Weaknesses of type CWE-290

607 results

Autenticação insuficiente contra falsificação de identidade

Ocorre quando o mecanismo de autenticação falha em validar corretamente a identidade do usuário ou cliente, permitindo que um atacante se passe por outra pessoa. A implementação não implementa verificações robustas (como criptografia, assinaturas digitais ou desafios aleatórios), deixando a autenticação vulnerável a spoofing.

Example

Um sistema de API que valida usuários apenas pelo campo 'nome de usuário' em um cabeçalho HTTP sem usar token, sessão ou assinatura criptográfica — um atacante altera o header e acessa dados de outros usuários. Ou um protocolo que aceita certificados autoassinados sem verificar a cadeia de confiança, autenticando servidores falsos.

How to mitigate

Use mecanismos de autenticação estabelecidos e testados: tokens JWT com assinatura, OAuth 2.0, ou mTLS. Sempre valide criptograficamente a identidade do cliente, nunca confie em cabeçalhos ou cookies não assinados. Implemente desafios multi-fator e revogue credenciais comprometidas rapidamente.

CVE-2024-43944LOWWordPress Maintenance & Coming Soon Redirect Animation plugin <= 2.3.3 - Bypass Vulnerability vulnerabilityEPSS 0.4%CVE-2026-86478CRITICALIn JetBrains YouTrack before 2025.3.161254, 2026.1.14042 improper authentication in YouTrack Helpdesk allowed unauthenticated account takeoEPSS 0.4%CVE-2026-49353HIGH9Router: Local-Only Access Gate Bypass in 9router via Host Header SpoofINGEPSS 0.4%CVE-2025-31122CRITICALscratch-coding-hut.github.io Login Links Generation vulnerabilityEPSS 0.4%CVE-2023-34157CRITICALVulnerability of HwWatchHealth being hijacked.Successful exploitation of this vulnerability may cause repeated pop-up windows of the app.EPSS 0.4%CVE-2024-8901MEDIUMLack of JWT issuer and signer validationEPSS 0.4%CVE-2023-48271MEDIUMWordPress Maspik – Spam Blacklist plugin <= 0.10.3 - IP Filtering Bypass vulnerabilityEPSS 0.4%CVE-2025-54288MEDIUMSource Container Identification Vulnerability via cmdline Spoofing in devLXD ServerEPSS 0.4%CVE-2023-48753MEDIUMWordPress Restricted Site Access plugin <= 7.4.1 - IP Restriction Bypass vulnerabilityEPSS 0.4%CVE-2026-84186MEDIUMIncorrect access control in PrestaShopEPSS 0.3%CVE-2025-26696HIGHCrafted email message incorrectly shown as being encryptedEPSS 0.3%CVE-2026-76835CRITICALOAuth2 Proxy 7.15.2 through 7.15.4 Authentication Bypass via X-Forwarded-Uri Under the Default Trusted Proxy SetEPSS 0.3%CVE-2022-4098HIGHWiesemann & Theis: Multiple products prone to missing authentication through spoofingEPSS 0.3%CVE-2026-73995MEDIUMWordPress User Registration plugin <= 5.2.6 - Broken Authentication vulnerabilityEPSS 0.3%CVE-2025-24628MEDIUMWordPress reCaptcha by BestWebSoft Plugin <= 1.78 - Captcha Bypass vulnerabilityEPSS 0.3%CVE-2026-86863CRITICALpgAdmin 4: Authentication bypass via a client-controlled identity header in Webserver authentication modeEPSS 0.3%CVE-2023-42889MEDIUMThe issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.1, macOS Monterey 12.7.1, macOS Ventura 13.6.1. An app EPSS 0.3%CVE-2025-58595MEDIUMWordPress All In One Login plugin <= 2.0.8 - Bypass Vulnerability vulnerabilityEPSS 0.3%CVE-2025-3029HIGHURL Bar Spoofing via non-BMP Unicode charactersEPSS 0.3%CVE-2025-69401HIGHWordPress WooODT Lite plugin <= 2.5.2 - Payment Bypass Vulnerability vulnerabilityEPSS 0.3%