Fallos del tipo CWE-287

2450 resultados

Autenticação inadequada ou ausente

A aplicação não valida ou valida de forma insuficiente a identidade de quem tenta acessá-la. Quando um usuário diz ser quem é, o sistema acredita sem verificar corretamente, permitindo que atacantes se façam passar por outros usuários ou contas legítimas.

Ejemplo

Um sistema que aceita login apenas com nome de usuário, sem senha. Ou uma API que confia no header 'User-ID' enviado pelo cliente sem validar se aquele usuário realmente existe ou tem sessão ativa. Um atacante simplesmente altera o header e acessa dados de outra conta.

Cómo mitigar

Implemente autenticação robusta: exija múltiplos fatores (senha forte + MFA), valide credenciais contra base de dados segura, use sessões com token assinado e com expiração, nunca confie em dados enviados pelo cliente como prova de identidade. Revise regularmente logs de acesso para detectar abusos.

CVE-2025-49012MEDIUMHimmelblau's Name-Based Group Matching in `pam_allow_groups` Leads to Potential Security BypassEPSS 0.3%CVE-2025-67507HIGHFilament's multi-factor authentication (app) recovery codes can be used multiple timesEPSS 0.3%CVE-2026-49502HIGHDell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Authentication vulnerability. An unauthenticated attacker with aEPSS 0.3%CVE-2024-51997HIGHThe Attestation Results Token can be arbitrarily modified without being detected in TrusteeEPSS 0.3%CVE-2024-5798LOWVault Incorrectly Validated JSON Web Tokens (JWT) Audience ClaimsEPSS 0.3%CVE-2024-58363MEDIUMSurrealDB before 1.5.4 Authentication Bypass via Database SwitchEPSS 0.3%CVE-2026-14568MEDIUMWP User Frontend < 4.3.8 - Unauthenticated Author-less Attachment DeletionEPSS 0.3%CVE-2026-18056HIGHHivePress Authentication <= 1.1.4 - Unauthenticated Authentication Bypass via 'access_token' Parameter to Facebook AuthenticatorEPSS 0.3%CVE-2022-4001HIGHAn authentication bypass vulnerability could allow an attacker to access API functions without authentication.EPSS 0.3%CVE-2025-65781HIGHAn issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Attachment upload API treats the AEPSS 0.3%CVE-2025-64423HIGHCoolify has a Privilege Escalation - low privileged users can see and use admin invitation linksEPSS 0.3%CVE-2026-89080HIGHReally Simple Security < 9.8.1 - Unauthenticated 2FA Bypass via Email Provider State DemotionEPSS 0.3%CVE-2026-63238MEDIUMAuthentication bypass vulnerabilityEPSS 0.3%CVE-2024-0130HIGHNVIDIA UFM Enterprise, UFM Appliance, and UFM CyberAI contain a vulnerability where an attacker can cause an improper authentication issue bEPSS 0.3%CVE-2023-42554MEDIUMImproper Authentication vulnerabiity in Samsung Pass prior to version 4.3.00.17 allows physical attackers to bypass authentication.EPSS 0.3%CVE-2025-24292MEDIUMA misconfigured query in UniFi Network (v9.1.120 and earlier) could allow users to authenticate to Enterprise WiFi or VPN Server (l2tp and OEPSS 0.3%CVE-2025-65127MEDIUMA lack of session validation in the web API component of Shenzhen Zhibotong Electronics ZBT WE2001 23.09.27 allows remote unauthenticated atEPSS 0.3%CVE-2025-7699HIGHAn improper access control vulnerability was found in the EZ Sync Manager of ADMEPSS 0.3%CVE-2026-18221HIGHIBM i is Affected By Improper Authorization and Authentication Vulnerabilities in DDM / DRDA [, ]EPSS 0.3%CVE-2026-53561HIGHApache Hive: Unauthenticated authentication bypass in HiveServer2 HTTP SAML bearer-token validation allows impersonation of any Hive userEPSS 0.3%