Falhas do tipo CWE-863

3.050 resultados

Falha em verificação de autorização

O software realiza uma verificação de autorização, mas a implementação está incorreta ou incompleta, permitindo que um atacante contorne as restrições de acesso pretendidas. O erro típico é lógica falha na verificação (condições mal formuladas, casos não tratados) ou confiança em dados do usuário para validar permissões.

Exemplo

Uma aplicação web valida se o usuário está autenticado, mas esquece de checar se ele tem permissão para acessar o recurso específico. Um atacante muda o ID do objeto na URL e acessa dados de outro usuário porque a aplicação não verifica propriedade ou role antes de retornar o conteúdo.

Como mitigar

Implemente verificações de autorização explícitas em todo ponto de acesso a recurso sensível, verificando não apenas quem é o usuário, mas se ele tem permissão específica para aquela ação. Use um modelo de controle de acesso bem definido (RBAC, ABAC) e teste sistematicamente casos de bypass (usuários não autorizados, escalação de privilégio, alteração de parâmetros).

CVE-2024-28174MEDIUMIn JetBrains TeamCity before 2023.11.4 presigned URL generation requests in S3 Artifact Storage plugin were authorized improperlyEPSS 0.3%CVE-2023-38486HIGHHardware Root of Trust Bypass in 9200 and 9000 Series Controllers and GatewaysEPSS 0.3%CVE-2026-28666HIGHIn multiple functions of LocalImageResolver.java, there is a possible Remote Persistent Denial of Service due to a DNG image rendering checkEPSS 0.3%CVE-2026-34364MEDIUMAVideo has User Group-Based Category Access Control Bypass via Missing and Broken Group Filtering in categories.json.phpEPSS 0.3%CVE-2026-41232MEDIUMFroxlor has an Email Sender Alias Domain Ownership Bypass via Wrong Array Index that Allows Cross-Customer Email SpoofingEPSS 0.3%CVE-2026-87544HIGHIncorrect authorization in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictionsEPSS 0.3%CVE-2023-5194LOWA system/user manager can demote / deactivate another managerEPSS 0.3%CVE-2026-76019HIGHIncorrect authorization in Workers in Google Chrome prior to 151.0.7922.173 allowed a remote attacker who had compromised the renderer proceEPSS 0.3%CVE-2026-5952MEDIUMIncorrect Authorization in GitLabEPSS 0.3%CVE-2025-40670HIGHIncorrect Authorization vulnerability in TCMAN GIMEPSS 0.3%CVE-2024-50671MEDIUMIncorrect access control in Adapt Learning Adapt Authoring Tool <= 0.11.3 allows attackers with Authenticated User roles to obtain email addEPSS 0.3%CVE-2024-47159MEDIUMIn JetBrains YouTrack before 2024.3.44799 user without appropriate permissions could restore workflows attached to a projectEPSS 0.3%CVE-2025-21562MEDIUMVulnerability in the PeopleSoft Enterprise CC Common Application Objects product of Oracle PeopleSoft (component: Run Control Management). EPSS 0.3%CVE-2026-68951MEDIUMGROWI contains an incorrect authorization vulnerability. If this vulnerability is exploited, an unauthenticated attacker could retrieve the EPSS 0.3%CVE-2026-61672HIGHCapsule: Tenant owner bypasses Capsule's forbidden namespace/service/node label and annotation enforcementEPSS 0.3%CVE-2024-57438MEDIUMInsecure permissions in RuoYi v4.8.0 allows authenticated attackers to escalate privileges by assigning themselves higher level roles.EPSS 0.3%CVE-2026-33470MEDIUMFrigate has cross-camera snapshot disclosure via unrestricted timeline IDs and missing authorization in /api/events/{event_id}/snapshot-clean.webpEPSS 0.3%CVE-2024-25149MEDIUMLiferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 15, and oEPSS 0.3%CVE-2026-30854MEDIUMParse Server: GraphQL `__type` introspection bypass via inline fragments when public introspection is disabledEPSS 0.3%CVE-2026-65602MEDIUMTraefik before 3.6.23 IngressRouteTCP ServersTransport Namespace BypassEPSS 0.3%