Fallos del tipo CWE-287

2450 resultados

Autenticação inadequada ou ausente

A aplicação não valida ou valida de forma insuficiente a identidade de quem tenta acessá-la. Quando um usuário diz ser quem é, o sistema acredita sem verificar corretamente, permitindo que atacantes se façam passar por outros usuários ou contas legítimas.

Ejemplo

Um sistema que aceita login apenas com nome de usuário, sem senha. Ou uma API que confia no header 'User-ID' enviado pelo cliente sem validar se aquele usuário realmente existe ou tem sessão ativa. Um atacante simplesmente altera o header e acessa dados de outra conta.

Cómo mitigar

Implemente autenticação robusta: exija múltiplos fatores (senha forte + MFA), valide credenciais contra base de dados segura, use sessões com token assinado e com expiração, nunca confie em dados enviados pelo cliente como prova de identidade. Revise regularmente logs de acesso para detectar abusos.

CVE-2026-29193HIGHZITADEL: Bypassing Zitadel Login Behavior and Security Policy in Login V2EPSS 0.3%CVE-2024-56335HIGHPrivilege escalation allows organization groups to be updated/deleted if their UUID is known in vaultwardenEPSS 0.3%CVE-2026-28800MEDIUMNatro Macro: Malicious actions allowed through Discord RC Commands by any userEPSS 0.3%CVE-2023-3591MEDIUMLack of previous password reset tokens on new token creationEPSS 0.3%CVE-2025-15346CRITICALwolfSSL Python library `CERT_REQUIRED` mode fails to enforce client certificate requirementEPSS 0.3%CVE-2026-81237MEDIUMDell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Improper Authentication vulnerability. An unauthenticated attacker wiEPSS 0.3%CVE-2024-3826HIGHBroken SAML ValidationEPSS 0.3%CVE-2026-71326LOWTraefik: BasicAuth singleflight key collision allows authenticated identity spoofingEPSS 0.3%CVE-2026-17628MEDIUMLangflow is affected by improper authentication due to missing password verification in the password reset endpointEPSS 0.3%CVE-2026-44720MEDIUMOpenLearnX: Critical Authentication Bypass via JWT Signature Verification Disabled Leading to Account TakeoverEPSS 0.3%CVE-2026-84623HIGHAn authorization issue was addressed with improved state management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27. EPSS 0.3%CVE-2026-60927HIGHVulnerability in the Oracle Public Sector Financials product of Oracle E-Business Suite (component: Internal Operations). Supported versionEPSS 0.3%CVE-2022-46774MEDIUMIBM Manage Application security bypassEPSS 0.3%CVE-2026-62493HIGHVulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affEPSS 0.3%CVE-2026-61188HIGHVulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Installation). The sEPSS 0.3%CVE-2026-60931HIGHVulnerability in the Oracle Public Sector Financials product of Oracle E-Business Suite (component: Internal Operations). Supported versionEPSS 0.3%CVE-2026-44351CRITICALfast-jwt: Empty HMAC secret accepted via async key resolver - JWT auth bypassEPSS 0.3%CVE-2026-60679HIGHVulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected areEPSS 0.3%CVE-2026-1410MEDIUMBeetel 777VR1 UART missing authenticationEPSS 0.3%CVE-2025-26438HIGHIn smp_process_secure_connection_oob_data of smp_act.cc, there is a possible way to bypass SMP authentication due to Incorrect implementatioEPSS 0.3%