Fallos del tipo CWE-287

2430 resultados

Autenticação inadequada ou ausente

A aplicação não valida ou valida de forma insuficiente a identidade de quem tenta acessá-la. Quando um usuário diz ser quem é, o sistema acredita sem verificar corretamente, permitindo que atacantes se façam passar por outros usuários ou contas legítimas.

Ejemplo

Um sistema que aceita login apenas com nome de usuário, sem senha. Ou uma API que confia no header 'User-ID' enviado pelo cliente sem validar se aquele usuário realmente existe ou tem sessão ativa. Um atacante simplesmente altera o header e acessa dados de outra conta.

Cómo mitigar

Implemente autenticação robusta: exija múltiplos fatores (senha forte + MFA), valide credenciais contra base de dados segura, use sessões com token assinado e com expiração, nunca confie em dados enviados pelo cliente como prova de identidade. Revise regularmente logs de acesso para detectar abusos.

CVE-2026-48812HIGHFreeScout Allows Unauthenticated Access to Legacy Attachment FilesEPSS 0.6%CVE-2025-52856CRITICALVioStorEPSS 0.6%CVE-2024-9946HIGHSocial Share, Social Login and Social Comments Plugin – Super Socializer <= 7.13.68 - Authentication Bypass via Disqus OAuth providerEPSS 0.6%CVE-2018-0163—A vulnerability in the 802.1x multiple-authentication (multi-auth) feature of Cisco IOS Software could allow an unauthenticated, adjacent atEPSS 0.6%CVE-2024-47807HIGHJenkins OpenId Connect Authentication Plugin 4.354.v321ce67a_1de8 and earlier does not check the `iss` (Issuer) claim of an ID Token, allowiEPSS 0.6%CVE-2024-47806HIGHJenkins OpenId Connect Authentication Plugin 4.354.v321ce67a_1de8 and earlier does not check the `aud` (Audience) claim of an ID Token, alloEPSS 0.6%CVE-2020-8350HIGHAn authentication bypass vulnerability was reported in Lenovo ThinkPad Stack Wireless Router firmware version 1.1.3.4 that could allow escalEPSS 0.6%CVE-2026-10243MEDIUMcode-projects Smart Parking System Admin Endpoint missing authenticationEPSS 0.6%CVE-2026-86808MEDIUMmoltis-org moltis vault.rs vault_recovery_handler missing authenticationEPSS 0.6%CVE-2025-55171HIGHWeGIA Anonymous Attacker can Delete Arbitrary Image file at endpoint `/html/personalizacao_remover.php`EPSS 0.6%CVE-2026-90504MEDIUMvvbbnn00 WARP-Clash-API authorized missing authenticationEPSS 0.6%CVE-2025-46348CRITICALYesWiki Vulnerable to Unauthenticated Site Backup Creation and DownloadEPSS 0.6%CVE-2026-35030CRITICALLiteLLM has an authentication bypass via OIDC userinfo cache key collisionEPSS 0.6%CVE-2026-53483CRITICALDell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1EPSS 0.6%CVE-2024-22442CRITICALThe vulnerability could be remotely exploited to bypass authentication.EPSS 0.6%CVE-2023-1065MEDIUMThis vulnerability in the Snyk Kubernetes Monitor can result in irrelevant data being posted to a Snyk Organization, which could in turn obfEPSS 0.6%CVE-2024-6576HIGHMOVEit Transfer Privilege Escalation VulnerabilityEPSS 0.6%CVE-2024-2873CRITICALUser authentication bypass in wolfSSH serverEPSS 0.6%CVE-2025-27672CRITICALVasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows OAUTH Security Bypass OVE-20230524-EPSS 0.6%CVE-2024-11322HIGHCyberPower PowerPanel Business Unauthenticated Restart DoSEPSS 0.6%