Fallos del tipo CWE-287

2452 resultados

Autenticação inadequada ou ausente

A aplicação não valida ou valida de forma insuficiente a identidade de quem tenta acessá-la. Quando um usuário diz ser quem é, o sistema acredita sem verificar corretamente, permitindo que atacantes se façam passar por outros usuários ou contas legítimas.

Ejemplo

Um sistema que aceita login apenas com nome de usuário, sem senha. Ou uma API que confia no header 'User-ID' enviado pelo cliente sem validar se aquele usuário realmente existe ou tem sessão ativa. Um atacante simplesmente altera o header e acessa dados de outra conta.

Cómo mitigar

Implemente autenticação robusta: exija múltiplos fatores (senha forte + MFA), valide credenciais contra base de dados segura, use sessões com token assinado e com expiração, nunca confie em dados enviados pelo cliente como prova de identidade. Revise regularmente logs de acesso para detectar abusos.

CVE-2026-35261MEDIUMVulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that EPSS 0.3%CVE-2025-48746MEDIUMNetwrix Directory Manager (formerly Imanami GroupID) v.11.0.0.0 and before, as well as after v.11.1.25134.03 lacks Authentication for a CritEPSS 0.3%CVE-2024-38426MEDIUMImproper Authentication in ModemEPSS 0.3%CVE-2022-34887MEDIUMStandard users can directly operate and set printer configuration information , such as IP, in some Lenovo Printers without having to authenEPSS 0.3%CVE-2024-23219MEDIUMThe issue was addressed with improved authentication. This issue is fixed in iOS 17.3 and iPadOS 17.3. Stolen Device Protection may be unexpEPSS 0.3%CVE-2025-0813HIGHCWE-287: Improper Authentication vulnerability exists that could cause an Authentication Bypass when an unauthorized user without permissionEPSS 0.3%CVE-2025-9815HIGHalaneuler batteryKid NSXPCListener PrivilegeHelper.swift missing authenticationEPSS 0.3%CVE-2026-94612HIGHauthentik: Authentication bypass via assertion confusion in SAML sourcesEPSS 0.3%CVE-2024-20301MEDIUMA vulnerability in Cisco Duo Authentication for Windows Logon and RDP could allow an authenticated, physical attacker to bypass secondary auEPSS 0.3%CVE-2023-52210MEDIUMWordPress Product Delivery Date for WooCommerce – Lite plugin <= 2.7.0 - Broken Access Control vulnerabilityEPSS 0.3%CVE-2024-6174HIGHWhen a non-x86 platform is detected, cloud-init grants root access to a hardcoded url with a local IP address. To prevent this, cloud-init dEPSS 0.3%CVE-2025-8964MEDIUMcode-projects Hostel Management System Login hostel_manage.exe improper authenticationEPSS 0.3%CVE-2024-7956HIGHSensitive Data Exposure and Escalating Privileges Vulnerabilities in DataMosaix™ Private CloudEPSS 0.3%CVE-2026-59208HIGHn8n: Cross-Issuer Token Exchange Account Binding via Subject-Only Identity ResolutionEPSS 0.3%CVE-2024-13088MEDIUMQHoraEPSS 0.3%CVE-2018-25030LOWMirmay Secure Private Browser / File Manager Auto Lock improper authenticationEPSS 0.3%CVE-2026-42008MEDIUMForwarding information received from a host listed as a trusted proxy is not kept separate from Dovecot's own authentication fields, so a vaEPSS 0.3%CVE-2026-4587MEDIUMHybridAuth SSL Curl.php certificate validationEPSS 0.3%CVE-2025-25452MEDIUMAn issue in TAAGSOLUTIONS GmbH MyTaag v.2024-11-24 and before allows a remote attacker to escalate privileges via the "/user" endpointEPSS 0.3%CVE-2025-59704HIGHEntrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow an attaEPSS 0.3%