Weaknesses of type CWE-640

219 results

Mecanismo fraco de recuperação de senha

É quando o sistema oferece um fluxo para recuperar senhas perdidas, mas esse fluxo usa verificações insuficientes (perguntas fáceis de responder, tokens previsíveis, links sem expiração) ou permite múltiplas tentativas sem limite. Um atacante consegue contornar a autenticação e assumir a conta sem saber a senha original.

Example

Um site que envia um e-mail com link de reset contendo um ID sequencial (user_id=1001, user_id=1002...), sem expiração, ou que valida a recuperação apenas pedindo a 'data de nascimento' — dados frequentemente públicos em redes sociais.

How to mitigate

Use tokens criptograficamente seguros e aleatórios com expiração curta (15-30 min). Implemente rate limiting rigoroso no fluxo de recuperação, valide o link apenas uma vez e considere autenticação multi-fator (SMS, app authenticator) como segunda camada de confirmação.

CVE-2026-10169MEDIUMOUSL-GROUP-BrinaryBrains School Student Management System Forgot Password Endpoint Login.php ajax_forgot_password password recoveryEPSS 0.3%CVE-2026-14364CRITICALTrueBooker <= 1.2.3 - Missing Authorization to Unauthenticated Arbitrary Password Reset via 'tbab-userid'EPSS 0.3%CVE-2021-29038MEDIUMLiferay Portal 7.2.0 through 7.3.5, and older unsupported versions, and Liferay DXP 7.3 before fix pack 1, 7.2 before fix pack 17, and olderEPSS 0.3%CVE-2026-2543MEDIUMvichan-devel vichan Password Change pages.php unverified password changeEPSS 0.3%CVE-2026-19361MEDIUMmacrozheng mall mall-portal getAuthCode password recoveryEPSS 0.3%CVE-2026-9273CRITICALMembership Plugin – Kadence Memberships <= 4.0.0 - Unauthenticated Password Reset Link Poisoning to Account TakeoverEPSS 0.3%CVE-2026-61181HIGHVulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Product Quality ManageEPSS 0.3%CVE-2026-13020HIGHWeak Password Recovery Mechanism in Portal for ArcGISEPSS 0.3%CVE-2026-30459HIGHAn issue in the Forgot Password feature of Daylight Studio FuelCMS v1.5.2 allows unauthenticated attackers to obtain the password reset tokeEPSS 0.3%CVE-2026-72772HIGHn8n before 2.32.1 Authentication Bypass via Token ExchangeEPSS 0.3%CVE-2026-34408CRITICALAn issue was discovered in Gambio 4.9.2.0 (patched in 2024-02 v1.0.0 for GX4 v4.0.0.0 to v4.9.2.0). The password reset function can be bypasEPSS 0.3%CVE-2026-45013HIGHApostrophe has a Weak Password Recovery Mechanism for Forgotten Password and Improper Input ValidationEPSS 0.3%CVE-2026-29199HIGHphpBB before 3.3.16 is vulnerable to Host Header Injection that can lead to password rest link poisoning. When force_server_vars is disabledEPSS 0.2%CVE-2026-81905MEDIUMConcrete CMS below 9.5.3 does not enforce validation-hash type on redemption, allowing a hash issued for one purpose to be redeemed for another.EPSS 0.2%CVE-2026-35676HIGHphpMyFAQ - Unauthenticated Password Reset via User Password Update EndpointEPSS 0.2%CVE-2020-37158HIGHAVideo Platform 8.1 - Cross Site Request Forgery (Password Reset)EPSS 0.2%CVE-2026-22723MEDIUMUAA User Token Revocation logic errorEPSS 0.2%CVE-2026-9609MEDIUMQianFox FoxCMS Admin.php edit password recoveryEPSS 0.2%CVE-2025-56748MEDIUMCreativeitem Academy LMS up to and including 5.13 uses predictable password reset tokens based on Base64 encoded templates without rate limiEPSS 0.2%CVE-2026-40585HIGHblueprintUE: Password Reset Tokens Have No Expiry WindowEPSS 0.2%