Fallos del tipo CWE-287

2453 resultados

Autenticação inadequada ou ausente

A aplicação não valida ou valida de forma insuficiente a identidade de quem tenta acessá-la. Quando um usuário diz ser quem é, o sistema acredita sem verificar corretamente, permitindo que atacantes se façam passar por outros usuários ou contas legítimas.

Ejemplo

Um sistema que aceita login apenas com nome de usuário, sem senha. Ou uma API que confia no header 'User-ID' enviado pelo cliente sem validar se aquele usuário realmente existe ou tem sessão ativa. Um atacante simplesmente altera o header e acessa dados de outra conta.

Cómo mitigar

Implemente autenticação robusta: exija múltiplos fatores (senha forte + MFA), valide credenciais contra base de dados segura, use sessões com token assinado e com expiração, nunca confie em dados enviados pelo cliente como prova de identidade. Revise regularmente logs de acesso para detectar abusos.

CVE-2026-61687HIGHhatchet - Unauthenticated OAuth state CSRF / login-CSRF via empty-state collision in ValidateOAuthStateEPSS 0.2%CVE-2025-41459HIGHInsecure authentication due to missing bruteforce protection and runtime manipulation in Two App Studio Journey 5.5.6 for iOSEPSS 0.2%CVE-2025-22236HIGHCVE-2025-22236 salt advisoryEPSS 0.2%CVE-2026-33248MEDIUMNATS has mTLS verify_and_map authentication bypass via incorrect Subject DN matchingEPSS 0.2%CVE-2025-64517MEDIUMsudo-rs doesn't record authenticating user properly in timestampEPSS 0.2%CVE-2019-6854—A CWE-287: Improper Authentication vulnerability exists in a folder within EcoStruxure Geo SCADA Expert (ClearSCADA) -with initial releases EPSS 0.2%CVE-2026-47272HIGHpam_usb: OTP pad authentication bypass via missing system pad check and uninitialized RNG bufferEPSS 0.2%CVE-2025-65431MEDIUMAn issue was discovered in allauth-django before 65.13.0. Both Okta and NetIQ were using preferred_username as the identifier for third-partEPSS 0.2%CVE-2025-32875MEDIUMAn issue was discovered in the COROS application through 3.8.12 for Android. Bluetooth pairing and bonding is neither initiated nor enforcedEPSS 0.2%CVE-2024-9133MEDIUMA user with administrator privileges is able to retrieve authentication tokensEPSS 0.2%CVE-2024-4601MEDIUMImproper Authentication vulnerability in Socomec Net VisionEPSS 0.2%CVE-2026-57178HIGHsocial-auth-core: VK App backend accepts unsigned callback data when auth_key is missingEPSS 0.2%CVE-2021-3784MEDIUMGaruda Linux Improper AuthorizationEPSS 0.2%CVE-2026-96456MEDIUMReachy Mini Bluetooth PIN authentication can be bypassed by racing an authenticated deviceEPSS 0.2%CVE-2025-26475MEDIUMDell Secure Connect Gateway (SCG) 5.0 Appliance - SRS, version(s) 5.26, Enables Live-Restore setting which enhances security by keeping contEPSS 0.2%CVE-2021-25430—Improper access control vulnerability in Bluetooth application prior to SMR July-2021 Release 1 allows untrusted application to access the BEPSS 0.2%CVE-2022-37345HIGHImproper authentication in BIOS firmware[A1] for some Intel(R) NUC Kits before version RY0386 may allow an authenticated user to potentiallyEPSS 0.2%CVE-2026-39969MEDIUMTypeBot: WhatsApp Webhook Endpoint Missing Signature VerificationEPSS 0.2%CVE-2022-36370HIGHImproper authentication in BIOS firmware for some Intel(R) NUC Boards and Intel(R) NUC Kits before version MYi30060 may allow a privileged uEPSS 0.2%CVE-2025-20083HIGHImproper authentication in the firmware for the Intel(R) Slim Bootloader may allow a privileged user to potentially enable escalation of priEPSS 0.2%