Weaknesses of type CWE-290

607 results

Autenticação insuficiente contra falsificação de identidade

Ocorre quando o mecanismo de autenticação falha em validar corretamente a identidade do usuário ou cliente, permitindo que um atacante se passe por outra pessoa. A implementação não implementa verificações robustas (como criptografia, assinaturas digitais ou desafios aleatórios), deixando a autenticação vulnerável a spoofing.

Example

Um sistema de API que valida usuários apenas pelo campo 'nome de usuário' em um cabeçalho HTTP sem usar token, sessão ou assinatura criptográfica — um atacante altera o header e acessa dados de outros usuários. Ou um protocolo que aceita certificados autoassinados sem verificar a cadeia de confiança, autenticando servidores falsos.

How to mitigate

Use mecanismos de autenticação estabelecidos e testados: tokens JWT com assinatura, OAuth 2.0, ou mTLS. Sempre valide criptograficamente a identidade do cliente, nunca confie em cabeçalhos ou cookies não assinados. Implemente desafios multi-fator e revogue credenciais comprometidas rapidamente.

CVE-2026-21862HIGHRustFS sourceIp bypass via spoofed X-Forwarded-For/Real-IP headersEPSS 0.2%CVE-2023-27199—PAX Technology A930 PayDroid_7.1.1_Virgo_V04.5.02_20220722 allows attackers to compile a malicious shared library and use LD_PRELOAD to bypaEPSS 0.2%CVE-2026-82180CRITICALIn Eclipse Arrowhead versions from 5.0.0 to 5.2.1 when the MQTT API is enabled with the certificate authentication policy, CertificateMqttFiEPSS 0.2%CVE-2026-14840MEDIUMYOP Poll < 7.0.6 - Unauthenticated Vote Restriction Bypass via IP Header SpoofingEPSS 0.2%CVE-2026-42602HIGHazureauthextension Authenticate method does not validate bearer tokens, allowing auth bypass via replayEPSS 0.2%CVE-2026-39419LOWMaxKB: Sandbox Result Validation Bypass via Tool Output SpoofingEPSS 0.2%CVE-2026-44183CRITICALCleanuparr: X-Forwarded-For leftmost parsing allows remote unauthenticated admin takeover when reverse-proxy mode is enabledEPSS 0.2%CVE-2026-13143MEDIUMWP Travel < 11.8.1 - Unauthenticated Payment Bypass via Forged PayPal IPNEPSS 0.2%CVE-2025-24458HIGHIn JetBrains YouTrack before 2024.3.55417 account takeover was possible via spoofed email and Helpdesk integrationEPSS 0.2%CVE-2026-72816MEDIUMgo-chi chi before 5.3.0 IP Spoofing via RealIP MiddlewareEPSS 0.2%CVE-2025-67298HIGHAn issue in ClasroomIO before v.0.2.6 allows a remote attacker to escalate privileges via the endpoints /api/verify and /rest/v1/profileEPSS 0.2%CVE-2026-44649CRITICALSillyTavern: Authentication Bypass via SSO Header InjectionEPSS 0.2%CVE-2025-71056HIGHImproper session management in GCOM EPON 1GE ONU version C00R371V00B01 allows attackers to execute a session hijacking attack via spoofing tEPSS 0.2%CVE-2024-30189MEDIUMA vulnerability has been identified in SCALANCE W721-1 RJ45 (6GK5721-1FC00-0AA0) (All versions), SCALANCE W721-1 RJ45 (6GK5721-1FC00-0AB0) (EPSS 0.2%CVE-2026-64875MEDIUMJoomla Extension - regularlabs.com - IP spoofing vulnerability in GeoIP extensionEPSS 0.2%CVE-2024-58127HIGHAccess control vulnerability in the security verification module Impact: Successful exploitation of this vulnerability will affect integrityEPSS 0.2%CVE-2024-58125HIGHAccess control vulnerability in the security verification module Impact: Successful exploitation of this vulnerability will affect integrityEPSS 0.2%CVE-2024-58126HIGHAccess control vulnerability in the security verification module Impact: Successful exploitation of this vulnerability will affect integrityEPSS 0.2%CVE-2024-58124HIGHAccess control vulnerability in the security verification module Impact: Successful exploitation of this vulnerability will affect integrityEPSS 0.2%CVE-2025-31170HIGHAccess control vulnerability in the security verification module Impact: Successful exploitation of this vulnerability will affect integrityEPSS 0.2%