Weaknesses of type CWE-290

607 results

Autenticação insuficiente contra falsificação de identidade

Ocorre quando o mecanismo de autenticação falha em validar corretamente a identidade do usuário ou cliente, permitindo que um atacante se passe por outra pessoa. A implementação não implementa verificações robustas (como criptografia, assinaturas digitais ou desafios aleatórios), deixando a autenticação vulnerável a spoofing.

Example

Um sistema de API que valida usuários apenas pelo campo 'nome de usuário' em um cabeçalho HTTP sem usar token, sessão ou assinatura criptográfica — um atacante altera o header e acessa dados de outros usuários. Ou um protocolo que aceita certificados autoassinados sem verificar a cadeia de confiança, autenticando servidores falsos.

How to mitigate

Use mecanismos de autenticação estabelecidos e testados: tokens JWT com assinatura, OAuth 2.0, ou mTLS. Sempre valide criptograficamente a identidade do cliente, nunca confie em cabeçalhos ou cookies não assinados. Implemente desafios multi-fator e revogue credenciais comprometidas rapidamente.

CVE-2025-36119HIGHIBM i authentication bypassEPSS 0.2%CVE-2024-39341MEDIUMEntrust Instant Financial Issuance (On Premise) Software (formerly known as Cardwizard) 6.10.0, 6.9.0, 6.9.1, 6.9.2, and 6.8.x and earlier lEPSS 0.2%CVE-2026-93511MEDIUMPremium Packages < 7.2.1 - Unauthenticated PayPal Webhook Signature Verification BypassEPSS 0.2%CVE-2024-36557MEDIUMThe device ID is based on IMEI in Forever KidsWatch Call Me KW50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h and Forever KidsWatch CallEPSS 0.2%CVE-2025-13636MEDIUMInappropriate implementation in Split View in Google Chrome prior to 143.0.7499.41 allowed a remote attacker who convinced a user to engage EPSS 0.2%CVE-2024-30190MEDIUMA vulnerability has been identified in SCALANCE W1748-1 M12 (6GK5748-1GY01-0AA0), SCALANCE W1748-1 M12 (6GK5748-1GY01-0TA0), SCALANCE W1788-EPSS 0.2%CVE-2026-63427HIGHAn authentication bypass vulnerability was discovered in Lenovo Software Fix that could allow a local authenticated user to perform arbitrarEPSS 0.2%CVE-2026-47123HIGHFreeScout: Agent Impersonation via Missing HMAC Verification on Notification Reply Message-ID PathEPSS 0.2%CVE-2026-94457MEDIUMWordPress Captcha Code plugin <= 3.32 - Bypass Vulnerability vulnerabilityEPSS 0.2%CVE-2024-27853MEDIUMThis issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.4. A maliciously crafted ZIP archive may bypass GatekeEPSS 0.2%CVE-2026-39411MEDIUMLobeHub has an unauthenticated authentication bypass on `webapi` routes via forgeable `X-lobe-chat-auth` headerEPSS 0.2%CVE-2023-6044MEDIUMA privilege escalation vulnerability was reported in Lenovo Vantage that could allow a local attacker with physical access to impersonate LeEPSS 0.2%CVE-2025-36754CRITICALAuthentication bypass on web interfaceEPSS 0.2%CVE-2026-46731HIGHDell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain an Authentication Bypass by Spoofing vulnerability. EPSS 0.2%CVE-2025-7448HIGHMan in the middle (MitM) attack vulnerability in Wi-SUN libraryEPSS 0.2%CVE-2026-6387HIGHA potential authentication bypass vulnerability was reported in Lenovo System Update that could allow a local authenticated user to execute EPSS 0.2%CVE-2023-41069MEDIUMThis issue was addressed by improving Face ID anti-spoofing models. This issue is fixed in iOS 17 and iPadOS 17. A 3D model constructed to lEPSS 0.2%CVE-2026-88819MEDIUMIn Siglet current and past versions the refresh token handler do not enforce proof of possession of the issuer DID.EPSS 0.2%CVE-2026-6090HIGHA potential authentication bypass was reported in Lenovo Smart Connect for Windows that could allow a local authenticated user to execute arEPSS 0.2%CVE-2026-39309MEDIUMTrilium Notes: macOS TCC Bypass via Prompt SpoofingEPSS 0.2%