Fallos del tipo CWE-287

2420 resultados

Autenticação inadequada ou ausente

A aplicação não valida ou valida de forma insuficiente a identidade de quem tenta acessá-la. Quando um usuário diz ser quem é, o sistema acredita sem verificar corretamente, permitindo que atacantes se façam passar por outros usuários ou contas legítimas.

Ejemplo

Um sistema que aceita login apenas com nome de usuário, sem senha. Ou uma API que confia no header 'User-ID' enviado pelo cliente sem validar se aquele usuário realmente existe ou tem sessão ativa. Um atacante simplesmente altera o header e acessa dados de outra conta.

Cómo mitigar

Implemente autenticação robusta: exija múltiplos fatores (senha forte + MFA), valide credenciais contra base de dados segura, use sessões com token assinado e com expiração, nunca confie em dados enviados pelo cliente como prova de identidade. Revise regularmente logs de acesso para detectar abusos.

CVE-2026-92401MEDIUMChangeWeDer crm improper authenticationEPSS 0.7%CVE-2023-51472CRITICALWordPress Checkout Mestres WP plugin <= 7.1.9.7 - Unauthenticated Account Takeover vulnerabilityEPSS 0.7%CVE-2025-37184CRITICALUnauthenticated Bypass Allows Multi-Factor Authentication CircumventionEPSS 0.7%CVE-2024-41196CRITICALAn issue in Ocuco Innovation - REPORTSERVER.EXE v2.10.24.13 allows attackers to bypass authentication and escalate privileges to AdministratEPSS 0.7%CVE-2022-42951HIGHAn issue was discovered in Couchbase Server 6.5.x and 6.6.x before 6.6.6, 7.x before 7.0.5, and 7.1.x before 7.1.2. During the start-up of aEPSS 0.7%CVE-2023-51405HIGHWordPress BookingPress plugin <= 1.0.74 - Booking Price Manipulation vulnerabilityEPSS 0.7%CVE-2026-0953CRITICALTutor LMS Pro <= 3.9.5 - Authentication Bypass via Social LoginEPSS 0.7%CVE-2023-51482CRITICALWordPress Eazy Plugin Manager plugin <= 4.1.2 - Auth. Arbitrary Options Update lead to RCE vulnerabilityEPSS 0.7%CVE-2026-15491MEDIUMRafyMrX TOKO-ONLINE-ROTI missing authenticationEPSS 0.7%CVE-2026-95271MEDIUMdgtlmoon changedetection.io Authentication Hook flask_app.py check_authentication improper authenticationEPSS 0.7%CVE-2026-13546MEDIUMFeehi CMS REST API Endpoint articles missing authenticationEPSS 0.7%CVE-2024-50645CRITICALMallChat v1.0-SNAPSHOT has an authentication bypass vulnerability. An attacker can exploit this vulnerability to access API without any tokeEPSS 0.7%CVE-2023-46249CRITICALauthentik potential installation takeover when default admin user is deletedEPSS 0.7%CVE-2026-3794MEDIUMdoramart DoraCMS Email API send improper authenticationEPSS 0.7%CVE-2023-30845HIGHESPv2 vulnerable to JWT authentication bypass via `X-HTTP-Method-Override` headerEPSS 0.7%CVE-2022-31122CRITICALWire-server vulnerable to Token Recipient Confusion resulting in account impersonation, deletion or malicious account creationEPSS 0.7%CVE-2022-47408CRITICALAn issue was discovered in the fp_newsletter (aka Newsletter subscriber management) extension before 1.1.1, 1.2.0, 2.x before 2.1.2, 2.2.1 tEPSS 0.7%CVE-2020-1778MEDIUMBypassing user account validationEPSS 0.7%CVE-2021-26074MEDIUMBroken Authentication in Atlassian Connect Spring Boot (ACSB) from version 1.1.0 before version 2.1.3: Atlassian Connect Spring Boot is a JaEPSS 0.7%CVE-2026-26035HIGHAn Improper Authentication vulnerability [CWE-287] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, ForEPSS 0.7%