealed Fields via Aggregate QueriesEPSS 0.4%