Fallos del tipo CWE-287

2410 resultados

Autenticação inadequada ou ausente

A aplicação não valida ou valida de forma insuficiente a identidade de quem tenta acessá-la. Quando um usuário diz ser quem é, o sistema acredita sem verificar corretamente, permitindo que atacantes se façam passar por outros usuários ou contas legítimas.

Ejemplo

Um sistema que aceita login apenas com nome de usuário, sem senha. Ou uma API que confia no header 'User-ID' enviado pelo cliente sem validar se aquele usuário realmente existe ou tem sessão ativa. Um atacante simplesmente altera o header e acessa dados de outra conta.

Cómo mitigar

Implemente autenticação robusta: exija múltiplos fatores (senha forte + MFA), valide credenciais contra base de dados segura, use sessões com token assinado e com expiração, nunca confie em dados enviados pelo cliente como prova de identidade. Revise regularmente logs de acesso para detectar abusos.

CVE-2024-50339CRITICALGLPI vulnerable to unauthenticated session hijackingEPSS 18.7%CVE-2025-58443CRITICALFOG's authentication bypass leads to full SQL DB dumpEPSS 18.5%CVE-2020-27838A flaw was found in keycloak in versions prior to 13.0.0. The client registration endpoint allows fetching information about PUBLIC clients EPSS 17.9%CVE-2017-11151A vulnerability in synotheme_upload.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to upload arbitraryEPSS 16.3%CVE-2023-20238CRITICALA vulnerability in the single sign-on (SSO) implementation of Cisco BroadWorks Application Delivery Platform and Cisco BroadWorks Xtended SeEPSS 16.3%CVE-2018-1163This vulnerability allows remote attackers to bypass authentication on vulnerable installations of Quest NetVault Backup 11.2.0.13. The specEPSS 16.0%CVE-2023-22501CRITICALAn authentication vulnerability was discovered in Jira Service Management Server and Data Center which allows an attacker to impersonate anoEPSS 15.5%CVE-2026-8181CRITICALBurst Statistics 3.4.0 - 3.4.1.1 - Authentication Bypass to Admin Account TakeoverEPSS 14.6%CVE-2021-24175The Plus Addons for Elementor Page Builder < 4.1.7 - Authentication BypassEPSS 14.5%CVE-2024-49039HIGHWindows Task Scheduler Elevation of Privilege VulnerabilityEPSS 14.2%KEVCVE-2016-1908CRITICALThe client in OpenSSH before 7.2 mishandles failed cookie generation for untrusted X11 forwarding and relies on the local X11 server for accEPSS 13.7%CVE-2025-0890CRITICAL**UNSUPPORTED WHEN ASSIGNED** Insecure default credentials for the Telnet function in the legacy DSL CPE Zyxel VMG4325-B10A firmware versionEPSS 13.5%CVE-2023-20867LOWVMware Tools Authentication Bypass VulnerabilityEPSS 13.5%KEVCVE-2026-46817CRITICALVulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affecteEPSS 13.0%KEVCVE-2024-21410CRITICALMicrosoft Exchange Server Elevation of Privilege VulnerabilityEPSS 12.6%KEVCVE-2021-26117ActiveMQ: LDAP-Authentication does not verify passwords on servers with anonymous bindEPSS 11.3%CVE-2025-52376CRITICALAn authentication bypass vulnerability in the /web/um_open_telnet.cgi endpoint in Nexxt Solutions NCM-X1800 Mesh Router firmware UV1.2.7 andEPSS 11.2%CVE-2026-42018HIGHAnonymous user token generation exposure in JFrog ArtifactoryEPSS 11.0%KEVCVE-2026-65400CRITICALAn authentication issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.7.9, macEPSS 10.5%KEVCVE-2021-24647Pie Register < 3.7.1.6 - Unauthenticated Arbitrary LoginEPSS 9.8%