Falhas do tipo CWE-862

7.125 resultados

Falha de verificação de autorização

A aplicação não valida se o usuário tem permissão para acessar um recurso ou executar uma ação específica. O código presume que quem chegou até ali já é confiável, pulando a checagem de privilégios. Qualquer atacante que consiga se autenticar (ou nem isso) pode fazer operações que deveria estar proibido.

Exemplo

Um admin painel que verifica login, mas depois deixa qualquer usuário logado deletar outros perfis acessando /admin/delete-user/123 diretamente. A autenticação existe, a autorização não.

Como mitigar

Implemente verificações de autorização (ACL, RBAC ou atributo-based) antes de cada operação sensível: confirme se o usuário tem a role ou permissão necessária. Não confie em autenticação alone — é login que prova quem você é, autorização que prova o que você pode fazer.

CVE-2022-39101HIGHIn power management service, there is a missing permission check. This could lead to set up power management service with no additional execEPSS 0.1%CVE-2022-39095HIGHIn power management service, there is a missing permission check. This could lead to set up power management service with no additional execEPSS 0.1%CVE-2022-39109HIGHIn Music service, there is a missing permission check. This could lead to elevation of privilege in Music service with no additional executiEPSS 0.1%CVE-2022-39111HIGHIn Music service, there is a missing permission check. This could lead to elevation of privilege in Music service with no additional executiEPSS 0.1%CVE-2022-39108HIGHIn Music service, there is a missing permission check. This could lead to elevation of privilege in Music service with no additional executiEPSS 0.1%CVE-2022-39099HIGHIn power management service, there is a missing permission check. This could lead to set up power management service with no additional execEPSS 0.1%CVE-2022-39100HIGHIn power management service, there is a missing permission check. This could lead to set up power management service with no additional execEPSS 0.1%CVE-2024-51516MEDIUMPermission control vulnerability in the ability module Impact: Successful exploitation of this vulnerability may cause features to function EPSS 0.1%CVE-2022-39097HIGHIn power management service, there is a missing permission check. This could lead to set up power management service with no additional execEPSS 0.1%CVE-2022-39098HIGHIn power management service, there is a missing permission check. This could lead to set up power management service with no additional execEPSS 0.1%CVE-2025-36192MEDIUMMissing Authorization with the DS8900F and DS8A00 Hardware Management ConsoleEPSS 0.1%CVE-2025-31171MEDIUMFile read permission bypass vulnerability in the kernel file system module Impact: Successful exploitation of this vulnerability may affect EPSS 0.1%CVE-2025-13348HIGHAn improper access control vulnerability exists in ASUS Secure Delete Driver of ASUS Business Manager. This vulnerability can be triggered bEPSS 0.1%CVE-2024-31332HIGHIn multiple locations, there is a possible way to bypass a restriction on adding new Wi-Fi connections due to a missing permission check. ThEPSS 0.1%CVE-2024-0052MEDIUMIn multiple functions of healthconnect, there is a possible leakage of exercise route data due to a missing permission check. This could leaEPSS 0.1%CVE-2022-20446LOWIn AlwaysOnHotwordDetector of AlwaysOnHotwordDetector.java, there is a possible way to access the microphone from the background due to a miEPSS 0.1%CVE-2022-38683MEDIUMIn contacts service, there is a missing permission check. This could lead to local denial of service in contacts service with no additional EPSS 0.1%CVE-2022-38678MEDIUMIn contacts service, there is a missing permission check. This could lead to local denial of service in contacts service with no additional EPSS 0.1%CVE-2022-39104MEDIUMIn contacts service, there is a missing permission check. This could lead to local denial of service in Contacts service with no additional EPSS 0.1%CVE-2025-5317MEDIUMImproper access restriction to critical folder in Bitdefender Endpoint Security Tools for MacEPSS 0.1%