Weaknesses of type CWE-290

606 results

Autenticação insuficiente contra falsificação de identidade

Ocorre quando o mecanismo de autenticação falha em validar corretamente a identidade do usuário ou cliente, permitindo que um atacante se passe por outra pessoa. A implementação não implementa verificações robustas (como criptografia, assinaturas digitais ou desafios aleatórios), deixando a autenticação vulnerável a spoofing.

Example

Um sistema de API que valida usuários apenas pelo campo 'nome de usuário' em um cabeçalho HTTP sem usar token, sessão ou assinatura criptográfica — um atacante altera o header e acessa dados de outros usuários. Ou um protocolo que aceita certificados autoassinados sem verificar a cadeia de confiança, autenticando servidores falsos.

How to mitigate

Use mecanismos de autenticação estabelecidos e testados: tokens JWT com assinatura, OAuth 2.0, ou mTLS. Sempre valide criptograficamente a identidade do cliente, nunca confie em cabeçalhos ou cookies não assinados. Implemente desafios multi-fator e revogue credenciais comprometidas rapidamente.

CVE-2026-24372HIGHWordPress Subscriptions for WooCommerce plugin <= 1.8.10 - Bypass Vulnerability vulnerabilityEPSS 0.5%CVE-2026-14450CRITICALMaas-billing: maas api: privilege escalation via forged http headers due to missing authenticationEPSS 0.5%CVE-2025-59319HIGHCPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to certify the integrity of the intended boot partition and selects the first pEPSS 0.5%CVE-2026-59157MEDIUMwebhookd: Unrestricted HTTP Header to Shell Variable InjectionEPSS 0.5%CVE-2025-48840MEDIUMAn authentication bypass by spoofing vulnerability in Fortinet FortiWeb 7.6.0 through 7.6.3, FortiWeb 7.4.0 through 7.4.8, FortiWeb 7.2 all EPSS 0.5%CVE-2024-32786MEDIUMWordPress Royal Elementor Addons and Templates plugin <= 1.3.93 - IP Bypass vulnerabilityEPSS 0.5%CVE-2025-12414CRITICALLooker account compromise via punycode homograph attackEPSS 0.5%CVE-2024-55470HIGHOqtane Framework 6.0.0 is vulnerable to Incorrect Access Control. By manipulating the entityid parameter, attackers can bypass passcode valiEPSS 0.5%CVE-2022-48513Vulnerability of identity verification being bypassed in the Gallery module. Successful exploitation of this vulnerability may cause out-of-EPSS 0.5%CVE-2026-80349CRITICALTarsWeb through 3.0.14 Authentication Bypass via Spoofed X-Forwarded-For and uid ParameterEPSS 0.5%CVE-2024-20384MEDIUMA vulnerability in the Network Service Group (NSG) feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat DeEPSS 0.4%CVE-2026-25660CRITICALAuthentication bypass for certain API callsEPSS 0.4%CVE-2026-21391CRITICALImproper Claim Validation in PingAM OIDC ProviderEPSS 0.4%CVE-2024-22092HIGHBundlemanager has an authentication bypass vulnerabilityEPSS 0.4%CVE-2026-33175HIGHOAuthenticator: Authentication Bypass in Auth0OAuthenticator via Unverified Email ClaimsEPSS 0.4%CVE-2026-3902HIGHASGI header spoofing via underscore/hyphen conflationEPSS 0.4%CVE-2026-0834HIGHLogic Vulnerability on TP-Link Archer C20, Archer AX53 and TL-WR841N v13EPSS 0.4%CVE-2023-51667MEDIUMWordPress Rate my Post – WP Rating System plugin <= 3.4.2 - Broken Access Control vulnerabilityEPSS 0.4%CVE-2024-22139LOWWordPress WordPress Manutenção plugin <= 1.0.6 - Bypass vulnerabilityEPSS 0.4%CVE-2026-47381MEDIUMNocoDB: Cross-Workspace Integration Use in Connection TestEPSS 0.4%