Fallos del tipo CWE-287

2430 resultados

Autenticação inadequada ou ausente

A aplicação não valida ou valida de forma insuficiente a identidade de quem tenta acessá-la. Quando um usuário diz ser quem é, o sistema acredita sem verificar corretamente, permitindo que atacantes se façam passar por outros usuários ou contas legítimas.

Ejemplo

Um sistema que aceita login apenas com nome de usuário, sem senha. Ou uma API que confia no header 'User-ID' enviado pelo cliente sem validar se aquele usuário realmente existe ou tem sessão ativa. Um atacante simplesmente altera o header e acessa dados de outra conta.

Cómo mitigar

Implemente autenticação robusta: exija múltiplos fatores (senha forte + MFA), valide credenciais contra base de dados segura, use sessões com token assinado e com expiração, nunca confie em dados enviados pelo cliente como prova de identidade. Revise regularmente logs de acesso para detectar abusos.

CVE-2024-11322HIGHCyberPower PowerPanel Business Unauthenticated Restart DoSEPSS 0.6%CVE-2022-46400MEDIUMThe Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) allows attackers to bypass passkey enEPSS 0.6%CVE-2026-25748HIGHauthentik has a forward authentication bypass with broken cookieEPSS 0.6%CVE-2024-51996HIGHSymphony has an Authentication Bypass via RememberMeEPSS 0.6%CVE-2023-1477HIGHImproper Authentication vulnerability in HYPR Keycloak Authenticator Extension allows Authentication Abuse.This issue affects HYPR Keycloak EPSS 0.6%CVE-2026-55652CRITICALWekan: Header-login IP allowlist bypass via X-Forwarded-For spoofing in Wekan allows unauthenticated full account takeover (incl. admin)EPSS 0.6%CVE-2024-11209MEDIUMApereo CAS 2FA login improper authenticationEPSS 0.6%CVE-2023-25913HIGHAuthentication Bypass in Danfoss AK-SM800AEPSS 0.6%CVE-2022-4441HIGHPrivilege Escalation Vulnerability in Hitachi Storage Plug-in for VMware vCenterEPSS 0.6%CVE-2023-30967CRITICALGotham Orbital Simulator path traversalEPSS 0.6%CVE-2023-44397HIGHCloudExplorer Lite permission bypass vulnerabilityEPSS 0.6%CVE-2024-7763CRITICALWhatsUp Gold getReport Missing Authentication Authentication Bypass VulnerabilityEPSS 0.6%CVE-2022-29893HIGHImproper authentication in firmware for Intel(R) AMT before versions 11.8.93, 11.22.93, 11.12.93, 12.0.92, 14.1.67, 15.0.42, 16.1.25 may allEPSS 0.6%CVE-2023-4816MEDIUMA vulnerability exists in the Equipment Tag Out authentication, when configured with Single Sign-On (SSO) with password validation in T214. EPSS 0.6%CVE-2026-8979CRITICALAuthentication BypassEPSS 0.6%CVE-2026-54089CRITICALFile Browser: Authentication Bypass via Proxy Auth Header ForgeryEPSS 0.6%CVE-2026-42041MEDIUMAxios: Authentication Bypass via Prototype Pollution Gadget in `validateStatus` Merge StrategyEPSS 0.6%CVE-2025-54888HIGH@fedify/fedify: Improper Authentication and Incorrect AuthorizationEPSS 0.6%CVE-2025-3850MEDIUMYXJ2018 SpringBoot-Vue-OnlineExam API improper authenticationEPSS 0.6%CVE-2026-37006CRITICALA vulnerability in the WebSocket endpoint of gpt-researcher v0.14.7 and before allows an unauthenticated remote attacker to achieve code exeEPSS 0.6%