Weaknesses of type CWE-1390

95 results

Autenticação Fraca

Mecanismos de autenticação que não verificam identidade com rigor suficiente, permitindo que atacantes se passem por usuários legítimos sem esforço significativo. Inclui senhas fracas aceitas, falta de validação adequada, ou métodos de autenticação facilmente contornáveis.

Example

Uma API que aceita login com apenas um email, sem senha ou segundo fator; ou um sistema que valida credenciais apenas no cliente (JavaScript), deixando o servidor confiar cegamente em qualquer requisição que diga estar autenticada.

How to mitigate

Implemente validação de credenciais forte no servidor (nunca no cliente), exija senhas com complexidade mínima, enforce autenticação multifator para contas sensíveis, e use protocolos padronizados (OAuth 2.0, SAML) em vez de esquemas caseiros.

CVE-2024-47397HIGHWeak authentication issue exists in AE1021 firmware versions 2.0.10 and earlier and AE1021PE firmware versions 2.0.10 and earlier. If this vEPSS 0.4%CVE-2025-30468MEDIUMThis issue was addressed through improved state management. This issue is fixed in iOS 26 and iPadOS 26. Private Browsing tabs may be accessEPSS 0.4%CVE-2024-29038MEDIUMtpm2 does not detect if quote was not generated by TPMEPSS 0.4%CVE-2025-1293HIGHHashiCorp Hermes Improperly Validates AWS ALB JWTs, which May Lead to Authentication BypassEPSS 0.3%CVE-2025-47479MEDIUMWordPress WP Compress plugin <= 6.30.30 - Broken Authentication VulnerabilityEPSS 0.3%CVE-2026-4924HIGHImproper authentication in the two-factor authentication (2FA) feature in Devolutions Server 2026.1.11 and earlier allows a remote attackeEPSS 0.3%CVE-2024-32119MEDIUMAn improper authentication vulnerability [CWE-287] in Fortinet FortiClientEMS version 7.4.0 and before 7.2.4 allows an unauthenticated attacEPSS 0.3%CVE-2026-44476MEDIUMDoorkeeper OpenID Connect: Dynamic Client Registration feature creates public clients with client_secretEPSS 0.3%CVE-2026-59135MEDIUMMicrosoft Windows Search Component Information Disclosure VulnerabilityEPSS 0.3%CVE-2026-1693MEDIUMUse of vulnerable Resource Owner Password Credentials flowEPSS 0.3%CVE-2026-68067CRITICALMira Hormone Monitor, Mira Android App Weak AuthenticationEPSS 0.3%CVE-2025-0605MEDIUMWeak Authentication in GitLabEPSS 0.3%CVE-2026-0274HIGHCortex XSOAR: Improper Validation of Credentials in CommvaultSecurityIQ integrationEPSS 0.3%CVE-2025-70994HIGHYadea T5 Electric Bicycles (models manufactured in/after 2024) have a weak authentication mechanism in their keyless entry system. The systeEPSS 0.3%CVE-2026-40417HIGHMicrosoft Dynamics 365 Business Central Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-57352MEDIUMWordPress ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce plugin <= 2.2.0 - Broken Authentication vulnerabilityEPSS 0.3%CVE-2026-4828HIGHImproper authentication in the OAuth login functionality in Devolutions Server 2026.1.11 and earlier allows a remote attacker with valid creEPSS 0.3%CVE-2024-5891MEDIUMQuay: unauthorized user may authenticate via oauth application tokenEPSS 0.2%CVE-2025-32885MEDIUMAn issue was discovered on goTenna v1 devices with app 5.5.3 and firmware 0.25.5. The app there makes it possible to inject any custom messaEPSS 0.2%CVE-2026-32497MEDIUMWordPress User Verification plugin <= 2.0.45 - Email Verification Bypass vulnerabilityEPSS 0.2%