Weaknesses of type CWE-290

607 results

Autenticação insuficiente contra falsificação de identidade

Ocorre quando o mecanismo de autenticação falha em validar corretamente a identidade do usuário ou cliente, permitindo que um atacante se passe por outra pessoa. A implementação não implementa verificações robustas (como criptografia, assinaturas digitais ou desafios aleatórios), deixando a autenticação vulnerável a spoofing.

Example

Um sistema de API que valida usuários apenas pelo campo 'nome de usuário' em um cabeçalho HTTP sem usar token, sessão ou assinatura criptográfica — um atacante altera o header e acessa dados de outros usuários. Ou um protocolo que aceita certificados autoassinados sem verificar a cadeia de confiança, autenticando servidores falsos.

How to mitigate

Use mecanismos de autenticação estabelecidos e testados: tokens JWT com assinatura, OAuth 2.0, ou mTLS. Sempre valide criptograficamente a identidade do cliente, nunca confie em cabeçalhos ou cookies não assinados. Implemente desafios multi-fator e revogue credenciais comprometidas rapidamente.

CVE-2026-19291HIGHBluetooth re-pairing can use a lower security level than previousEPSS 0.2%CVE-2026-16101HIGHforced re-pairing with already bonded deviceEPSS 0.2%CVE-2026-33223MEDIUMNATS Server: Incomplete Stripping of Nats-Request-Info Header Allows Identity SpoofingEPSS 0.2%CVE-2026-5792MEDIUMAuthentication Bypass in Hedef Media's Related Marketing Cloud (RMC)EPSS 0.2%CVE-2026-28480MEDIUMOpenClaw < 2026.2.14 - Identity Spoofing via Mutable Username in Telegram Allowlist AuthorizationEPSS 0.2%CVE-2026-53823HIGHOpenClaw < 2026.5.3 - Privilege Escalation via Mutable Slack Display Names in allowFromEPSS 0.2%CVE-2026-89327LOWFluentBoards < 2.0.15 - Board Member+ Comment Author Spoofing via 'comment_by' ParameterEPSS 0.2%CVE-2026-54763HIGHTraefik: headerField underscore-variant identity spoofing in BasicAuth / DigestAuth / ForwardAuthEPSS 0.2%CVE-2025-48906HIGHAuthentication bypass vulnerability in the DSoftBus module Impact: Successful exploitation of this vulnerability may affect availability.EPSS 0.2%CVE-2026-88879MEDIUMTraefik before v2.11.56 Identity Spoofing via Header AliasEPSS 0.2%CVE-2026-72809HIGHSiYuan before v3.7.4 Authentication Bypass via Localhost TrustEPSS 0.2%CVE-2026-66674MEDIUMWordPress Simple Cloudflare Turnstile plugin <= 1.42.1 - Captcha Bypass vulnerabilityEPSS 0.2%CVE-2026-93511MEDIUMPremium Packages < 7.2.1 - Unauthenticated PayPal Webhook Signature Verification BypassEPSS 0.2%CVE-2026-64797HIGHJoomla Extension - regularlabs.com - IP spoofing vulnerability in IP login extensionEPSS 0.2%CVE-2026-8676HIGHAn attacker is able to downgrade the security of a Bluetooth LE connection by deleting an existing bond, spoofing the bonded device and creaEPSS 0.2%CVE-2025-66270MEDIUMThe KDE Connect protocol 8 before 2025-11-28 does not correlate device IDs across two packets. This affects KDE Connect before 25.12 on deskEPSS 0.2%CVE-2026-84766MEDIUMWordPress FluentBooking Pro plugin <= 2.2.1 - Bypass Vulnerability vulnerabilityEPSS 0.2%CVE-2025-36119HIGHIBM i authentication bypassEPSS 0.2%CVE-2024-39341MEDIUMEntrust Instant Financial Issuance (On Premise) Software (formerly known as Cardwizard) 6.10.0, 6.9.0, 6.9.1, 6.9.2, and 6.8.x and earlier lEPSS 0.2%CVE-2024-36557MEDIUMThe device ID is based on IMEI in Forever KidsWatch Call Me KW50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h and Forever KidsWatch CallEPSS 0.2%