Fallos del tipo CWE-287

2421 resultados

Autenticação inadequada ou ausente

A aplicação não valida ou valida de forma insuficiente a identidade de quem tenta acessá-la. Quando um usuário diz ser quem é, o sistema acredita sem verificar corretamente, permitindo que atacantes se façam passar por outros usuários ou contas legítimas.

Ejemplo

Um sistema que aceita login apenas com nome de usuário, sem senha. Ou uma API que confia no header 'User-ID' enviado pelo cliente sem validar se aquele usuário realmente existe ou tem sessão ativa. Um atacante simplesmente altera o header e acessa dados de outra conta.

Cómo mitigar

Implemente autenticação robusta: exija múltiplos fatores (senha forte + MFA), valide credenciais contra base de dados segura, use sessões com token assinado e com expiração, nunca confie em dados enviados pelo cliente como prova de identidade. Revise regularmente logs de acesso para detectar abusos.

CVE-2024-28009CRITICALImproper authentication vulnerability in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WEPSS 0.7%CVE-2024-28007CRITICALImproper authentication vulnerability in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WEPSS 0.7%CVE-2023-31123CRITICALeffectindex/tripreporter vulnerable to improper password verification on POST `/api/v1/account/login`EPSS 0.6%CVE-2026-52830CRITICALfast-mcp-telegram: Bearer token path traversal bypasses reserved Telegram session protectionEPSS 0.6%CVE-2026-31377HIGHApache Doris: Improper Authentication Allows Unauthorized Access to FE Meta ServiceEPSS 0.6%CVE-2023-43805HIGHNexkey allows users to bypass authentication of Bull dashboardEPSS 0.6%CVE-2025-47889CRITICALIn Jenkins WSO2 Oauth Plugin 1.0 and earlier, authentication claims are accepted without validation by the "WSO2 Oauth" security realm, alloEPSS 0.6%CVE-2022-1349WPQA < 5.2 - Subscriber+ Arbitrary Profile Picture Deletion via IDOREPSS 0.6%CVE-2026-69854CRITICALSpring Cloud Azure Elevation of Privilege VulnerabilityEPSS 0.6%CVE-2022-31164HIGHTovy before v0.7.51 vulnerable to users logging in as and impersonating other usersEPSS 0.6%CVE-2026-37271CRITICALFire-Boltt Smartwatch FB BGS001 Firmware: MOY-JS14-2.0.4 is vulnerable to Improper Authentication, The device accepts GATT Write Request comEPSS 0.6%CVE-2025-6528MEDIUM70mai M300 RTSP Live Video Stream Endpoint 12 improper authenticationEPSS 0.6%CVE-2024-3701CRITICALImproper Authentication in com.transsion.kolun.aiserviceEPSS 0.6%CVE-2023-46717MEDIUMAn improper authentication vulnerability [CWE-287] in FortiOS versions 7.4.1 and below, versions 7.2.6 and below, and versions 7.0.12 and beEPSS 0.6%CVE-2026-66014HIGHPotential authentication bypass leading to privilege escalation in ArtifactoryEPSS 0.6%CVE-2022-46875MEDIUMThe executable file warning was not presented when downloading .atloc and .ftploc files, which can run commands on a user's computer. <br>*NEPSS 0.6%CVE-2026-16198MEDIUMSipeed PicoClaw First Run Setup access_control.go authentication bypassEPSS 0.6%CVE-2022-39263MEDIUMNextAuth.js Upstash Adapter missing token verificationEPSS 0.6%CVE-2025-1475CRITICALWPCOM Member <= 1.7.5 - Authentication Bypass via 'user_phone'EPSS 0.6%CVE-2026-48812HIGHFreeScout Allows Unauthenticated Access to Legacy Attachment FilesEPSS 0.6%