Fallos del tipo CWE-287

2405 resultados

Autenticação inadequada ou ausente

A aplicação não valida ou valida de forma insuficiente a identidade de quem tenta acessá-la. Quando um usuário diz ser quem é, o sistema acredita sem verificar corretamente, permitindo que atacantes se façam passar por outros usuários ou contas legítimas.

Ejemplo

Um sistema que aceita login apenas com nome de usuário, sem senha. Ou uma API que confia no header 'User-ID' enviado pelo cliente sem validar se aquele usuário realmente existe ou tem sessão ativa. Um atacante simplesmente altera o header e acessa dados de outra conta.

Cómo mitigar

Implemente autenticação robusta: exija múltiplos fatores (senha forte + MFA), valide credenciais contra base de dados segura, use sessões com token assinado e com expiração, nunca confie em dados enviados pelo cliente como prova de identidade. Revise regularmente logs de acesso para detectar abusos.

CVE-2024-1147CRITICALWeak Access Control - Arbitrary file downloadEPSS 0.7%CVE-2023-51477CRITICALWordPress BuddyBoss Theme theme <= 2.4.60 - Unauth. Arbitrary WordPress Settings Change vulnerabilityEPSS 0.7%CVE-2026-15542MEDIUMwill-moss Isaiah Websocket Connection Authentication main.go improper authenticationEPSS 0.7%CVE-2025-7875MEDIUMMetasoft 美特软件 MetaCRM debug.jsp improper authenticationEPSS 0.7%CVE-2026-90524MEDIUMjaychouchannel Tourism-Management-System Update Endpoint missing authenticationEPSS 0.7%CVE-2023-3337HIGHPuneethReddyHC Online Shopping System Advanced Admin Registration reg.php improper authenticationEPSS 0.7%CVE-2024-25699HIGHPortal for ArcGIS has an invalid authentication vulnerabilityEPSS 0.7%CVE-2024-10097HIGHLoginizer Security and Loginizer <= 1.9.2 - Authentication Bypass via WordPress.com OAuth providerEPSS 0.7%CVE-2022-39801HIGHSAP GRC Access control Emergency Access Management allows an authenticated attacker to access a Firefighter session even after it is closed EPSS 0.7%CVE-2025-52572CRITICALHikka vulnerable to RCE through dangling web interfaceEPSS 0.7%CVE-2020-36832CRITICALIndeed Membership Pro 7.3 - 8.6 - Authentication BypassEPSS 0.7%CVE-2023-51442HIGHAuthentication bypass vulnerability in navidrome's subsonic endpointEPSS 0.7%CVE-2024-27767CRITICALUnitronics Unistream Unilogic – Versions prior to 1.35.227 CWE-287: Improper AuthenticationEPSS 0.7%CVE-2026-14622MEDIUMjairiidriss restaurant-website-php-mysql AJAX Endpoint ajax_files missing authenticationEPSS 0.7%CVE-2022-39264HIGHnheko vulnerable to secret poisoning using MITM on secret requests by the homeserverEPSS 0.7%CVE-2023-23460CRITICALPriority Web – Authentication bypass EPSS 0.7%CVE-2025-32877CRITICALAn issue was discovered on COROS PACE 3 devices through 3.0808.0. It identifies itself as a device without input or output capabilities, whiEPSS 0.7%CVE-2026-15557MEDIUMwaooAI waoowaoo Internal Task Header api-auth.ts requireProjectAuthLight improper authenticationEPSS 0.7%CVE-2026-16210MEDIUMnewpanjing simpleui AjaxAdmin AJAX Endpoint admin.py self.get_action missing authenticationEPSS 0.7%CVE-2026-61435HIGHPraisonAI before 4.6.78 Authentication Bypass via Host Header SpoofingEPSS 0.7%