Weaknesses of type CWE-305

169 results

Autenticação tecnicamente correta, mas bypassável por fraqueza secundária

A autenticação em si é implementada corretamente, mas há uma falha em outro ponto do código (validação de entrada, gestão de sessão, controle de acesso) que permite contorná-la sem quebrar o mecanismo de autenticação. É quando o algortimo está certo, mas a orquestração dele falha.

Example

Sistema verifica corretamente senha com hash bcrypt, mas aceita também um parâmetro de URL 'admin=true' que não é validado, permitindo bypass direto dos privilégios de autenticação. Ou: autenticação funciona, mas a geração de tokens de sessão usa sequência previsível ou reutiliza IDs antigos.

How to mitigate

Não confie só na função de autenticação isolada: revise toda a cadeia de autorização (validação de entrada, tratamento de sessão, controle de acesso). Faça teste de penetração focado em bypass, não só em quebra de autenticação; implemente múltiplas camadas de validação e nunca deixe parâmetros de privilégio sob controle do cliente.

CVE-2026-40039HIGHPachno 1.0.6 Open Redirection via return_to ParameterEPSS 0.3%CVE-2025-23017MEDIUMWorkOS Hosted AuthKit before 2025-01-07 allows a password authentication MFA bypass (by enrolling a new authentication factor) when the attaEPSS 0.3%CVE-2025-41450HIGHAuthentication bypass with privileged access in Danfoss AK-SM 8xxA Series prior to version 4.2EPSS 0.3%CVE-2025-4994HIGHAuthentication Bypass for SafeLine SL6 and SL6+EPSS 0.3%CVE-2024-49587CRITICALGlutton V1 endpoints missing authenticationEPSS 0.3%CVE-2025-47776HIGHMantisBT: Authentication bypass for some passwords due to PHP type jugglingEPSS 0.3%CVE-2026-9047HIGHImproper handling of factor key state in the multi-factor authentication management feature in Devolutions Server allows an attacker with knEPSS 0.3%CVE-2026-9571MEDIUMDeactivated user accounts can continue to obtain valid OAuth access tokens via refresh token grant in MattermostEPSS 0.3%CVE-2026-20152MEDIUMCisco Secure Web Appliance Authentication Service Traffic Bypass VulnerabilityEPSS 0.3%CVE-2024-9683MEDIUMQuay: quay allows successful authentication with trucated version of the passwordEPSS 0.3%CVE-2025-59980MEDIUMJunos OS: When a user with the name ftp or anonymous is configured unauthenticated filesystem access is allowedEPSS 0.3%CVE-2019-0042MEDIUMIncorrect messages from Juniper Identity Management Service (JIMS) can trigger Denial of Service or firewall bypass conditions for SRX series devicesEPSS 0.3%CVE-2026-1621MEDIUMRegister Bypass in Universal Sotware's E-MunicipalityEPSS 0.3%CVE-2020-10126NCR SelfServ ATMs running APTRA XFS 05.01.00 do not properly validate softare updates for the bunch note acceptor (BNA), enabling an attackeEPSS 0.3%CVE-2026-53561HIGHApache Hive: Unauthenticated authentication bypass in HiveServer2 HTTP SAML bearer-token validation allows impersonation of any Hive userEPSS 0.3%CVE-2024-4784MEDIUMAuthentication Bypass by Primary Weakness in GitLabEPSS 0.3%CVE-2026-1965MEDIUMbad reuse of HTTP Negotiate connectionEPSS 0.3%CVE-2025-1880LOWi-Drive i11/i12 Device Pairing authentication bypassEPSS 0.2%CVE-2026-62427HIGHsysctl and platform-op locks open to abuseEPSS 0.2%CVE-2025-59941MEDIUMgo-f3 is Vulnerable to Cached Justification Verification BypassEPSS 0.2%