Weaknesses of type CWE-290

607 results

Autenticação insuficiente contra falsificação de identidade

Ocorre quando o mecanismo de autenticação falha em validar corretamente a identidade do usuário ou cliente, permitindo que um atacante se passe por outra pessoa. A implementação não implementa verificações robustas (como criptografia, assinaturas digitais ou desafios aleatórios), deixando a autenticação vulnerável a spoofing.

Example

Um sistema de API que valida usuários apenas pelo campo 'nome de usuário' em um cabeçalho HTTP sem usar token, sessão ou assinatura criptográfica — um atacante altera o header e acessa dados de outros usuários. Ou um protocolo que aceita certificados autoassinados sem verificar a cadeia de confiança, autenticando servidores falsos.

How to mitigate

Use mecanismos de autenticação estabelecidos e testados: tokens JWT com assinatura, OAuth 2.0, ou mTLS. Sempre valide criptograficamente a identidade do cliente, nunca confie em cabeçalhos ou cookies não assinados. Implemente desafios multi-fator e revogue credenciais comprometidas rapidamente.

CVE-2025-11209HIGHInappropriate implementation in Omnibox in Google Chrome on Android prior to 141.0.7390.54 allowed a remote attacker to spoof the contents oEPSS 0.2%CVE-2026-27700HIGHHono is Vulnerable to Authentication Bypass by IP Spoofing in AWS Lambda ALB conninfoEPSS 0.2%CVE-2026-63329MEDIUMWarpgate: x-warpgate-username Header Not Stripped from Client Requests Enables Identity Spoofing to WebSocket Backend TargetsEPSS 0.2%CVE-2025-9265CRITICALAPI Authentication Bypass via Header Spoofing vulnerability in Kiloview NDI N30 ProductsEPSS 0.2%CVE-2026-0385MEDIUMMicrosoft Edge (Chromium-based) for Android Spoofing VulnerabilityEPSS 0.2%CVE-2024-44104HIGHAn incorrectly implemented authentication scheme that is subjected to a spoofing attack in the management console of Ivanti Workspace ControEPSS 0.2%CVE-2026-73840MEDIUMOpenChoreo: Unauthenticated build/workflow trigger via git-provider confusion (webhook signature bypass)EPSS 0.2%CVE-2026-88011MEDIUMTraefik: ForwardAuth identity spoofing via dot-form header aliasEPSS 0.2%CVE-2026-4728MEDIUMSpoofing issue in the Privacy: Anti-Tracking componentEPSS 0.2%CVE-2026-82228HIGHWordPress SiteGround Security plugin <= 1.6.6 - 2FA Bypass vulnerabilityEPSS 0.2%CVE-2026-45056MEDIUMMatrix Rust SDK: Sender-binding gaps in to-device and room-key attributionEPSS 0.2%CVE-2024-30191HIGHA vulnerability has been identified in SCALANCE W1748-1 M12 (6GK5748-1GY01-0AA0), SCALANCE W1748-1 M12 (6GK5748-1GY01-0TA0), SCALANCE W1788-EPSS 0.2%CVE-2025-59154MEDIUMOpenfire allows potential identity spoofing via unsafe CN parsingEPSS 0.2%CVE-2026-65502MEDIUMWordPress Element Pack Elementor Addons plugin <= 8.7.13 - Captcha Bypass vulnerabilityEPSS 0.2%CVE-2026-32469MEDIUMWordPress CAPTCHA 4WP plugin <= 7.6.0 - Captcha Bypass vulnerabilityEPSS 0.2%CVE-2023-5616MEDIUMIn Ubuntu, gnome-control-center did not properly reflect SSH remote login status when the system was configured to use systemd socket activaEPSS 0.2%CVE-2025-60868MEDIUMThe Alt Redirect 1.6.3 addon for Statamic fails to consistently strip query string parameters when the "Query String Strip" feature is enablEPSS 0.2%CVE-2026-65570HIGHWordPress Login with phone number plugin <= 1.8.70 - Bypass vulnerability vulnerabilityEPSS 0.2%CVE-2026-63683HIGHJoomla Extension - regularlabs.com - Client IP spoofing vulnerability in Regular Labs conditions managerEPSS 0.2%CVE-2026-53857HIGHOpenClaw < 2026.5.3 - Mutable Display Name Binding in Zalo allowFrom PolicyEPSS 0.2%