Fallos del tipo CWE-287

2430 resultados

Autenticação inadequada ou ausente

A aplicação não valida ou valida de forma insuficiente a identidade de quem tenta acessá-la. Quando um usuário diz ser quem é, o sistema acredita sem verificar corretamente, permitindo que atacantes se façam passar por outros usuários ou contas legítimas.

Ejemplo

Um sistema que aceita login apenas com nome de usuário, sem senha. Ou uma API que confia no header 'User-ID' enviado pelo cliente sem validar se aquele usuário realmente existe ou tem sessão ativa. Um atacante simplesmente altera o header e acessa dados de outra conta.

Cómo mitigar

Implemente autenticação robusta: exija múltiplos fatores (senha forte + MFA), valide credenciais contra base de dados segura, use sessões com token assinado e com expiração, nunca confie em dados enviados pelo cliente como prova de identidade. Revise regularmente logs de acesso para detectar abusos.

CVE-2023-6155MEDIUMQuiz Maker < 6.4.9.5 - Unauthenticated Email Address DisclosureEPSS 0.6%CVE-2024-12287CRITICALBiagiotti Membership <= 1.0.2 - Authentication Bypass via biagiotti_membership_check_facebook_userEPSS 0.6%CVE-2023-51471HIGHWordPress Checkout Mestres WP plugin <= 7.1.9.7 - Unauthenticated Arbitrary Options Update vulnerabilityEPSS 0.6%CVE-2025-11287MEDIUMsamanhappy MCPHub sseService.ts handleSseConnectionfunction improper authenticationEPSS 0.6%CVE-2023-28962MEDIUMJunos OS: Unauthenticated access vulnerability in J-WebEPSS 0.6%CVE-2023-3127HIGHImproper Authentication in iSTAREPSS 0.6%CVE-2025-52395CRITICALAn issue in Roadcute API v.1 allows a remote attacker to execute arbitrary code via the application exposing a password reset API endpoint tEPSS 0.6%CVE-2024-10327HIGHA vulnerability in Okta Verify for iOS versions 9.25.1 (beta) and 9.27.0 (including beta) allows push notification responses through the iOSEPSS 0.6%CVE-2026-3192MEDIUMChia Blockchain RPC Credential rpc_server_base.py _authenticate improper authenticationEPSS 0.6%CVE-2026-18922CRITICAL389-ds-base: 389-ds-base: sasl plain authentication allows privilege escalation to directory manager via stale identity in cyrus sasl auxiliary propertyEPSS 0.6%CVE-2021-25368LOWHijacking vulnerability in Samsung Cloud prior to version 4.7.0.3 allows attackers to intercept when the provider is executed.EPSS 0.6%CVE-2024-12919CRITICALPaid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction <= 2.13.7 - Authentication Bypass via pms_payment_idEPSS 0.6%CVE-2023-48703HIGHSAML authentication bypass vulnerability in RobotsAndPencils/go-samlEPSS 0.6%CVE-2026-12598HIGHLoginPress Pro <= 6.2.3 - Unauthenticated Authentication Bypass via Unverified OAuth Email in Spotify OAuth CallbackEPSS 0.6%CVE-2026-12595HIGHLoginPress Pro <= 6.2.3 - Unauthenticated Authentication Bypass via Unverified OAuth Email via Discord OAuth CallbackEPSS 0.6%CVE-2025-49812HIGHApache HTTP Server: mod_ssl TLS upgrade attackEPSS 0.6%CVE-2023-48865MEDIUMAn issue discovered in Reportico Till 8.1.0 allows attackers to obtain sensitive information via execute_mode parameter of the URL.EPSS 0.6%CVE-2022-37774MEDIUMThere is a broken access control vulnerability in the Maarch RM 2.8.3 solution. When accessing some specific document (pdf, email) from an aEPSS 0.6%CVE-2026-24898CRITICALOpenEMR has an Unauthenticated MedEx Token DisclosureEPSS 0.6%CVE-2026-14627MEDIUMNousResearch hermes-agent Discord Platform Integration discord.py DiscordAdapter._is_allowed_user improper authenticationEPSS 0.6%