Fallos del tipo CWE-287

2456 resultados

Autenticação inadequada ou ausente

A aplicação não valida ou valida de forma insuficiente a identidade de quem tenta acessá-la. Quando um usuário diz ser quem é, o sistema acredita sem verificar corretamente, permitindo que atacantes se façam passar por outros usuários ou contas legítimas.

Ejemplo

Um sistema que aceita login apenas com nome de usuário, sem senha. Ou uma API que confia no header 'User-ID' enviado pelo cliente sem validar se aquele usuário realmente existe ou tem sessão ativa. Um atacante simplesmente altera o header e acessa dados de outra conta.

Cómo mitigar

Implemente autenticação robusta: exija múltiplos fatores (senha forte + MFA), valide credenciais contra base de dados segura, use sessões com token assinado e com expiração, nunca confie em dados enviados pelo cliente como prova de identidade. Revise regularmente logs de acesso para detectar abusos.

CVE-2026-56850MEDIUMA flaw in Node.js HTTPS Agent connection reuse can cause PFX object-array key collisions, allowing mutual TLS (mTLS) client identities to beEPSS 0.1%CVE-2024-29757HIGHthere is a possible permission bypass due to Debug certs being allowlisted. This could lead to local escalation of privilege with no additioEPSS 0.1%CVE-2023-21466MEDIUMPendingIntent hijacking vulnerability in CertificatePolicy in framework prior to SMR Apr-2023 Release 1 allows local attackers to access conEPSS 0.1%CVE-2026-94419LOWClient session cache reference poisoning allows resumption with wrong serverEPSS 0.1%CVE-2025-20730MEDIUMIn preloader, there is a possible escalation of privilege due to an insecure default value. This could lead to local escalation of privilegeEPSS 0.1%CVE-2026-100876MEDIUMmathurvishal CloudClassroom-PHP-Project loginlinkstudent.php missing authenticationEPSS —CVE-2026-100903MEDIUMООО НПО Ритм GEOritm REST API obj-groups missing authenticationEPSS —CVE-2026-52749MEDIUMImproper Authentication in Kaon AR2140XEPSS —CVE-2026-101004MEDIUMnotionnext-org NotionNext Authentication Guard cache.js cleanCache missing authenticationEPSS —CVE-2026-100871HIGHSylius before 1.12.25, 1.13.17, 1.14.20, 2.1.16, and 2.2.9 JWT Audience Confusion Allows Admin API AuthenticationEPSS —CVE-2026-101042HIGHParse Server 9.0.0 Authentication Bypass via Unverified Provider IdentityEPSS —CVE-2026-101073MEDIUMNetcore NR289-GE CGI Dispatcher boa improper authenticationEPSS —CVE-2026-101050HIGHHeym before 0.0.53 Authentication Bypass via Telegram WebhookEPSS —CVE-2026-101077CRITICALNetcore NR289-GE boa_temp process_request missing authenticationEPSS —CVE-2026-101049HIGHHeym before 0.0.53 Slack Webhook Signature Verification BypassEPSS —CVE-2026-100886CRITICALSeetong T8108/T8108P/T8116/T8232 Debug Service improper authenticationEPSS —