Weaknesses of type CWE-290

607 results

Autenticação insuficiente contra falsificação de identidade

Ocorre quando o mecanismo de autenticação falha em validar corretamente a identidade do usuário ou cliente, permitindo que um atacante se passe por outra pessoa. A implementação não implementa verificações robustas (como criptografia, assinaturas digitais ou desafios aleatórios), deixando a autenticação vulnerável a spoofing.

Example

Um sistema de API que valida usuários apenas pelo campo 'nome de usuário' em um cabeçalho HTTP sem usar token, sessão ou assinatura criptográfica — um atacante altera o header e acessa dados de outros usuários. Ou um protocolo que aceita certificados autoassinados sem verificar a cadeia de confiança, autenticando servidores falsos.

How to mitigate

Use mecanismos de autenticação estabelecidos e testados: tokens JWT com assinatura, OAuth 2.0, ou mTLS. Sempre valide criptograficamente a identidade do cliente, nunca confie em cabeçalhos ou cookies não assinados. Implemente desafios multi-fator e revogue credenciais comprometidas rapidamente.

CVE-2025-13634MEDIUMInappropriate implementation in Downloads in Google Chrome on Windows prior to 143.0.7499.41 allowed a local attacker to bypass mark of the EPSS 0.2%CVE-2026-16404HIGHSpoofing issue in Firefox for AndroidEPSS 0.2%CVE-2023-7169MEDIUMImpersonate vendor signed Powershell scriptsEPSS 0.2%CVE-2026-75037HIGHPolkit authentication bypass in LACTEPSS 0.2%CVE-2026-28849MEDIUMThe issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5. A maliciouEPSS 0.2%CVE-2026-28900MEDIUMA file quarantine bypass was addressed with additional checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS TahoeEPSS 0.2%CVE-2026-44118HIGHOpenClaw < 2026.4.22 - Owner Context Spoofing via Bearer Token HeaderEPSS 0.2%CVE-2025-37147HIGHSecure Boot Bypass allows for Compromise of Hardware Root of TrustEPSS 0.2%CVE-2025-54305HIGHAn issue was discovered in the Thermo Fisher Torrent Suite Django application 5.18.1. One of the middlewares included in this application, LEPSS 0.2%CVE-2025-13635MEDIUMInappropriate implementation in Downloads in Google Chrome prior to 143.0.7499.41 allowed a local attacker to perform UI spoofing via a crafEPSS 0.1%CVE-2026-59916HIGHDell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain Improper Access Control vulnerability. A low privileEPSS 0.1%CVE-2026-53832HIGHOpenClaw < 2026.5.18 - Identity Header Forgery via Trusted-Proxy ConfigurationEPSS 0.1%CVE-2026-20071LOWISE 802.1x Session Hijack VulnerabilityEPSS 0.1%CVE-2026-61217MEDIUMVulnerability in the Oracle Security Service product of Oracle Fusion Middleware (component: Oracle SSL API). The supported version that iEPSS 0.1%CVE-2026-34778MEDIUMElectron: Service worker can spoof executeJavaScript IPC repliesEPSS 0.1%CVE-2026-65399MEDIUMA file quarantine bypass was addressed with additional checks. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS EPSS 0.1%CVE-2026-39959HIGHTmds.DBus: malicious D-Bus peers can spoof signals, exhaust file descriptor resources, and cause denial of serviceEPSS 0.1%CVE-2025-13455HIGHA vulnerability was reported in ThinkPlus configuration software that could allow a local authenticated user to bypass ThinkPlus device authEPSS 0.1%CVE-2025-27389MEDIUMApplication Installation Source Verification Flaw May Lead to Risk Detection BypassEPSS 0.1%CVE-2026-0292LOWPrisma Access Agent: Local Security Inspection Bypass Vulnerability on WindowsEPSS 0.1%