Falhas do tipo CWE-862

7.332 resultados

Falha de verificação de autorização

A aplicação não valida se o usuário tem permissão para acessar um recurso ou executar uma ação específica. O código presume que quem chegou até ali já é confiável, pulando a checagem de privilégios. Qualquer atacante que consiga se autenticar (ou nem isso) pode fazer operações que deveria estar proibido.

Exemplo

Um admin painel que verifica login, mas depois deixa qualquer usuário logado deletar outros perfis acessando /admin/delete-user/123 diretamente. A autenticação existe, a autorização não.

Como mitigar

Implemente verificações de autorização (ACL, RBAC ou atributo-based) antes de cada operação sensível: confirme se o usuário tem a role ou permissão necessária. Não confie em autenticação alone — é login que prova quem você é, autorização que prova o que você pode fazer.

CVE-2022-0543CRITICALIt was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific) Lua sandbox escapeEPSS 99.3%KEVCVE-2023-52163HIGHDigiever DS-2105 Pro 3.1.0.71-11 devices allow time_tzsetup.cgi Command Injection. NOTE: This vulnerability only affects products that are nEPSS 96.9%KEVCVE-2022-1329HIGHElementor Website Builder 3.6.0 - 3.6.2 - Missing Authorization to Remote Code ExecutionEPSS 92.7%CVE-2023-6875CRITICALPOST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress <= 2.8.7 - Authorization Bypass via type connect-app APIEPSS 90.3%CVE-2021-21307HIGHRemote Code Exploit in Lucee AdminEPSS 89.2%CVE-2025-20362MEDIUMUpdate: On November 5, 2025, Cisco became aware of a new attack variant against devices running Cisco Secure ASA Software or Cisco Secure FTEPSS 85.5%KEVCVE-2023-26035HIGHZoneMinder vulnerable to Missing AuthorizationEPSS 80.5%CVE-2022-23944Apache ShenYu 2.4.1 Improper access controlEPSS 79.0%CVE-2024-41730CRITICALMissing Authentication check in SAP BusinessObjects Business Intelligence PlatformEPSS 75.9%CVE-2024-31997CRITICALXWiki Platform remote code execution from account through UIExtension parametersEPSS 73.9%CVE-2025-8943CRITICALUnsupervised OS command execution leads to remote code execution by unauthenticated network attackersEPSS 72.3%CVE-2025-6205CRITICALMissing authorization vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025EPSS 71.1%KEVCVE-2021-45467CRITICALIn CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1107, an unauthenticated attacker can use %00 bytes to cause /user/loader.phEPSS 70.9%CVE-2022-0218HIGHWP HTML Mail <= 3.0.9 Missing Authorization on REST-API RouteEPSS 70.5%CVE-2021-30657MEDIUMA logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina. A EPSS 68.5%KEVCVE-2023-25573HIGHImproper access control to download file in metersphereEPSS 51.6%CVE-2025-11833CRITICALPost SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App <= 3.6.0 - Missing Authorization to Account Takeover via Unauthenticated Email Log DisclosureEPSS 51.0%CVE-2024-1380MEDIUMRelevanssi – A Better Search <= 4.22.0 (Free) and <= 2.25.0 (Premium) - Missing Authorization to Unauthenticated Query Log ExportEPSS 50.2%CVE-2025-5394CRITICALAlone – Charity Multipurpose Non-profit WordPress Theme <= 7.8.3 - Missing Authorization to Unauthenticated Arbitrary File Upload via Plugin InstallationEPSS 49.5%CVE-2021-21246HIGHPre-Auth Access token leakEPSS 49.1%