Fallos del tipo CWE-287

2451 resultados

Autenticação inadequada ou ausente

A aplicação não valida ou valida de forma insuficiente a identidade de quem tenta acessá-la. Quando um usuário diz ser quem é, o sistema acredita sem verificar corretamente, permitindo que atacantes se façam passar por outros usuários ou contas legítimas.

Ejemplo

Um sistema que aceita login apenas com nome de usuário, sem senha. Ou uma API que confia no header 'User-ID' enviado pelo cliente sem validar se aquele usuário realmente existe ou tem sessão ativa. Um atacante simplesmente altera o header e acessa dados de outra conta.

Cómo mitigar

Implemente autenticação robusta: exija múltiplos fatores (senha forte + MFA), valide credenciais contra base de dados segura, use sessões com token assinado e com expiração, nunca confie em dados enviados pelo cliente como prova de identidade. Revise regularmente logs de acesso para detectar abusos.

CVE-2026-19709MEDIUMMembership For WooCommerce < 3.1.2 - Unauthenticated Member Data Disclosure via REST Consumer Secret BypassEPSS 0.3%CVE-2026-77771HIGHminiOrange 2FA (Free & Pro) - 2FA Bypass via Session-Scoped OTP LockoutEPSS 0.3%CVE-2026-11923HIGHSecurity vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify AccessEPSS 0.3%CVE-2026-55759HIGHRocket.Chat: Apple Sign-In skips JWT claims validation, allowing expired and cross-audience token replayEPSS 0.3%CVE-2025-10224MEDIUMIncorrect Evaluation of LDAP Nested Groups during Login in AxxonSoft Axxon One (C-Werk)EPSS 0.3%CVE-2023-29117HIGHAuthentication Bypass in JuiceBox Web Manager interfaceEPSS 0.3%CVE-2026-76548HIGHProfile Builder < 4.0.1 - Unauthenticated Unpublished Content and Media Modification via Front-End Upload Auth BypassEPSS 0.3%CVE-2024-41589HIGHDrayTek Vigor310 devices through 4.3.2.6 use unencrypted HTTP for authentication requests.EPSS 0.3%CVE-2026-65121HIGHNVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause an improper authentication issue. A succeEPSS 0.3%CVE-2026-18891HIGHLangflow is affected by multiple authentication bypass, path traversal, authorization, and server-side request forgery vulnerabilitiesEPSS 0.3%CVE-2025-15069HIGHPrivilege Escalation in Gmission Web FAXEPSS 0.3%CVE-2025-54761HIGHAn issue was discovered in PPress 0.0.9 allowing attackers to gain escilated privlidges via crafted session cookie.EPSS 0.3%CVE-2024-38351MEDIUMPassword auth and OAuth2 unverified email linkingEPSS 0.3%CVE-2026-80128MEDIUMDell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper AuthentiEPSS 0.3%CVE-2026-44166MEDIUMPocketbase: Account pre-hijacking via OAuth2 unverfied->verified autolinking upgradeEPSS 0.3%CVE-2025-52054MEDIUMAn issue was discovered in Tenda AC8 v4.0 AC1200 Dual-band Gigabit Wireless Router AC8v4.0 Firmware 16.03.33.05. The root password of the deEPSS 0.3%CVE-2023-5502HIGHOn affected platforms running Arista EOS with 802.1x authentication configured on the access/trunk ports, a malicious supplicant may bypass authentication.EPSS 0.3%CVE-2026-33512HIGHAVideo has an unauthenticated decrypt oracle leaking any ciphertextEPSS 0.3%CVE-2026-8508MEDIUMAn improper authentication vulnerability in the "social_login.cgi" CGI program in Zyxel WAX650S firmware versions through 7.10(ABRM.4)C0 couEPSS 0.3%CVE-2026-24170HIGHNVIDIA UFM Enterprise contains a vulnerability in the web interface authorization component, where an authenticated user could cause impropeEPSS 0.3%