Fallos del tipo CWE-287

2452 resultados

Autenticação inadequada ou ausente

A aplicação não valida ou valida de forma insuficiente a identidade de quem tenta acessá-la. Quando um usuário diz ser quem é, o sistema acredita sem verificar corretamente, permitindo que atacantes se façam passar por outros usuários ou contas legítimas.

Ejemplo

Um sistema que aceita login apenas com nome de usuário, sem senha. Ou uma API que confia no header 'User-ID' enviado pelo cliente sem validar se aquele usuário realmente existe ou tem sessão ativa. Um atacante simplesmente altera o header e acessa dados de outra conta.

Cómo mitigar

Implemente autenticação robusta: exija múltiplos fatores (senha forte + MFA), valide credenciais contra base de dados segura, use sessões com token assinado e com expiração, nunca confie em dados enviados pelo cliente como prova de identidade. Revise regularmente logs de acesso para detectar abusos.

CVE-2020-7276MEDIUMUnrestricted Policy Management using MfeUpgradeTool.exeEPSS 0.3%CVE-2024-40648MEDIUM`UserIdentity::is_verified` not checking verification status of own user identity while performing the check in matrix-rust-sdkEPSS 0.3%CVE-2024-45347CRITICALMi Connect Service APP protocol flaws lead to unauthorized accessEPSS 0.3%CVE-2023-28647MEDIUMApp pin of the iOS app can be bypassed in Nextcloud iOSEPSS 0.3%CVE-2026-14563CRITICALAdvanced Customized Prompts <= 1.0.1 - Unauthenticated Account TakeoverEPSS 0.3%CVE-2023-52111HIGHAuthorization vulnerability in the BootLoader module. Successful exploitation of this vulnerability may affect service integrity.EPSS 0.3%CVE-2026-77244CRITICAL[mcp-atlassian] Authentication bypass in HTTP transport: AtlassianOpaqueTokenVerifier accepts any non-empty tokenEPSS 0.3%CVE-2026-14559CRITICALTeddy Bear Customize Addon <= 1.0.5 - Unauthenticated Account TakeoverEPSS 0.3%CVE-2026-90623MEDIUMandreashappe cochise SSH Host Key ssh_connection.py asyncssh.connect certificate validationEPSS 0.3%CVE-2026-53512CRITICALBetter Auth: OAuth refresh-token replay via missing client authentication on oidc-provider and mcp pluginsEPSS 0.3%CVE-2025-65128HIGHA missing authentication mechanism in the web management API components of Shenzhen Zhibotong Electronics ZBT WE2001 23.09.27 allows unautheEPSS 0.3%CVE-2022-42453MEDIUMHCL BigFix Platform is affected by insufficient warningsEPSS 0.3%CVE-2026-14561MEDIUMAuthora - Easy Login with Mobile Number < 1.7.7 - Unauthenticated Account Takeover via OTP DisclosureEPSS 0.3%CVE-2025-54573MEDIUMCVAT vulnerable to email verification bypass by use of basic authenticationEPSS 0.3%CVE-2026-39324CRITICALRack::Session::Cookie secrets: decrypt failure fallback enables secretless session forgery and Marshal deserializationEPSS 0.3%CVE-2024-37408HIGHfprintd through 1.94.3 lacks a security attention mechanism, and thus unexpected actions might be authorized by "auth sufficient pam_fprintdEPSS 0.3%CVE-2022-29838MEDIUMAuthentication issue with the encrypted volumes and auto mount feature in My Cloud devicesEPSS 0.3%CVE-2026-35261MEDIUMVulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that EPSS 0.3%CVE-2025-7095MEDIUMComodo Internet Security Premium Update certificate validationEPSS 0.3%CVE-2026-60434MEDIUMVulnerability in the Oracle Transportation Management product of Oracle Supply Chain (component: Authentication). The supported version thEPSS 0.3%