Fallos del tipo CWE-287

2451 resultados

Autenticação inadequada ou ausente

A aplicação não valida ou valida de forma insuficiente a identidade de quem tenta acessá-la. Quando um usuário diz ser quem é, o sistema acredita sem verificar corretamente, permitindo que atacantes se façam passar por outros usuários ou contas legítimas.

Ejemplo

Um sistema que aceita login apenas com nome de usuário, sem senha. Ou uma API que confia no header 'User-ID' enviado pelo cliente sem validar se aquele usuário realmente existe ou tem sessão ativa. Um atacante simplesmente altera o header e acessa dados de outra conta.

Cómo mitigar

Implemente autenticação robusta: exija múltiplos fatores (senha forte + MFA), valide credenciais contra base de dados segura, use sessões com token assinado e com expiração, nunca confie em dados enviados pelo cliente como prova de identidade. Revise regularmente logs de acesso para detectar abusos.

CVE-2023-20199MEDIUMCisco Duo Two-Factor Authentication for macOS Authentication Bypass VulnerabilityEPSS 0.3%CVE-2025-22477HIGHDell Storage Center - Dell Storage Manager, version(s) 20.1.20, contain(s) an Improper Authentication vulnerability. An unauthenticated attaEPSS 0.3%CVE-2026-16739MEDIUMEpeken All Kurir <= 2.1.4 - Unauthenticated Order Payment Confirmation ForgeryEPSS 0.3%CVE-2026-73733MEDIUMAuthentication Bypasses in API allow Continued Authenticated Access in HPE Networking Fabric ComposerEPSS 0.3%CVE-2026-97063CRITICALX-SpringBoot through 6.0 Authentication Bypass via Login CodeEPSS 0.3%CVE-2026-74240MEDIUMQuay: jwt claim validation bypasses in quay federated robot and sso authenticationEPSS 0.3%CVE-2026-12695HIGHminiOrange 2FA < 6.2.6 - 2FA Bypass via Attacker-Controlled ga_secretEPSS 0.3%CVE-2026-49848MEDIUMFreeSWITCH: Pre-authentication `userVariables` injection in `mod_verto`EPSS 0.3%CVE-2025-10772MEDIUMhuggingface LeRobot ZeroMQ Socket lekiwi_remote.py missing authenticationEPSS 0.3%CVE-2026-48117MEDIUMDroneAware's Improper Account Activation in Registration and SSO Flows Leads to Account TakeoverEPSS 0.3%CVE-2025-1024HIGHSession Hijacking via Reflected Cross-Site Scripting (XSS) in ChurchCRM EditEventAttendees.php EID ParameterEPSS 0.3%CVE-2025-56447CRITICALTM2 Monitoring v3.04 contains an authentication bypass and plaintext credential disclosure.EPSS 0.3%CVE-2022-25768HIGHImproper Access Control in UI upgrade processEPSS 0.3%CVE-2026-53516HIGHBetter Auth: Account takeover via OAuth auto-link to unverified pre-registered emailEPSS 0.3%CVE-2026-100607CRITICALFlowise through 3.1.4 Authentication Bypass via Email-Only SSOEPSS 0.3%CVE-2023-49790MEDIUMApp PIN code can be bypassed in Nextcloud Files iOSEPSS 0.3%CVE-2020-8108HIGHInsufficient client validation in Bitdefender Endpoint Security for Mac (VA-8759)EPSS 0.3%CVE-2025-54786MEDIUMSuiteCRM: Legacy iCal service allows unauthenticated access to meeting dataEPSS 0.3%CVE-2026-100709HIGHFroxlor before 2.3.12 2FA Bypass via Namespace ConfusionEPSS 0.3%CVE-2024-56445MEDIUMInstruction authentication bypass vulnerability in the Findnetwork module Impact: Successful exploitation of this vulnerability may cause feEPSS 0.3%