Fallos del tipo CWE-287

2451 resultados

Autenticação inadequada ou ausente

A aplicação não valida ou valida de forma insuficiente a identidade de quem tenta acessá-la. Quando um usuário diz ser quem é, o sistema acredita sem verificar corretamente, permitindo que atacantes se façam passar por outros usuários ou contas legítimas.

Ejemplo

Um sistema que aceita login apenas com nome de usuário, sem senha. Ou uma API que confia no header 'User-ID' enviado pelo cliente sem validar se aquele usuário realmente existe ou tem sessão ativa. Um atacante simplesmente altera o header e acessa dados de outra conta.

Cómo mitigar

Implemente autenticação robusta: exija múltiplos fatores (senha forte + MFA), valide credenciais contra base de dados segura, use sessões com token assinado e com expiração, nunca confie em dados enviados pelo cliente como prova de identidade. Revise regularmente logs de acesso para detectar abusos.

CVE-2025-6505HIGHUnauthorized access and impersonation can occur in versions 4.6.2.3226 and below of Progress Software's Hybrid Data Pipeline Server on LinuxEPSS 0.3%CVE-2025-3627MEDIUMMoodle: partial data exposure in moodle before completing multi-factor authenticationEPSS 0.3%CVE-2024-28188MEDIUMjupyter-scheduler's endpoint is missing authenticationEPSS 0.3%CVE-2025-15135MEDIUMjoey-zhou xiaozhi-esp32-server-java Cookie AuthenticationInterceptor.java tryAuthenticateWithCookies improper authenticationEPSS 0.3%CVE-2025-64103HIGHZitadel Bypass Second Authentication FactorEPSS 0.3%CVE-2026-56353MEDIUMn8n - Authentication Bypass in Chat Trigger NodeEPSS 0.3%CVE-2018-19937MEDIUMA local, authenticated attacker can bypass the passcode in the VideoLAN VLC media player app before 3.1.5 for iOS by opening a URL and turniEPSS 0.3%CVE-2026-27968MEDIUMPackistry accepts expired access tokensEPSS 0.3%CVE-2025-56578MEDIUMAn issue in RTSPtoWeb v.2.4.3 allows a remote attacker to obtain sensitive information and executearbitrary code via the lack of authenticatEPSS 0.3%CVE-2020-7323MEDIUMAuthentication Protection Bypass vulnerability in ENS for WindowsEPSS 0.3%CVE-2024-49755LOWDuende IdentityServer has insufficient validation of DPoP cnf claim in Local APIsEPSS 0.3%CVE-2024-45042MEDIUMOry Kratos's `highest_available` setting does not properly respect code + mfa credentialsEPSS 0.3%CVE-2018-17923—SAGA1-L8B with any firmware versions prior to A0.10 are vulnerable to an attack that an attacker with physical access to the product may ablEPSS 0.3%CVE-2026-31946CRITICALOpenOLAT: Authentication bypass via forged JWT in OIDC implicit flowEPSS 0.3%CVE-2026-42602HIGHazureauthextension Authenticate method does not validate bearer tokens, allowing auth bypass via replayEPSS 0.3%CVE-2026-52793HIGHFroxlor: API Authentication bypasses 2FA AuthenticationEPSS 0.3%CVE-2024-55886MEDIUMOpenTelemetry Logs source may lack authentication with some custom pluginsEPSS 0.3%CVE-2025-52571CRITICALHikka vulnerable to RCE through edits in a channelEPSS 0.3%CVE-2026-15240HIGHCustomer Switching for WooCommerce < 2.1.3 - Customer+ Privilege Escalation to Administrator via Insecure Operator ResolutionEPSS 0.3%CVE-2026-11923HIGHSecurity vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify AccessEPSS 0.3%