Fallos del tipo CWE-287

2410 resultados

Autenticação inadequada ou ausente

A aplicação não valida ou valida de forma insuficiente a identidade de quem tenta acessá-la. Quando um usuário diz ser quem é, o sistema acredita sem verificar corretamente, permitindo que atacantes se façam passar por outros usuários ou contas legítimas.

Ejemplo

Um sistema que aceita login apenas com nome de usuário, sem senha. Ou uma API que confia no header 'User-ID' enviado pelo cliente sem validar se aquele usuário realmente existe ou tem sessão ativa. Um atacante simplesmente altera o header e acessa dados de outra conta.

Cómo mitigar

Implemente autenticação robusta: exija múltiplos fatores (senha forte + MFA), valide credenciais contra base de dados segura, use sessões com token assinado e com expiração, nunca confie em dados enviados pelo cliente como prova de identidade. Revise regularmente logs de acesso para detectar abusos.

CVE-2026-61435HIGHPraisonAI before 4.6.78 Authentication Bypass via Host Header SpoofingEPSS 0.7%CVE-2022-48364MEDIUMThe undo_mark_statuses_as_sensitive method in app/services/approve_appeal_service.rb in Mastodon 3.5.x before 3.5.3 does not use the server'EPSS 0.7%CVE-2024-1610HIGHOPPO Store app include remote account token hijacking and sensitive information leakageEPSS 0.7%CVE-2026-37270CRITICALTrueview Security camera T18161- AF v4.9.60.0 contains an authentication bypass vulnerability caused by improper password validation and theEPSS 0.7%CVE-2023-43793HIGHMisskey allows users to bypass authentication of Bull dashboardEPSS 0.7%CVE-2024-22206CRITICAL@clerk/nextjs auth() and getAuth() methods vulnerable to insecure direct object reference (IDOR)EPSS 0.7%CVE-2025-14703MEDIUMShiguangwu sgwbox N3 POST Message fsnotify improper authenticationEPSS 0.7%CVE-2023-22497MEDIUMNetdata is vulnerable to improper authenticationEPSS 0.7%CVE-2019-13423Search Guard Kibana Plugin versions before 5.6.8-7 and before 6.x.y-12 had an issue that an authenticated Kibana user could impersonate as kEPSS 0.7%CVE-2024-47080HIGHmatrix-js-sdk keys sent via `sendSharedHistoryKeys` vulnerable to interception by malicious homeserverEPSS 0.7%CVE-2026-28323CRITICALSolarWinds Web Help Desk SAML Authentication Bypass VulnerabilityEPSS 0.7%CVE-2024-11494HIGH**UNSUPPORTED WHEN ASSIGNED** The improper authentication vulnerability in the Zyxel P-6101C ADSL modem firmware version P-6101CSA6AP_201403EPSS 0.7%CVE-2025-60534CRITICALBlue Access Cobalt v02.000.195 suffers from an authentication bypass vulnerability, which allows an attacker to selectively proxy requests iEPSS 0.7%CVE-2025-7897MEDIUMharry0703 MoneyPrinterTurbo API Endpoint base.py verify_token missing authenticationEPSS 0.7%CVE-2025-66022CRITICALFACTION Unauthenticated Custom Extension Upload leads to RCEEPSS 0.7%CVE-2023-25597MEDIUMA vulnerability in the web conferencing component of Mitel MiCollab through 9.6.2.9 could allow an unauthenticated attacker to download a shEPSS 0.7%CVE-2022-36296MEDIUMWordPress ActiveDEMAND plugin <= 0.2.27 - Broken Authentication vulnerabilityEPSS 0.7%CVE-2022-24901HIGHAuthentication bypass and denial of service (DoS) vulnerabilities in Apple Game Center auth adapter EPSS 0.7%CVE-2023-44752CRITICALAn issue in Student Study Center Desk Management System v1.0 allows attackers to bypass authentication via a crafted GET request to /php-sscEPSS 0.7%CVE-2026-4664MEDIUMCustomer Reviews for WooCommerce <= 5.103.0 - Unauthenticated Authentication Bypass to Arbitrary Review Submission via 'key' ParameterEPSS 0.7%