Weaknesses of type CWE-290

606 results

Autenticação insuficiente contra falsificação de identidade

Ocorre quando o mecanismo de autenticação falha em validar corretamente a identidade do usuário ou cliente, permitindo que um atacante se passe por outra pessoa. A implementação não implementa verificações robustas (como criptografia, assinaturas digitais ou desafios aleatórios), deixando a autenticação vulnerável a spoofing.

Example

Um sistema de API que valida usuários apenas pelo campo 'nome de usuário' em um cabeçalho HTTP sem usar token, sessão ou assinatura criptográfica — um atacante altera o header e acessa dados de outros usuários. Ou um protocolo que aceita certificados autoassinados sem verificar a cadeia de confiança, autenticando servidores falsos.

How to mitigate

Use mecanismos de autenticação estabelecidos e testados: tokens JWT com assinatura, OAuth 2.0, ou mTLS. Sempre valide criptograficamente a identidade do cliente, nunca confie em cabeçalhos ou cookies não assinados. Implemente desafios multi-fator e revogue credenciais comprometidas rapidamente.

CVE-2020-27276SOOIL Developments Co Ltd DiabecareRS,AnyDana-i & AnyDana-A, the communication protocol of the insulin pump and its AnyDana-i & AnyDana-A moEPSS 0.5%CVE-2026-33661HIGHWeChat Pay callback signature verification bypassed when Host header is localhostEPSS 0.5%CVE-2026-53791CRITICALrsync < 3.5.0 Daemon IP Spoofing via PROXY Protocol HeaderEPSS 0.5%CVE-2026-56675HIGH9router: Reverse proxy locality collapse allows unauthenticated access to 9router /v1 APIsEPSS 0.5%CVE-2024-8935HIGHCWE-290: Authentication Bypass by Spoofing vulnerability exists that could cause a denial of service and loss of confidentiality and integriEPSS 0.5%CVE-2026-62644MEDIUMIn Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the password plugin of the Roundcube Webmail was subject to username spoofing viaEPSS 0.5%CVE-2024-50380HIGHAuthentication Bypass by Spoofing in Snap One OVRC cloudEPSS 0.5%CVE-2026-56020CRITICALWebmin HTTP header authentication bypassEPSS 0.5%CVE-2024-30522MEDIUMWordPress Newsletter plugin <= 8.2.0 - IP Blacklist Bypass vulnerabilityEPSS 0.5%CVE-2026-76949CRITICALRemember-me sign-in guard reads a session key that is never written in ash_authentication, allowing session replacementEPSS 0.5%CVE-2023-6263HIGHServer Spoofing Vulnerability in NxCloudEPSS 0.5%CVE-2026-33654HIGHZero-Click Indirect Prompt Injection and Authentication Bypass via Email PollingEPSS 0.5%CVE-2026-45074HIGHSymfony: Cas2Handler Derives CAS service URL from Client Host Header → Cross-Service Ticket ReplayEPSS 0.5%CVE-2025-22223MEDIUMSpring Security 6.4.0 - 6.4.3 may not correctly locate method security annotations on parameterized types or methods. This may cause an authEPSS 0.5%CVE-2025-36594CRITICALDell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3.0.15, LTS2024 releasEPSS 0.5%CVE-2023-20245MEDIUMMultiple vulnerabilities in the per-user-override feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat DefEPSS 0.5%CVE-2024-28228MEDIUMIn JetBrains YouTrack before 2024.1.25893 creation comments on behalf of an arbitrary user in HelpDesk was possibleEPSS 0.5%CVE-2026-92929MEDIUMOpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 trusts an X-Forwarded-For header supplied by an arbitrary client when determiniEPSS 0.5%CVE-2026-21894MEDIUMn8n's Missing Stripe-Signature Verification Allows Unauthenticated Forged WebhooksEPSS 0.5%CVE-2024-20299MEDIUMCisco Adaptive Security Appliance and Firepower Threat Defense AnyConnect Access Control List Bypass VulnerabilityEPSS 0.5%