Weaknesses of type CWE-290

607 results

Autenticação insuficiente contra falsificação de identidade

Ocorre quando o mecanismo de autenticação falha em validar corretamente a identidade do usuário ou cliente, permitindo que um atacante se passe por outra pessoa. A implementação não implementa verificações robustas (como criptografia, assinaturas digitais ou desafios aleatórios), deixando a autenticação vulnerável a spoofing.

Example

Um sistema de API que valida usuários apenas pelo campo 'nome de usuário' em um cabeçalho HTTP sem usar token, sessão ou assinatura criptográfica — um atacante altera o header e acessa dados de outros usuários. Ou um protocolo que aceita certificados autoassinados sem verificar a cadeia de confiança, autenticando servidores falsos.

How to mitigate

Use mecanismos de autenticação estabelecidos e testados: tokens JWT com assinatura, OAuth 2.0, ou mTLS. Sempre valide criptograficamente a identidade do cliente, nunca confie em cabeçalhos ou cookies não assinados. Implemente desafios multi-fator e revogue credenciais comprometidas rapidamente.

CVE-2026-53817HIGHOpenClaw < 2026.5.22 - Control UI Locality Spoofing in Device PairingEPSS 0.3%CVE-2025-12430HIGHObject lifecycle issue in Media in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to perform UI spoofing via a crafted HTML EPSS 0.3%CVE-2024-23558MEDIUMHCL DevOps Deploy / HCL Launch does not invalidate all session authentication cookies after logoutEPSS 0.3%CVE-2026-33621MEDIUMPinchTab: Unapplied Rate Limiting Middleware Allows Unbounded Brute-Force of API TokenEPSS 0.3%CVE-2025-61778CRITICALAkka.Remote TLS did not properly implement certificate-based authenticationEPSS 0.3%CVE-2024-39337MEDIUMClick Studios Passwordstate Core before 9.8 build 9858 allows Authentication Bypass.EPSS 0.3%CVE-2025-69203MEDIUMSignal K Server Vulnerable to Access Request SpoofingEPSS 0.3%CVE-2026-0890MEDIUMSpoofing issue in the DOM: Copy & Paste and Drag & Drop componentEPSS 0.3%CVE-2026-92395CRITICAL@fastify/proxy-addr vulnerable to IP spoofing via IPv4-mapped IPv6 trust subnetEPSS 0.3%CVE-2025-46018MEDIUMCSC Pay Mobile App 2.19.4 (fixed in version 2.20.0) contains a vulnerability allowing users to bypass payment authorization by disabling BluEPSS 0.3%CVE-2025-68644HIGHYealink RPS before 2025-06-27 allows unauthorized access to information, including AutoP URL addresses. This was fixed by deploying an enhanEPSS 0.3%CVE-2026-8963HIGHSpoofing issue in the Web Speech componentEPSS 0.3%CVE-2026-19538HIGHBypass of BLOCKED ACL items on proxy protocol port over TCP or TLSEPSS 0.3%CVE-2025-50454MEDIUMAn Authentication Bypass vulnerability in Blue Access' Cobalt X1 thru 02.000.187 allows an unauthorized attacker to log into the applicationEPSS 0.3%CVE-2026-54308MEDIUMn8n: Missing Token Validation on Microsoft Agent 365 Trigger NodeEPSS 0.3%CVE-2026-58575HIGHDell PowerStore contains an Authentication Bypass by Spoofing vulnerability. An authenticated attacker could potentially exploit this vulnerEPSS 0.3%CVE-2024-35749LOWWordPress Under Construction / Maintenance Mode from Acurax plugin <= 2.6 - IP Bypass vulnerabilityEPSS 0.3%CVE-2026-40854HIGHSession auth bypass via cookie value in T-Mobile 5G Box IDU routersEPSS 0.3%CVE-2026-6181MEDIUMThe Device Configuration Framework is vulnerable to an authentication bypass flaw. This flaw can only be exploited after authenticating withEPSS 0.3%CVE-2025-10530MEDIUMSpoofing issue in the WebAuthn component in Firefox for AndroidEPSS 0.3%