Fallos del tipo CWE-287

2417 resultados

Autenticação inadequada ou ausente

A aplicação não valida ou valida de forma insuficiente a identidade de quem tenta acessá-la. Quando um usuário diz ser quem é, o sistema acredita sem verificar corretamente, permitindo que atacantes se façam passar por outros usuários ou contas legítimas.

Ejemplo

Um sistema que aceita login apenas com nome de usuário, sem senha. Ou uma API que confia no header 'User-ID' enviado pelo cliente sem validar se aquele usuário realmente existe ou tem sessão ativa. Um atacante simplesmente altera o header e acessa dados de outra conta.

Cómo mitigar

Implemente autenticação robusta: exija múltiplos fatores (senha forte + MFA), valide credenciais contra base de dados segura, use sessões com token assinado e com expiração, nunca confie em dados enviados pelo cliente como prova de identidade. Revise regularmente logs de acesso para detectar abusos.

CVE-2026-86426CRITICALLibreNMS before 26.8.0 Authentication Bypass via API Token Type ConfusionEPSS 2.1%CVE-2024-57046HIGHA vulnerability in the Netgear DGN2200 router with firmware version v1.0.0.46 and earlier permits unauthorized individuals to bypass the autEPSS 2.1%CVE-2017-9939A vulnerability was discovered in Siemens SiPass integrated (All versions before V2.70) that could allow an attacker with network access to EPSS 2.1%CVE-2022-29165CRITICALArgo CD will blindly trust JWT claims if anonymous access is enabledEPSS 2.1%CVE-2017-12196MEDIUMundertow before versions 1.4.18.SP1, 2.0.2.Final, 1.4.24.Final was found vulnerable when using Digest authentication, the server does not enEPSS 2.0%CVE-2018-0382MEDIUMCisco Wireless LAN Controller Software Session Hijacking VulnerabilityEPSS 2.0%CVE-2017-12316A vulnerability in the Guest Portal login page of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to peEPSS 2.0%CVE-2019-18284A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). The AdminService is available wEPSS 2.0%CVE-2022-36436CRITICALOSU Open Source Lab VNCAuthProxy through 1.1.1 is affected by an vncap/vnc/protocol.py VNCServerAuthenticator authentication-bypass vulnerabEPSS 2.0%CVE-2017-7930An Improper Authentication issue was discovered in OSIsoft PI Server 2017 PI Data Archive versions prior to 2017. PI Data Archive has protocEPSS 2.0%CVE-2026-27960CRITICALOpenCTI privilege escalation and unauthenticated access via default admin accountEPSS 2.0%CVE-2024-48445CRITICALAn issue in compop.ca ONLINE MALL v.3.5.3 allows a remote attacker to execute arbitrary code via the rid, tid, et, and ts parameters.EPSS 2.0%CVE-2020-27780A flaw was found in Linux-Pam in versions prior to 1.5.1 in the way it handle empty passwords for non-existing users. When the user doesn't EPSS 2.0%CVE-2022-1049A flaw was found in the Pacemaker configuration tool (pcs). The pcs daemon was allowing expired accounts, and accounts with expired passwordEPSS 2.0%CVE-2017-12225A vulnerability in the web functionality of the Cisco Prime LAN Management Solution could allow an authenticated, remote attacker to hijack EPSS 2.0%CVE-2021-38161Not validating origin TLS certificateEPSS 1.9%CVE-2026-53595CRITICALFreeScout vulnerable to anonymous account takeover via /user-setup empty invite_hash on MySQLEPSS 1.9%CVE-2024-23465HIGHSolarWinds Access Rights Manager (ARM) ChangeHumster Exposed Dangerous Method Authentication Bypass VulnerabilityEPSS 1.9%CVE-2026-0558HIGHUnauthenticated File Upload in parisneo/lollmsEPSS 1.9%CVE-2026-49869CRITICALKestra: Unauthenticated Remote Code Execution via Authentication Bypass in `AuthenticationFilter`EPSS 1.9%KEV