Fallos del tipo CWE-287

2419 resultados

Autenticação inadequada ou ausente

A aplicação não valida ou valida de forma insuficiente a identidade de quem tenta acessá-la. Quando um usuário diz ser quem é, o sistema acredita sem verificar corretamente, permitindo que atacantes se façam passar por outros usuários ou contas legítimas.

Ejemplo

Um sistema que aceita login apenas com nome de usuário, sem senha. Ou uma API que confia no header 'User-ID' enviado pelo cliente sem validar se aquele usuário realmente existe ou tem sessão ativa. Um atacante simplesmente altera o header e acessa dados de outra conta.

Cómo mitigar

Implemente autenticação robusta: exija múltiplos fatores (senha forte + MFA), valide credenciais contra base de dados segura, use sessões com token assinado e com expiração, nunca confie em dados enviados pelo cliente como prova de identidade. Revise regularmente logs de acesso para detectar abusos.

CVE-2022-39038HIGHFLOWRING Agentflow BPM - Broken Access ControlEPSS 0.9%CVE-2022-39366CRITICALDataHub missing JWT signature checkEPSS 0.9%CVE-2024-21632HIGHomniauth-microsoft_graph vulnerable to account takeover (nOAuth)EPSS 0.9%CVE-2026-45480CRITICALAzure Active Directory Elevation of Privilege VulnerabilityEPSS 0.9%CVE-2026-19924CRITICALTenda AC10 httpd R7WebsSecurityHandler improper authenticationEPSS 0.9%CVE-2026-75429CRITICALPowerJob versions 4.x through 5.1.2 contain an unauthenticated remote code execution vulnerability in the /friend/process endpoint of the SeEPSS 0.9%CVE-2026-1202MEDIUMCRMEB LoginController.php appleLogin improper authenticationEPSS 0.9%CVE-2024-7395CRITICALInsufficient AuthenticationEPSS 0.9%CVE-2022-23600MEDIUMLimited ability to spoof SAML authentication with missing audience verificationEPSS 0.9%CVE-2021-29487HIGHAuthentication bypass in OctobercmsEPSS 0.9%CVE-2026-12761CRITICALminiOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) <= 7.7.0 - Unauthenticated Authentication Bypass to Administrator Account Takeover via Profile Completion OTP FlowEPSS 0.9%CVE-2022-3173MEDIUMImproper Authentication in snipe/snipe-itEPSS 0.9%CVE-2024-5732MEDIUMClash Proxy Port improper authenticationEPSS 0.9%CVE-2018-16464A missing access check in Nextcloud Server prior to 14.0.0 could lead to continued access to password protected link shares when the owner hEPSS 0.9%CVE-2023-43809HIGHSoft Serve Public Key Authentication Bypass Vulnerability when Keyboard-Interactive SSH Authentication is EnabledEPSS 0.9%CVE-2022-48195CRITICALAn issue was discovered in Mellium mellium.im/sasl before 0.3.1. When performing SCRAM-based SASL authentication, if the remote end advertisEPSS 0.9%CVE-2022-44620HIGHImproper authentication vulnerability in UDR-JA1604/UDR-JA1608/UDR-JA1616 firmware versions 71x10.1.107112.43A and earlier allows a remote aEPSS 0.9%CVE-2022-37397HIGHThe software is vulnerable when using LDAP-based authentication in YCQL with Microsoft’s Active DirectoryEPSS 0.9%CVE-2022-2572CRITICALIn affected versions of Octopus Server where access is managed by an external authentication provider, it was possible that the API key/keysEPSS 0.9%CVE-2026-57216MEDIUMRabbitMQ: AMQP 1.0, AMQP 0-9-1, Stream Protocol loopback enforcement can lead to remote guest sessions due to listener-address loopback checksEPSS 0.9%