Fallos del tipo CWE-287

2453 resultados

Autenticação inadequada ou ausente

A aplicação não valida ou valida de forma insuficiente a identidade de quem tenta acessá-la. Quando um usuário diz ser quem é, o sistema acredita sem verificar corretamente, permitindo que atacantes se façam passar por outros usuários ou contas legítimas.

Ejemplo

Um sistema que aceita login apenas com nome de usuário, sem senha. Ou uma API que confia no header 'User-ID' enviado pelo cliente sem validar se aquele usuário realmente existe ou tem sessão ativa. Um atacante simplesmente altera o header e acessa dados de outra conta.

Cómo mitigar

Implemente autenticação robusta: exija múltiplos fatores (senha forte + MFA), valide credenciais contra base de dados segura, use sessões com token assinado e com expiração, nunca confie em dados enviados pelo cliente como prova de identidade. Revise regularmente logs de acesso para detectar abusos.

CVE-2025-0981HIGHSession Hijacking via Stored Cross-Site Scripting (XSS) in ChurchCRM GroupEditor.php Description FieldEPSS 0.2%CVE-2025-10672HIGHwhuan132 AIBattery com.collweb.AIBatteryHelper BatteryXPCService.swift missing authenticationEPSS 0.2%CVE-2026-56294MEDIUMcapacitor-native-biometric - Authentication Bypass via Unvalidated CryptoObject in onAuthenticationSucceededEPSS 0.2%CVE-2026-12112HIGHForeman-mcp-server: mcp server: active session hijacking via insecure session state reuseEPSS 0.2%CVE-2024-22247MEDIUMVMware SD-WAN Edge contains a missing authentication and protection mechanism vulnerability. A malicious actor with physical access to the EPSS 0.2%CVE-2026-54510HIGHSpeakr: CSRF bypass via unauthenticated API token parameter in csrf_exempt_for_api_tokens hookEPSS 0.2%CVE-2025-0672LOWAuthentication Bypass in Multiple WSO2 Products via Stale FIDO Credential AssociationEPSS 0.2%CVE-2023-42935MEDIUMAn authentication issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.6.4. A local attacker may be aEPSS 0.2%CVE-2025-0249LOWHCL IEM is affected by an improper invalidation of access or JWT token vulnerabilityEPSS 0.2%CVE-2026-0633LOWMetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor <= 4.1.0 - Unauthenticated Form Submission Exposure via Forgeable Cookie ValueEPSS 0.2%CVE-2023-31189MEDIUMImproper authentication in some Intel(R) Server Product OpenBMC firmware before version egs-1.09 may allow an authenticated user to enable eEPSS 0.2%CVE-2022-48254MEDIUMThere is a data processing error vulnerability in Leia-B29 2.0.0.49(M03). Successful exploitation could bypass lock screen authentication.EPSS 0.2%CVE-2026-44711HIGHpam_usb: Symlink attacks on pad directory and pad files enable authentication bypass and root file corruptionEPSS 0.2%CVE-2026-86890MEDIUMA logic issue was addressed with improved checks. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27. An attacker with phEPSS 0.2%CVE-2021-25377LOWIntent redirection in Samsung Experience Service versions 10.8.0.4 in Android P(9.0) below, and 12.2.0.5 in Android Q(10.0) above allows attEPSS 0.2%CVE-2025-67859MEDIUMPolkit Authorization Check can be Bypassed in the TLP power daemonEPSS 0.2%CVE-2025-52294MEDIUMInsufficient validation of the screen lock mechanism in Trust Wallet v8.45 allows physically proximate attackers to bypass the lock screen aEPSS 0.2%CVE-2024-39767MEDIUMSpoofed push notifications from malicious serverEPSS 0.2%CVE-2022-28790MEDIUMImproper authentication in Link to Windows Service prior to version 2.3.04.1 allows attacker to lock the device. The patch adds proper calleEPSS 0.2%CVE-2026-34204HIGHMinIO is Vulnerable to SSE Metadata Injection via Replication HeadersEPSS 0.2%