Fallos del tipo CWE-287

2452 resultados

Autenticação inadequada ou ausente

A aplicação não valida ou valida de forma insuficiente a identidade de quem tenta acessá-la. Quando um usuário diz ser quem é, o sistema acredita sem verificar corretamente, permitindo que atacantes se façam passar por outros usuários ou contas legítimas.

Ejemplo

Um sistema que aceita login apenas com nome de usuário, sem senha. Ou uma API que confia no header 'User-ID' enviado pelo cliente sem validar se aquele usuário realmente existe ou tem sessão ativa. Um atacante simplesmente altera o header e acessa dados de outra conta.

Cómo mitigar

Implemente autenticação robusta: exija múltiplos fatores (senha forte + MFA), valide credenciais contra base de dados segura, use sessões com token assinado e com expiração, nunca confie em dados enviados pelo cliente como prova de identidade. Revise regularmente logs de acesso para detectar abusos.

CVE-2024-21635HIGHMemos Access Tokens Stay Valid after User Password ChangeEPSS 0.3%CVE-2024-56445MEDIUMInstruction authentication bypass vulnerability in the Findnetwork module Impact: Successful exploitation of this vulnerability may cause feEPSS 0.3%CVE-2026-85056HIGHZITADEL: MFA bypass via session reuse in Login V2EPSS 0.3%CVE-2026-56666MEDIUMZITADEL: Auto-linking by email: IdP-side email verification is not checkedEPSS 0.3%CVE-2025-68402HIGHFreshRSS has an authentication bypass due to truncated bcrypt hash [edge branch]EPSS 0.3%CVE-2024-45036MEDIUMImproper Access Control Vulnerability When Accessing a Maliciously Crafted Tophat LinkEPSS 0.3%CVE-2026-18960MEDIUMBlock User Account < 2.0.1 - Subscriber+ Account Block Bypass via Application PasswordsEPSS 0.3%CVE-2026-23708MEDIUMA improper authentication vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR on-preEPSS 0.3%CVE-2025-29773MEDIUMFroxlor allows Multiple Accounts to Share the Same Email Address Leading to Potential Privilege Escalation or Account TakeoverEPSS 0.3%CVE-2022-41579MEDIUMThere is an insufficient authentication vulnerability in some Huawei band products. Successful exploit could allow the attacker to spoof theEPSS 0.3%CVE-2026-4829MEDIUMImproper authentication in the external OAuth authentication flow in Devolutions Server 2026.1.11 and earlier allows an authenticated user tEPSS 0.3%CVE-2026-67335MEDIUMbetter-auth before 1.6.2 OAuth State Validation BypassEPSS 0.3%CVE-2026-18651MEDIUM389-ds-base: 389-ds-base: sasl plain bind installs connection credentials before account-lock check, allowing continued access as a locked accountEPSS 0.3%CVE-2020-3151MEDIUMCisco Connected Mobile Experiences Restricted Shell Escape VulnerabilityEPSS 0.3%CVE-2026-24003MEDIUMEvseV2G has sequence state validation bypassEPSS 0.3%CVE-2024-27137MEDIUMApache Cassandra: unrestricted deserialization of JMX authentication credentialsEPSS 0.3%CVE-2026-49203HIGHUnauthenticated eSIM Configuration ManipulationEPSS 0.3%CVE-2026-33215MEDIUMNATS is vulnerable to MQTT hijacking via Client IDEPSS 0.3%CVE-2026-14214LOWAmelia < 2.4.4 - Amelia Manager+ Arbitrary User-Field Modification via Mass AssignmentEPSS 0.3%CVE-2026-40178MEDIUMajenti.plugin.core has a race conditions in 2FAEPSS 0.3%