Weaknesses of type CWE-290

607 results

Autenticação insuficiente contra falsificação de identidade

Ocorre quando o mecanismo de autenticação falha em validar corretamente a identidade do usuário ou cliente, permitindo que um atacante se passe por outra pessoa. A implementação não implementa verificações robustas (como criptografia, assinaturas digitais ou desafios aleatórios), deixando a autenticação vulnerável a spoofing.

Example

Um sistema de API que valida usuários apenas pelo campo 'nome de usuário' em um cabeçalho HTTP sem usar token, sessão ou assinatura criptográfica — um atacante altera o header e acessa dados de outros usuários. Ou um protocolo que aceita certificados autoassinados sem verificar a cadeia de confiança, autenticando servidores falsos.

How to mitigate

Use mecanismos de autenticação estabelecidos e testados: tokens JWT com assinatura, OAuth 2.0, ou mTLS. Sempre valide criptograficamente a identidade do cliente, nunca confie em cabeçalhos ou cookies não assinados. Implemente desafios multi-fator e revogue credenciais comprometidas rapidamente.

CVE-2023-49741LOWWordPress Coming soon and Maintenance mode plugin <= 3.7.3 - IP Filtering Bypass vulnerabilityEPSS 0.3%CVE-2023-47769LOWWordPress WP Maintenance plugin <= 6.1.3 - IP Filtering Bypass vulnerabilityEPSS 0.3%CVE-2024-45453LOWWordPress Maintenance Redirect plugin <= 2.0.1 - IP Bypass vulnerabilityEPSS 0.3%CVE-2026-52690MEDIUMSpoofed answers can mark an authoritative non-EDNS capableEPSS 0.3%CVE-2025-2188HIGHWhitelist bypass Vulnerability in GameCenterEPSS 0.3%CVE-2025-0442MEDIUMInappropriate implementation in Payments in Google Chrome prior to 132.0.6834.83 allowed a remote attacker who convinced a user to engage inEPSS 0.3%CVE-2025-50328HIGHA vulnerability in B1 Free Archiver v1.5.86 allows files extracted from downloaded archives to bypass Windows Mark of the Web (MotW) protectEPSS 0.3%CVE-2025-66570CRITICALcpp-httplib Untrusted HTTP Header Handling: Internal Header Shadowing (REMOTE*/LOCAL*)EPSS 0.3%CVE-2024-31802MEDIUMDESIGNA ABACUS v.18 and before allows an attacker to bypass the payment process via a crafted QR code.EPSS 0.3%CVE-2026-8644CRITICALIBM WebSphere Application Server is affected by an identity spoofing vulnerabilityEPSS 0.3%CVE-2026-69183HIGHMonkeytype: Rate-limit and anti-brute-force controls bypassable via spoofed HTTP headers (forgotPasswordEmail/verificationEmail mail bombing and badAuth bypass)EPSS 0.3%CVE-2026-7656HIGHBroken IPv6 Neighbor Discovery input validation allows spoofed RA/NS/NA acceptance in Zephyr net stackEPSS 0.3%CVE-2026-77089CRITICALCommand Center API Authentication BypassEPSS 0.3%CVE-2025-59699MEDIUMEntrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a physiEPSS 0.3%CVE-2026-32666HIGHAutomated Logic WebCTRL Premium Server Authentication Bypass by SpoofingEPSS 0.3%CVE-2026-6213CRITICALRemote Spark SparkView RCEEPSS 0.3%CVE-2024-10125MEDIUMLack of JWT issuer and signer validationEPSS 0.3%CVE-2026-55641HIGH9router: Unauthenticated `/v1` proxy access via `Host`-header spoofing → open AI relay + SSRFEPSS 0.3%CVE-2026-8961MEDIUMSpoofing issue in the Form Autofill componentEPSS 0.3%CVE-2025-36753HIGHSWD Interface Open on Growatt ShineLan-XEPSS 0.3%