Fallos del tipo CWE-287

2419 resultados

Autenticação inadequada ou ausente

A aplicação não valida ou valida de forma insuficiente a identidade de quem tenta acessá-la. Quando um usuário diz ser quem é, o sistema acredita sem verificar corretamente, permitindo que atacantes se façam passar por outros usuários ou contas legítimas.

Ejemplo

Um sistema que aceita login apenas com nome de usuário, sem senha. Ou uma API que confia no header 'User-ID' enviado pelo cliente sem validar se aquele usuário realmente existe ou tem sessão ativa. Um atacante simplesmente altera o header e acessa dados de outra conta.

Cómo mitigar

Implemente autenticação robusta: exija múltiplos fatores (senha forte + MFA), valide credenciais contra base de dados segura, use sessões com token assinado e com expiração, nunca confie em dados enviados pelo cliente como prova de identidade. Revise regularmente logs de acesso para detectar abusos.

CVE-2023-25597MEDIUMA vulnerability in the web conferencing component of Mitel MiCollab through 9.6.2.9 could allow an unauthenticated attacker to download a shEPSS 0.7%CVE-2022-36296MEDIUMWordPress ActiveDEMAND plugin <= 0.2.27 - Broken Authentication vulnerabilityEPSS 0.7%CVE-2023-44752CRITICALAn issue in Student Study Center Desk Management System v1.0 allows attackers to bypass authentication via a crafted GET request to /php-sscEPSS 0.7%CVE-2026-4664MEDIUMCustomer Reviews for WooCommerce <= 5.103.0 - Unauthenticated Authentication Bypass to Arbitrary Review Submission via 'key' ParameterEPSS 0.7%CVE-2025-60424HIGHA lack of rate limiting in the OTP verification component of Nagios Fusion v2024R1.2 and v2024R2 allows attackers to bypass authentication vEPSS 0.7%CVE-2022-2664HIGHPrivate Cloud Management Platform POST Request global_config_query improper authenticationEPSS 0.7%CVE-2026-50559HIGHAuthentication/Authorization Bypass via Advanced Path Normalization VulnerabilitiesEPSS 0.7%CVE-2022-39009CRITICALThe WLAN module has a vulnerability in permission verification. Successful exploitation of this vulnerability may cause third-party apps to EPSS 0.7%CVE-2026-47159MEDIUMVaultwarden: Authentication Flow Information Disclosure in SSO Discovery Allows Organization Enumeration and Pre-Validation Token ExposureEPSS 0.7%CVE-2023-32347HIGH Teltonika’s Remote Management System versions prior to 4.10.0 use device serial numbers and MAC addresses to identify devices from the userEPSS 0.7%CVE-2026-56162CRITICALAzure SQL Database Elevation of Privilege VulnerabilityEPSS 0.7%CVE-2026-5270CRITICALAuthentication Bypass in Navigator and Blue Planet ProductsEPSS 0.7%CVE-2026-55445CRITICALQinglong: Incomplete fix for CVE-2026-3965: Improper AuthenticationEPSS 0.7%CVE-2026-61740CRITICALLightRAG: Authentication bypass: hardcoded DEFAULT_TOKEN_SECRET and public /auth-status defeat LIGHTRAG_API_KEY protectionEPSS 0.7%CVE-2025-4019MEDIUM20120630 Novel-Plus GeneratorController.java genCode missing authenticationEPSS 0.7%CVE-2026-8305MEDIUMOpenClaw bluebubbles Webhook monitor.ts handleBlueBubblesWebhookRequest improper authenticationEPSS 0.7%CVE-2026-86810MEDIUMOpen-Web-Analytics Controller Controller.php checkCapabilityAndAuthenticateUser improper authenticationEPSS 0.7%CVE-2020-7293CRITICALWeb Gateway (MWG) - Privilege Escalation vulnerabilityEPSS 0.7%CVE-2023-35940HIGHGLPI vulnerable to unauthenticated access to Dashboard dataEPSS 0.7%CVE-2022-23554MEDIUMAuthentication bypass in AlpineEPSS 0.7%