Weaknesses of type CWE-290

607 results

Autenticação insuficiente contra falsificação de identidade

Ocorre quando o mecanismo de autenticação falha em validar corretamente a identidade do usuário ou cliente, permitindo que um atacante se passe por outra pessoa. A implementação não implementa verificações robustas (como criptografia, assinaturas digitais ou desafios aleatórios), deixando a autenticação vulnerável a spoofing.

Example

Um sistema de API que valida usuários apenas pelo campo 'nome de usuário' em um cabeçalho HTTP sem usar token, sessão ou assinatura criptográfica — um atacante altera o header e acessa dados de outros usuários. Ou um protocolo que aceita certificados autoassinados sem verificar a cadeia de confiança, autenticando servidores falsos.

How to mitigate

Use mecanismos de autenticação estabelecidos e testados: tokens JWT com assinatura, OAuth 2.0, ou mTLS. Sempre valide criptograficamente a identidade do cliente, nunca confie em cabeçalhos ou cookies não assinados. Implemente desafios multi-fator e revogue credenciais comprometidas rapidamente.

CVE-2026-19538HIGHBypass of BLOCKED ACL items on proxy protocol port over TCP or TLSEPSS 0.2%CVE-2023-5616MEDIUMIn Ubuntu, gnome-control-center did not properly reflect SSH remote login status when the system was configured to use systemd socket activaEPSS 0.2%CVE-2026-27478CRITICALUnity Catalog has a JWT Issuer Validation Bypass Allows Complete User ImpersonationEPSS 0.2%CVE-2025-60868MEDIUMThe Alt Redirect 1.6.3 addon for Statamic fails to consistently strip query string parameters when the "Query String Strip" feature is enablEPSS 0.2%CVE-2026-21862HIGHRustFS sourceIp bypass via spoofed X-Forwarded-For/Real-IP headersEPSS 0.2%CVE-2023-27199—PAX Technology A930 PayDroid_7.1.1_Virgo_V04.5.02_20220722 allows attackers to compile a malicious shared library and use LD_PRELOAD to bypaEPSS 0.2%CVE-2026-48063CRITICALBaileys has message upsert / hist sync spoofing and app state corruption when using maliciously crafted protocolMessage payloadEPSS 0.2%CVE-2025-24458HIGHIn JetBrains YouTrack before 2024.3.55417 account takeover was possible via spoofed email and Helpdesk integrationEPSS 0.2%CVE-2025-67298HIGHAn issue in ClasroomIO before v.0.2.6 allows a remote attacker to escalate privileges via the endpoints /api/verify and /rest/v1/profileEPSS 0.2%CVE-2025-71056HIGHImproper session management in GCOM EPON 1GE ONU version C00R371V00B01 allows attackers to execute a session hijacking attack via spoofing tEPSS 0.2%CVE-2026-31813MEDIUMSupabase Auth has insecure Apple and Azure authentication with ID tokensEPSS 0.2%CVE-2024-30189MEDIUMA vulnerability has been identified in SCALANCE W721-1 RJ45 (6GK5721-1FC00-0AA0) (All versions), SCALANCE W721-1 RJ45 (6GK5721-1FC00-0AB0) (EPSS 0.2%CVE-2024-58124HIGHAccess control vulnerability in the security verification module Impact: Successful exploitation of this vulnerability will affect integrityEPSS 0.2%CVE-2024-58125HIGHAccess control vulnerability in the security verification module Impact: Successful exploitation of this vulnerability will affect integrityEPSS 0.2%CVE-2024-58126HIGHAccess control vulnerability in the security verification module Impact: Successful exploitation of this vulnerability will affect integrityEPSS 0.2%CVE-2024-58127HIGHAccess control vulnerability in the security verification module Impact: Successful exploitation of this vulnerability will affect integrityEPSS 0.2%CVE-2025-31170HIGHAccess control vulnerability in the security verification module Impact: Successful exploitation of this vulnerability will affect integrityEPSS 0.2%CVE-2025-48906HIGHAuthentication bypass vulnerability in the DSoftBus module Impact: Successful exploitation of this vulnerability may affect availability.EPSS 0.2%CVE-2026-62987MEDIUMFabio - Incomplete fix for CVE-2025-48865: operator-configured trust headers (clientip/tls/requestid) still strippable via the Connection headerEPSS 0.2%CVE-2025-66270MEDIUMThe KDE Connect protocol 8 before 2025-11-28 does not correlate device IDs across two packets. This affects KDE Connect before 25.12 on deskEPSS 0.2%