Fallos del tipo CWE-287

2409 resultados

Autenticação inadequada ou ausente

A aplicação não valida ou valida de forma insuficiente a identidade de quem tenta acessá-la. Quando um usuário diz ser quem é, o sistema acredita sem verificar corretamente, permitindo que atacantes se façam passar por outros usuários ou contas legítimas.

Ejemplo

Um sistema que aceita login apenas com nome de usuário, sem senha. Ou uma API que confia no header 'User-ID' enviado pelo cliente sem validar se aquele usuário realmente existe ou tem sessão ativa. Um atacante simplesmente altera o header e acessa dados de outra conta.

Cómo mitigar

Implemente autenticação robusta: exija múltiplos fatores (senha forte + MFA), valide credenciais contra base de dados segura, use sessões com token assinado e com expiração, nunca confie em dados enviados pelo cliente como prova de identidade. Revise regularmente logs de acesso para detectar abusos.

CVE-2026-20127CRITICALCisco Catalyst SD-WAN Controller Authentication Bypass VulnerabilityEPSS 88.2%KEVCVE-2022-0540CRITICALA vulnerability in Jira Seraph allows a remote, unauthenticated attacker to bypass authentication by sending a specially crafted HTTP requesEPSS 88.1%CVE-2023-28121An issue in WooCommerce Payments plugin for WordPress (versions 5.6.1 and lower) allows an unauthenticated attacker to send requests on behaEPSS 86.5%CVE-2022-41678Apache ActiveMQ: Insufficient API restrictions on Jolokia allow authenticated users to perform RCEEPSS 85.8%CVE-2026-50751CRITICALUser Authentication Bypass in VPN Remote Access and Mobile AccessEPSS 83.8%KEVCVE-2015-1187CRITICALThe ping tool in multiple D-Link and TRENDnet devices allow remote attackers to execute arbitrary code via the ping_addr parameter to ping.cEPSS 82.9%KEVCVE-2023-38096CRITICALNETGEAR ProSAFE Network Management System MyHandlerInterceptor Authentication Bypass VulnerabilityEPSS 82.0%CVE-2024-5806CRITICALMOVEit Transfer Authentication Bypass VulnerabilityEPSS 81.5%CVE-2023-27351HIGHThis vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). AuthenticEPSS 78.1%KEVCVE-2021-41303Apache Shiro before 1.8.0, when using Apache Shiro with Spring Boot, a specially crafted HTTP request may cause an authentication bypassEPSS 76.7%CVE-2019-1937CRITICALCisco Integrated Management Controller Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data Authentication Bypass VulnerabilityEPSS 75.9%CVE-2023-32243CRITICALWordPress Essential Addons for Elementor Plugin 5.4.0-5.7.1 is vulnerable to Privilege EscalationEPSS 75.5%CVE-2025-1044CRITICALLogsign Unified SecOps Platform Authentication Bypass VulnerabilityEPSS 75.3%CVE-2024-28255CRITICALAuthentication Bypass in OpenMetadataEPSS 73.3%CVE-2026-16232CRITICALAuthentication Bypass in the SmartConsole Login Process Using an Application TokenEPSS 72.1%KEVCVE-2023-27482CRITICALhomeassistant is an open source home automation tool. A remotely exploitable vulnerability bypassing authentication for accessing the SupervEPSS 72.0%CVE-2020-4427CRITICALIBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 could allow a remote attacker to bypass security restrictions when configEPSS 70.0%KEVCVE-2020-26214CRITICALLDAP authentication bypass in AlertaEPSS 65.9%CVE-2023-6329CRITICALControl iD iDSecure passwordCustom Authentication BypassEPSS 65.0%CVE-2022-44574An improper authentication vulnerability exists in Avalanche version 6.3.x and below allows unauthenticated attacker to modify properties onEPSS 64.8%