Fallos del tipo CWE-287

2430 resultados

Autenticação inadequada ou ausente

A aplicação não valida ou valida de forma insuficiente a identidade de quem tenta acessá-la. Quando um usuário diz ser quem é, o sistema acredita sem verificar corretamente, permitindo que atacantes se façam passar por outros usuários ou contas legítimas.

Ejemplo

Um sistema que aceita login apenas com nome de usuário, sem senha. Ou uma API que confia no header 'User-ID' enviado pelo cliente sem validar se aquele usuário realmente existe ou tem sessão ativa. Um atacante simplesmente altera o header e acessa dados de outra conta.

Cómo mitigar

Implemente autenticação robusta: exija múltiplos fatores (senha forte + MFA), valide credenciais contra base de dados segura, use sessões com token assinado e com expiração, nunca confie em dados enviados pelo cliente como prova de identidade. Revise regularmente logs de acesso para detectar abusos.

CVE-2026-16015MEDIUMpoco-ai poco-claw executor_manager API tasks.py create_task missing authenticationEPSS 0.6%CVE-2023-37226CRITICALLoftware Spectrum before 4.6 HF14 has Missing Authentication for a Critical Function.EPSS 0.6%CVE-2018-8862—In ATI Systems Emergency Mass Notification Systems (HPSS16, HPSS32, MHPSS, and ALERT4000) devices, an improper authentication vulnerability EPSS 0.6%CVE-2024-45106HIGHApache Ozone: Improper authentication when generating S3 secretsEPSS 0.6%CVE-2026-2065MEDIUMFlycatcher Toys smART Pixelator Bluetooth Low Energy missing authenticationEPSS 0.6%CVE-2025-27138HIGHDataEase has an improper authentication vulnerabilityEPSS 0.6%CVE-2026-0589MEDIUMcode-projects Online Product Reservation System Administration Backend improper authenticationEPSS 0.6%CVE-2026-59955HIGHApollo ConfigService access key authentication bypass via raw config file appId parsingEPSS 0.6%CVE-2023-48312CRITICALAuthentication bypass using an empty token in capsule-proxyEPSS 0.6%CVE-2026-59954HIGHApollo ConfigService access key authentication bypass via appId parsing and non-canonical matchingEPSS 0.6%CVE-2025-68717CRITICALKAYSUS KS-WR3600 routers with firmware 1.0.5.9.1 allow authentication bypass during session validation. If any user is logged in, endpoints EPSS 0.6%CVE-2022-0985—Insufficient capability checks could allow users with the moodle/site:uploadusers capability to delete users, without having the necessary mEPSS 0.6%CVE-2024-7050HIGHImproper Authentication vulnerability in OpenText OpenText Directory Services may allow Multi-factor Authentication Bypass in particular sceEPSS 0.6%CVE-2022-27839LOWImproper authentication vulnerability in SecretMode in Samsung Internet prior to version 16.2.1 allows attackers to access bookmark tab withEPSS 0.6%CVE-2024-47070CRITICALauthentik vulnerable to password authentication bypass via X-Forwarded-For HTTP headerEPSS 0.6%CVE-2026-12597HIGHLoginPress Pro <= 6.2.3 - Unauthenticated Authentication Bypass via Unverified OAuth Email via GitHub OAuth CallbackEPSS 0.6%CVE-2024-41198CRITICALAn issue in Ocuco Innovation - REPORTS.EXE v2.10.24.13 allows attackers to bypass authentication and escalate privileges to Administrator viEPSS 0.6%CVE-2024-41197CRITICALAn issue in Ocuco Innovation - INVCLIENT.EXE v2.10.24.5 allows attackers to bypass authentication and escalate privileges to Administrator vEPSS 0.6%CVE-2024-41195CRITICALAn issue in Ocuco Innovation - INNOVASERVICEINTF.EXE v2.10.24.17 allows attackers to bypass authentication and escalate privileges to AdminiEPSS 0.6%CVE-2023-6155MEDIUMQuiz Maker < 6.4.9.5 - Unauthenticated Email Address DisclosureEPSS 0.6%