Fallos del tipo CWE-287

2451 resultados

Autenticação inadequada ou ausente

A aplicação não valida ou valida de forma insuficiente a identidade de quem tenta acessá-la. Quando um usuário diz ser quem é, o sistema acredita sem verificar corretamente, permitindo que atacantes se façam passar por outros usuários ou contas legítimas.

Ejemplo

Um sistema que aceita login apenas com nome de usuário, sem senha. Ou uma API que confia no header 'User-ID' enviado pelo cliente sem validar se aquele usuário realmente existe ou tem sessão ativa. Um atacante simplesmente altera o header e acessa dados de outra conta.

Cómo mitigar

Implemente autenticação robusta: exija múltiplos fatores (senha forte + MFA), valide credenciais contra base de dados segura, use sessões com token assinado e com expiração, nunca confie em dados enviados pelo cliente como prova de identidade. Revise regularmente logs de acesso para detectar abusos.

CVE-2026-1524LOWAuth misconfiguration when multiple providers enabledEPSS 0.3%CVE-2024-7487MEDIUMImproper Authentication in WSO2 Identity Server 7.0.0 Allows Bypass of App-Native AuthenticationEPSS 0.3%CVE-2024-40713HIGHA vulnerability that allows a user who has been assigned a low-privileged role within Veeam Backup & Replication to alter Multi-Factor AutheEPSS 0.3%CVE-2025-65397MEDIUMAn insecure authentication mechanism in the safe_exec.sh startup script of Blurams Flare Camera version 24.1114.151.929 and earlier allows aEPSS 0.3%CVE-2025-31228MEDIUMThe issue was addressed with improved authentication. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7. An attacker with physiEPSS 0.3%CVE-2025-66515LOWNextcloud Approval app allows users to request approval for other users fileEPSS 0.3%CVE-2022-31011HIGHTiDB authentication bypass vulnerabilityEPSS 0.3%CVE-2025-22232MEDIUMSpring Cloud Config Server May Not Use Vault Token Sent By ClientsEPSS 0.3%CVE-2024-50341LOWSecurity::login does not take into account custom user_checker in symfony/security-bundleEPSS 0.3%CVE-2025-41108CRITICALImproper Authentication vulnerability in Ghost Robotics' Vision 60EPSS 0.3%CVE-2026-30223HIGHOliveTin: JWT Audience Validation Bypass in Local Key and HMAC ModesEPSS 0.3%CVE-2024-0568HIGH CWE-287: Improper Authentication vulnerability exists that could cause unauthorized tampering of device configuration over NFC communicatioEPSS 0.3%CVE-2025-55340HIGHWindows Remote Desktop Protocol Security Feature BypassEPSS 0.3%CVE-2026-15087MEDIUMClean RESTful - Critical - Unsupported - SA-CONTRIB-2026-078EPSS 0.3%CVE-2026-25922HIGHauthentik has a Signature Verification Bypass via SAML Assertion WrappingEPSS 0.3%CVE-2023-40282MEDIUMImproper authentication vulnerability in Rakuten WiFi Pocket all versions allows a network-adjacent attacker to log in to the product's ManaEPSS 0.3%CVE-2026-30836CRITICALStep CA: Unauthenticated Certificate Issuance via SCEP UpdateReq (MessageType=18)EPSS 0.3%CVE-2021-33076MEDIUMImproper authentication in firmware for some Intel(R) SSD DC Products may allow an unauthenticated user to potentially enable escalation of EPSS 0.3%CVE-2023-21467MEDIUMError in 3GPP specification implementation in Exynos baseband prior to SMR Apr-2023 Release 1 allows incorrect handling of unencrypted messaEPSS 0.3%CVE-2024-37897MEDIUMInsufficient access control for password reset in sftpgoEPSS 0.3%