Falhas do tipo CWE-863

3.050 resultados

Falha em verificação de autorização

O software realiza uma verificação de autorização, mas a implementação está incorreta ou incompleta, permitindo que um atacante contorne as restrições de acesso pretendidas. O erro típico é lógica falha na verificação (condições mal formuladas, casos não tratados) ou confiança em dados do usuário para validar permissões.

Exemplo

Uma aplicação web valida se o usuário está autenticado, mas esquece de checar se ele tem permissão para acessar o recurso específico. Um atacante muda o ID do objeto na URL e acessa dados de outro usuário porque a aplicação não verifica propriedade ou role antes de retornar o conteúdo.

Como mitigar

Implemente verificações de autorização explícitas em todo ponto de acesso a recurso sensível, verificando não apenas quem é o usuário, mas se ele tem permissão específica para aquela ação. Use um modelo de controle de acesso bem definido (RBAC, ABAC) e teste sistematicamente casos de bypass (usuários não autorizados, escalação de privilégio, alteração de parâmetros).

CVE-2025-53943HIGHVoidBot Open-Source Has Improper Permission Check That Allows Unauthorized Command ExecutionEPSS 0.3%CVE-2024-25149MEDIUMLiferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 15, and oEPSS 0.3%CVE-2026-15388MEDIUMCookie Consent < 0.0.10 - Subscriber+ Consent Settings Update and Consent Log DisclosureEPSS 0.3%CVE-2026-48076MEDIUMOpenReception's bootstrap booking flow allows unauthenticated booking on isPublic=false channelsEPSS 0.3%CVE-2025-48881HIGHValtimo backend libraries allows objects in the object-api to be accessed and modified by unauthorized usersEPSS 0.3%CVE-2026-47238MEDIUMClipBucket: IDOR in videos subtitle editorEPSS 0.3%CVE-2026-21722MEDIUMPublic Dashboards time range restriction on annotations can be bypassedEPSS 0.3%CVE-2026-40213HIGHOpenStack Cyborg before 16.0.1 uses rule:allow (check_str='@') as the default policy for multiple API endpoints. This unconditionally authorEPSS 0.3%CVE-2024-5539CRITICALALC WebCTRL Carrier i-Vu Access Control BypassEPSS 0.3%CVE-2023-5553HIGHDuring internal Axis Security Development Model (ASDM) threat-modelling, a flaw was found in the protection for device tampering (commonly kEPSS 0.3%CVE-2026-5374MEDIUMrunZero Platform MCP information leakEPSS 0.3%CVE-2025-4972LOWIncorrect Authorization in GitLabEPSS 0.3%CVE-2026-5384MEDIUMrunZero Platform incorrect credential scopeEPSS 0.3%CVE-2026-55472MEDIUMSnipe-IT: API Location Creation Bypasses FMCS Parent-Child Company Boundary ValidationEPSS 0.3%CVE-2026-77786MEDIUMRank Math SEO < 1.0.277 - Editor+ Core Settings Modification via fix-site-seo AbilityEPSS 0.3%CVE-2026-63309MEDIUMSurrealDB < 3.1.5 Information Disclosure via ORDER BYEPSS 0.3%CVE-2026-89267MEDIUMstarlette-admin 0.16.1 through 0.17.1 Searchable Fields Allowlist BypassEPSS 0.3%CVE-2021-3469—Foreman versions before 2.3.4 and before 2.4.0 is affected by an improper authorization handling flaw. An authenticated attacker can impersoEPSS 0.3%CVE-2025-59683HIGHPexip Infinity 15.0 through 38.0 before 38.1 has Improper Access Control in the Secure Scheduler for Exchange service, when used with OfficeEPSS 0.3%CVE-2026-46635MEDIUMTwig: Sandbox property allowlist bypass via the `column` filter (array_column on objects)EPSS 0.3%