Falhas do tipo CWE-863

2.980 resultados

Falha em verificação de autorização

O software realiza uma verificação de autorização, mas a implementação está incorreta ou incompleta, permitindo que um atacante contorne as restrições de acesso pretendidas. O erro típico é lógica falha na verificação (condições mal formuladas, casos não tratados) ou confiança em dados do usuário para validar permissões.

Exemplo

Uma aplicação web valida se o usuário está autenticado, mas esquece de checar se ele tem permissão para acessar o recurso específico. Um atacante muda o ID do objeto na URL e acessa dados de outro usuário porque a aplicação não verifica propriedade ou role antes de retornar o conteúdo.

Como mitigar

Implemente verificações de autorização explícitas em todo ponto de acesso a recurso sensível, verificando não apenas quem é o usuário, mas se ele tem permissão específica para aquela ação. Use um modelo de controle de acesso bem definido (RBAC, ABAC) e teste sistematicamente casos de bypass (usuários não autorizados, escalação de privilégio, alteração de parâmetros).

CVE-2021-20179A flaw was found in pki-core. An attacker who has successfully compromised a key could use this flaw to renew the corresponding certificate EPSS 1.2%CVE-2023-27526MEDIUMApache Superset: Improper Authorization check on import chartsEPSS 1.2%CVE-2023-26829CRITICALAn authentication bypass vulnerability in the Password Reset component of Gladinet CentreStack before 13.5.9808 allows remote attackers to sEPSS 1.2%CVE-2025-27696MEDIUMApache Superset: Incorrect authorization leading to resource ownership takeoverEPSS 1.2%CVE-2022-0670A flaw was found in Openstack manilla owning a Ceph File system "share", which enables the owner to read/write any manilla share or entire fEPSS 1.2%CVE-2022-21706HIGHMulti-use invitations can grant access to other organizations in ZulipEPSS 1.2%CVE-2022-39956HIGHPartial rule set bypass in OWASP ModSecurity Core Rule Set for HTTP multipart requests using character encoding in the Content-Type or Content-Transfer-Encoding headerEPSS 1.2%CVE-2026-24780HIGHAutoGPT is Vulnerable to RCE via Disabled Block ExecutionEPSS 1.2%CVE-2024-27138HIGHApache Archiva: disabling user registration is not effectiveEPSS 1.2%CVE-2022-0580HIGHIncorrect Authorization in librenms/librenmsEPSS 1.2%CVE-2026-47101HIGHLiteLLM < 1.83.14 Privilege Escalation via API Key GenerationEPSS 1.2%CVE-2024-28394CRITICALAn issue in Advanced Plugins reportsstatistics v1.3.20 and before allows a remote attacker to execute arbitrary code via the Sales Reports, EPSS 1.2%CVE-2021-39156HIGHFragments in Path May Lead to Authorization Policy BypassEPSS 1.2%CVE-2022-21713MEDIUMExposure of Sensitive Information in GrafanaEPSS 1.2%CVE-2022-0981A flaw was found in Quarkus. The state and potentially associated permissions can leak from one web request to another in RestEasy Reactive.EPSS 1.2%CVE-2026-48286CRITICALAdobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863)EPSS 1.2%CVE-2022-42344HIGH[CVE-2021-36032] Magento IDOR Leads to Account TakeoverEPSS 1.2%CVE-2021-34647MEDIUMNinja Forms <= 3.5.7 Sensitive Information DisclosureEPSS 1.2%CVE-2022-24721HIGHIncorrect Authorization in org.cometd.oortEPSS 1.1%CVE-2023-36387MEDIUMApache Superset: Improper API permission for low privilege usersEPSS 1.1%