Fallos del tipo CWE-287

2419 resultados

Autenticação inadequada ou ausente

A aplicação não valida ou valida de forma insuficiente a identidade de quem tenta acessá-la. Quando um usuário diz ser quem é, o sistema acredita sem verificar corretamente, permitindo que atacantes se façam passar por outros usuários ou contas legítimas.

Ejemplo

Um sistema que aceita login apenas com nome de usuário, sem senha. Ou uma API que confia no header 'User-ID' enviado pelo cliente sem validar se aquele usuário realmente existe ou tem sessão ativa. Um atacante simplesmente altera o header e acessa dados de outra conta.

Cómo mitigar

Implemente autenticação robusta: exija múltiplos fatores (senha forte + MFA), valide credenciais contra base de dados segura, use sessões com token assinado e com expiração, nunca confie em dados enviados pelo cliente como prova de identidade. Revise regularmente logs de acesso para detectar abusos.

CVE-2025-30432MEDIUMA logic issue was addressed with improved state management. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sonoma 14.EPSS 0.8%CVE-2026-15981CRITICALSAML Single Sign On <= 5.4.4 - Unauthenticated Authentication Bypass via SAMLResponse ParameterEPSS 0.8%CVE-2023-6847HIGHImproper Authentication in GitHub Enterprise Server leading to Authentication Bypass for Public Repository DataEPSS 0.8%CVE-2018-14637MEDIUMThe SAML broker consumer endpoint in Keycloak before version 4.6.0.Final ignores expiration conditions on SAML assertions. An attacker can eEPSS 0.8%CVE-2024-7923CRITICALPuppet-pulpcore: an authentication bypass vulnerability exists in pulpcoreEPSS 0.8%CVE-2021-43833HIGHAccount takeover in eLabFTWEPSS 0.8%CVE-2025-3621CRITICALRemote Code Execution in ProTNS ActADUREPSS 0.8%CVE-2018-16465Missing state in Nextcloud Server prior to 14.0.0 would not enforce the use of a second factor at login if the the provider of the second faEPSS 0.8%CVE-2021-38688HIGHImproper Authentication in QfileEPSS 0.8%CVE-2022-39248HIGHmatrix-android-sdk2 vulnerable to Olm/Megolm protocol confusionEPSS 0.8%CVE-2019-5426In Ubiquiti Networks EdgeSwitch X v1.1.0 and prior, an unauthenticated user can use the "local port forwarding" and "dynamic port forwardingEPSS 0.8%CVE-2026-41574CRITICALNhost Vulnerable to Account Takeover via OAuth Email Verification BypassEPSS 0.8%CVE-2022-39257HIGHMatrix iOS SDK vulnerable to impersonation via forwarded Megolm sessionsEPSS 0.8%CVE-2024-11015CRITICALSign In With Google <= 1.8.0 - Authentication Bypass in authenticate_userEPSS 0.8%CVE-2024-52786CRITICALAn authentication bypass vulnerability in anji-plus AJ-Report up to v1.4.2 allows unauthenticated attackers to execute arbitrary code via a EPSS 0.8%CVE-2021-26253HIGHBypass of Splunk Enterprise's implementation of DUO MFAEPSS 0.8%CVE-2021-41309MEDIUMAffected versions of Atlassian Jira Server and Data Center allow a user who has had their Jira Service Management access revoked to export aEPSS 0.8%CVE-2020-15240HIGHRegression in JWT Signature ValidationEPSS 0.8%CVE-2023-38372MEDIUMIBM Watson IoT Platform information disclosureEPSS 0.8%CVE-2021-27451HIGHMesa Labs AmegaView improper authenticationEPSS 0.8%