Weaknesses of type CWE-1390
97 resultsAutenticação Fraca
Mecanismos de autenticação que não verificam identidade com rigor suficiente, permitindo que atacantes se passem por usuários legítimos sem esforço significativo. Inclui senhas fracas aceitas, falta de validação adequada, ou métodos de autenticação facilmente contornáveis.
Example
Uma API que aceita login com apenas um email, sem senha ou segundo fator; ou um sistema que valida credenciais apenas no cliente (JavaScript), deixando o servidor confiar cegamente em qualquer requisição que diga estar autenticada.
How to mitigate
Implemente validação de credenciais forte no servidor (nunca no cliente), exija senhas com complexidade mínima, enforce autenticação multifator para contas sensíveis, e use protocolos padronizados (OAuth 2.0, SAML) em vez de esquemas caseiros.
CVE-2025-40554CRITICALSolarWinds Web Help Desk Authentication Bypass VulnerabilityEPSS 59.2%CVE-2025-40552CRITICALSolarWinds Web Help Desk Authentication Bypass VulnerabilityEPSS 49.7%CVE-2026-55040CRITICALMicrosoft SharePoint Server Security Feature Bypass VulnerabilityEPSS 17.5%KEVCVE-2025-27740HIGHActive Directory Certificate Services Elevation of Privilege VulnerabilityEPSS 3.4%CVE-2024-49019HIGHActive Directory Certificate Services Elevation of Privilege VulnerabilityEPSS 2.0%CVE-2024-38239HIGHWindows Kerberos Elevation of Privilege VulnerabilityEPSS 1.7%CVE-2025-26635MEDIUMWindows Hello Security Feature Bypass VulnerabilityEPSS 1.5%CVE-2023-24890MEDIUMMicrosoft OneDrive for iOS Security Feature Bypass VulnerabilityEPSS 1.2%CVE-2024-8322MEDIUMWeak authentication in Patch Management of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker tEPSS 1.1%CVE-2026-65098HIGHNVIDIA NemoClaw for Linux contains a vulnerability in its remote-access helper workflow, where an attacker could cause weak authentication. EPSS 1.0%CVE-2025-24070HIGHASP.NET Core and Visual Studio Elevation of Privilege VulnerabilityEPSS 1.0%CVE-2024-35248HIGHMicrosoft Dynamics 365 Business Central Elevation of Privilege VulnerabilityEPSS 1.0%CVE-2022-43400CRITICALA vulnerability has been identified in Siveillance Video Mobile Server V2022 R2 (All versions < V22.2a (80)). The mobile server component ofEPSS 0.9%CVE-2023-41900LOWJetty's OpenId Revoked authentication allows one requestEPSS 0.9%CVE-2025-26343HIGHA CWE-1390 "Weak Authentication" in the PIN authentication mechanism in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthEPSS 0.9%CVE-2026-73025CRITICALWindows iSCSI Security Feature Bypass VulnerabilityEPSS 0.9%CVE-2024-38182CRITICALMicrosoft Dynamics 365 Elevation of Privilege VulnerabilityEPSS 0.9%CVE-2023-49340CRITICALAn issue was discovered in Newland Nquire 1000 Interactive Kiosk version NQ1000-II_G_V1.00.011, allows remote attackers to escalate privilegEPSS 0.9%CVE-2026-6886CRITICALBorG Technology Corporation|Borg SPM 2007 - Authentication BypassEPSS 0.8%CVE-2025-59249HIGHMicrosoft Exchange Server Elevation of Privilege VulnerabilityEPSS 0.8%