Weaknesses of type CWE-290

607 results

Autenticação insuficiente contra falsificação de identidade

Ocorre quando o mecanismo de autenticação falha em validar corretamente a identidade do usuário ou cliente, permitindo que um atacante se passe por outra pessoa. A implementação não implementa verificações robustas (como criptografia, assinaturas digitais ou desafios aleatórios), deixando a autenticação vulnerável a spoofing.

Example

Um sistema de API que valida usuários apenas pelo campo 'nome de usuário' em um cabeçalho HTTP sem usar token, sessão ou assinatura criptográfica — um atacante altera o header e acessa dados de outros usuários. Ou um protocolo que aceita certificados autoassinados sem verificar a cadeia de confiança, autenticando servidores falsos.

How to mitigate

Use mecanismos de autenticação estabelecidos e testados: tokens JWT com assinatura, OAuth 2.0, ou mTLS. Sempre valide criptograficamente a identidade do cliente, nunca confie em cabeçalhos ou cookies não assinados. Implemente desafios multi-fator e revogue credenciais comprometidas rapidamente.

CVE-2023-29147—In Malwarebytes EDR 1.0.11 for Linux, it is possible to bypass the detection layers that depend on inode identifiers, because an identifier EPSS 0.3%CVE-2025-29621HIGHFrancois Jacquet RosarioSIS v12.0.0 was discovered to contain a content spoofing vulnerability in the Theme configuration under the My PrefeEPSS 0.3%CVE-2024-9391MEDIUMA user who enables full-screen mode on a specially crafted web page could potentially be prevented from exiting full screen mode. This may EPSS 0.3%CVE-2025-65046LOWMicrosoft Edge (Chromium-based) Spoofing VulnerabilityEPSS 0.3%CVE-2023-34160MEDIUMVulnerability of spoofing trustlists of Huawei desktop.Successful exploitation of this vulnerability can cause third-party apps to hide app EPSS 0.3%CVE-2026-15640CRITICALAuthentication Bypass via SAML Response ManipulationEPSS 0.3%CVE-2023-34158MEDIUMVulnerability of spoofing trustlists of Huawei desktop.Successful exploitation of this vulnerability can cause third-party apps to hide app EPSS 0.3%CVE-2023-34167MEDIUMVulnerability of spoofing trustlists of Huawei desktop.Successful exploitation of this vulnerability can cause third-party apps to hide app EPSS 0.3%CVE-2025-30142HIGHAn issue was discovered on G-Net Dashcam BB GONX devices. Bypassing of Device Pairing can occur. It uses MAC address verification as the solEPSS 0.3%CVE-2026-46356MEDIUMFleet: IP spoofing allows bypassing API rate limitingEPSS 0.3%CVE-2025-30110MEDIUMOn IROAD X5 devices, a Bypass of Device Pairing can occur via MAC Address Spoofing. The dashcam's pairing mechanism relies solely on MAC addEPSS 0.3%CVE-2024-8399MEDIUMWebsites could utilize Javascript links to spoof URL addresses in the Focus navigation bar This vulnerability affects Focus for iOS < 130.EPSS 0.3%CVE-2026-90447HIGHA routing rule selects between two different authentication mechanisms for the same downstream service based on the value of a client-suppliEPSS 0.3%CVE-2026-53849HIGHOpenClaw < 2026.5.7 - Privilege Escalation via Mutable Discord Display Names in allowFromEPSS 0.3%CVE-2026-31889HIGHShopware has a potential take over of app credentialsEPSS 0.3%CVE-2026-27089HIGHWordPress WpTravelly plugin <= 2.1.7 - Bypass Vulnerability vulnerabilityEPSS 0.3%CVE-2026-47737HIGHPuma PROXY Protocol v1 Accepts Repeated Protocol Headers on Persistent ConnectionsEPSS 0.3%CVE-2024-5812LOWSmart Rule Overwrite Bypass in BeyondInsight PasswordSafeEPSS 0.3%CVE-2024-1524HIGHA local user can be impersonated when using federated authentication with Silent JIT Provisioning.EPSS 0.3%CVE-2026-82530MEDIUMIP2Location Country Blocker < 2.45.0 Access Control Bypass via X-Real-IP HeaderEPSS 0.3%