Fallos del tipo CWE-287

2453 resultados

Autenticação inadequada ou ausente

A aplicação não valida ou valida de forma insuficiente a identidade de quem tenta acessá-la. Quando um usuário diz ser quem é, o sistema acredita sem verificar corretamente, permitindo que atacantes se façam passar por outros usuários ou contas legítimas.

Ejemplo

Um sistema que aceita login apenas com nome de usuário, sem senha. Ou uma API que confia no header 'User-ID' enviado pelo cliente sem validar se aquele usuário realmente existe ou tem sessão ativa. Um atacante simplesmente altera o header e acessa dados de outra conta.

Cómo mitigar

Implemente autenticação robusta: exija múltiplos fatores (senha forte + MFA), valide credenciais contra base de dados segura, use sessões com token assinado e com expiração, nunca confie em dados enviados pelo cliente como prova de identidade. Revise regularmente logs de acesso para detectar abusos.

CVE-2023-31015MEDIUMNVIDIA DGX H100 BMC contains a vulnerability in the REST service where a host user may cause as improper authentication issue. A successful EPSS 0.2%CVE-2025-37731MEDIUMElasticsearch Improper AuthenticationEPSS 0.2%CVE-2022-43451HIGHMultiple path traversal in appspawn and nwebspawn services.EPSS 0.2%CVE-2023-3028HIGHImproper backend communication allows access and manipulation of the telemetry dataEPSS 0.2%CVE-2025-0217HIGHPrivileged Remote Access Authentication BypassEPSS 0.2%CVE-2026-39411MEDIUMLobeHub has an unauthenticated authentication bypass on `webapi` routes via forgeable `X-lobe-chat-auth` headerEPSS 0.2%CVE-2023-28377MEDIUMImproper authentication in some Intel(R) NUC Kit NUC11PH USB firmware installation software before version 1.1 for Windows may allow an authEPSS 0.2%CVE-2026-20683HIGHAn authentication issue was addressed with improved state management. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, macEPSS 0.2%CVE-2026-55626HIGHxrdp: No authentication required with Xvnc backend on RHEL 9EPSS 0.2%CVE-2026-12504HIGHLoytec LINX firmware: Improper Authentication in PAM configurationEPSS 0.2%CVE-2026-82843CRITICALWP OAuth Server < 6.4.0 - Subscriber+ Cross-User Account Takeover via OIDC ID Token SubstitutionEPSS 0.2%CVE-2023-26455MEDIUMRMI was not requiring authentication when calling ChronosRMIService:setEventOrganizer. Attackers with local or adjacent network access couldEPSS 0.2%CVE-2025-31267MEDIUMAn authentication issue was addressed with improved state management. This issue is fixed in App Store Connect 3.0. An attacker with physicaEPSS 0.2%CVE-2025-64434MEDIUMKubeVirt Improper TLS Certificate Management Handling Allows API Identity SpoofingEPSS 0.2%CVE-2026-11718CRITICALAn authentication bypass vulnerability exists in the generic opaque token validation path (validateOpaqueToken) of googleapis/mcp-toolbox. EPSS 0.2%CVE-2026-33314MEDIUMpyload-ng: Improper Authentication and Origin Validation ErrorEPSS 0.2%CVE-2026-48991MEDIUMXianYuLauncher: Legacy Microsoft account OAuth sign-in flow lacks PKCE and state validationEPSS 0.2%CVE-2021-33159HIGHImproper authentication in subsystem for Intel(R) AMT before versions 11.8.93, 11.22.93, 11.12.93, 12.0.92, 14.1.67, 15.0.42, 16.1.25 may alEPSS 0.2%CVE-2022-2752MEDIUMPotential vulnerabilities in GM login processEPSS 0.2%CVE-2023-0036MEDIUMplatform_callback_stub in misc subsystem has an authentication bypass vulnerability which allows an "SA relay attack".EPSS 0.2%