Fallos del tipo CWE-287

2430 resultados

Autenticação inadequada ou ausente

A aplicação não valida ou valida de forma insuficiente a identidade de quem tenta acessá-la. Quando um usuário diz ser quem é, o sistema acredita sem verificar corretamente, permitindo que atacantes se façam passar por outros usuários ou contas legítimas.

Ejemplo

Um sistema que aceita login apenas com nome de usuário, sem senha. Ou uma API que confia no header 'User-ID' enviado pelo cliente sem validar se aquele usuário realmente existe ou tem sessão ativa. Um atacante simplesmente altera o header e acessa dados de outra conta.

Cómo mitigar

Implemente autenticação robusta: exija múltiplos fatores (senha forte + MFA), valide credenciais contra base de dados segura, use sessões com token assinado e com expiração, nunca confie em dados enviados pelo cliente como prova de identidade. Revise regularmente logs de acesso para detectar abusos.

CVE-2026-5570MEDIUMTechnostrobe HI-LED-WR120-G2 LoginCB index_config improper authenticationEPSS 0.6%CVE-2025-22228HIGHCVE-2025-22228: Spring Security BCryptPasswordEncoder does not enforce maximum password lengthEPSS 0.6%CVE-2022-39254HIGHWhen matrix-nio receives forwarded room keys, the receiver doesn't check if it requested the key from the forwarderEPSS 0.6%CVE-2025-60772CRITICALImproper authentication in the web-based management interface of NETLINK HG322G V1.0.00-231017, allows a remote unauthenticated attacker to EPSS 0.6%CVE-2024-0002CRITICALA condition exists in FlashArray Purity whereby an attacker can employ a privileged account allowing remote access to the array.EPSS 0.6%CVE-2024-2450HIGHMattermost versions 8.1.x before 8.1.10, 9.2.x before 9.2.6, 9.3.x before 9.3.2, and 9.4.x before 9.4.3 fail to correctly verify account ownEPSS 0.6%CVE-2024-37893MEDIUMMFA bypass in oauth flow in Firefly IIIEPSS 0.6%CVE-2026-17142CRITICALVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.6%CVE-2019-1758MEDIUMCisco IOS Software Catalyst 6500 Series 802.1x Authentication Bypass VulnerabilityEPSS 0.6%CVE-2025-5149MEDIUMWCMS Login getallcon getMemberByUid improper authenticationEPSS 0.6%CVE-2026-2165MEDIUMdetronetdip E-commerce Account Creation Endpoint add_seller.php missing authenticationEPSS 0.6%CVE-2025-30215CRITICALNATS-Server Fails to Authorize Certain Jetstream Admin APIsEPSS 0.6%CVE-2024-45404HIGHOpenCTI's lack of Rate Limit lead to OTP brute forcingEPSS 0.6%CVE-2025-0604MEDIUMKeycloak-ldap-federation: authentication bypass due to missing ldap bind after password reset in keycloakEPSS 0.6%CVE-2020-8236—A wrong configuration in Nextcloud Server 19.0.1 incorrectly made the user feel the passwordless WebAuthn is also a two factor verification EPSS 0.6%CVE-2024-25652HIGHIn Delinea PAM Secret Server 11.4, it is possible for a user assigned "Administer Reports" permission and/or with access to Report functionaEPSS 0.6%CVE-2021-25505LOWImproper authentication in Samsung Pass prior to 3.0.02.4 allows to use app without authentication when lockscreen is unlocked.EPSS 0.6%CVE-2025-15097MEDIUMAlteryx Server status improper authenticationEPSS 0.6%CVE-2022-24740MEDIUMImproper Authentication in VoltoEPSS 0.6%CVE-2024-23813HIGHA vulnerability has been identified in Polarion ALM (All versions < V2404.0). The REST API endpoints of doorsconnector of the affected produEPSS 0.6%