Fallos del tipo CWE-287

2453 resultados

Autenticação inadequada ou ausente

A aplicação não valida ou valida de forma insuficiente a identidade de quem tenta acessá-la. Quando um usuário diz ser quem é, o sistema acredita sem verificar corretamente, permitindo que atacantes se façam passar por outros usuários ou contas legítimas.

Ejemplo

Um sistema que aceita login apenas com nome de usuário, sem senha. Ou uma API que confia no header 'User-ID' enviado pelo cliente sem validar se aquele usuário realmente existe ou tem sessão ativa. Um atacante simplesmente altera o header e acessa dados de outra conta.

Cómo mitigar

Implemente autenticação robusta: exija múltiplos fatores (senha forte + MFA), valide credenciais contra base de dados segura, use sessões com token assinado e com expiração, nunca confie em dados enviados pelo cliente como prova de identidade. Revise regularmente logs de acesso para detectar abusos.

CVE-2026-57175MEDIUMsocial-auth-core has an Improper Authentication issueEPSS 0.2%CVE-2026-40205MEDIUMAn attacker that holds an OAuth2 token granting only part of the required scopes can authenticate, because when more than one scope is requiEPSS 0.2%CVE-2026-19718HIGHBlogVault, MalCare and WP Remote 5.16 - 6.62 - Unauthenticated Site Takeover via Connection Key RecoveryEPSS 0.2%CVE-2026-49454CRITICALRelyra SAML SignatureValue not cryptographically verified -> authentication bypassEPSS 0.2%CVE-2026-43674MEDIUMAn authentication issue was addressed with improved state management. This issue is fixed in iOS 27 and iPadOS 27. An attacker with physicalEPSS 0.2%CVE-2021-25341MEDIUMCalling of non-existent provider in S Assistant prior to version 6.5.01.22 allows unauthorized actions including denial of service attack byEPSS 0.2%CVE-2021-25342MEDIUMCalling of non-existent provider in SMP sdk prior to version 3.0.9 allows unauthorized actions including denial of service attack by hijackiEPSS 0.2%CVE-2022-25825MEDIUMImproper access control vulnerability in Samsung Account prior to version 13.1.0.1 allows attackers to access to the authcode for sign-in.EPSS 0.2%CVE-2022-22284MEDIUMImproper authentication vulnerability in Samsung Internet prior to 16.0.2.19 allows attackers to bypass secret mode password authenticationEPSS 0.2%CVE-2021-25343MEDIUMCalling of non-existent provider in Samsung Members prior to version 2.4.81.13 (in Android O(8.1) and below) and 3.8.00.13 (in Android P(9.0EPSS 0.2%CVE-2026-81703HIGHopenssl_encrypt before 1.4.9 Authentication Bypass via Unencrypted PQC KeyEPSS 0.2%CVE-2026-47202CRITICALKavita: Pre-Auth Account TakeoverEPSS 0.2%CVE-2020-36548MEDIUMGE Voluson S8 Service Browser users.cgi improper authenticationEPSS 0.2%CVE-2025-11130HIGHiHongRen pptp-vpn XPC Service HelperTool.m shouldAcceptNewConnection missing authenticationEPSS 0.2%CVE-2026-9084MEDIUMMISP OIDC authentication bypass via automatic email-based account linking under insecure IdP configurationsEPSS 0.2%CVE-2025-29906HIGHFinit bundled getty can bypass /bin/loginEPSS 0.2%CVE-2026-71416HIGHHeadroom vulnerable to Cross-Site WebSocket Hijacking (CSWSH)EPSS 0.2%CVE-2025-54154MEDIUMQNAP AuthenticatorEPSS 0.2%CVE-2025-10672HIGHwhuan132 AIBattery com.collweb.AIBatteryHelper BatteryXPCService.swift missing authenticationEPSS 0.2%CVE-2021-28493HIGHIn Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, a user may be abEPSS 0.2%