Fallos del tipo CWE-287

2430 resultados

Autenticação inadequada ou ausente

A aplicação não valida ou valida de forma insuficiente a identidade de quem tenta acessá-la. Quando um usuário diz ser quem é, o sistema acredita sem verificar corretamente, permitindo que atacantes se façam passar por outros usuários ou contas legítimas.

Ejemplo

Um sistema que aceita login apenas com nome de usuário, sem senha. Ou uma API que confia no header 'User-ID' enviado pelo cliente sem validar se aquele usuário realmente existe ou tem sessão ativa. Um atacante simplesmente altera o header e acessa dados de outra conta.

Cómo mitigar

Implemente autenticação robusta: exija múltiplos fatores (senha forte + MFA), valide credenciais contra base de dados segura, use sessões com token assinado e com expiração, nunca confie em dados enviados pelo cliente como prova de identidade. Revise regularmente logs de acesso para detectar abusos.

CVE-2026-14627MEDIUMNousResearch hermes-agent Discord Platform Integration discord.py DiscordAdapter._is_allowed_user improper authenticationEPSS 0.6%CVE-2025-49851HIGHImproper Authentication in ControlID iDSecure On-premisesEPSS 0.6%CVE-2022-44610MEDIUMImproper authentication in the Intel(R) DCM software before version 5.1 may allow an authenticated user to potentially enable escalation of EPSS 0.6%CVE-2025-5985MEDIUMcode-projects School Fees Payment System improper authenticationEPSS 0.6%CVE-2025-4144MEDIUMPKCE bypass via downgrade attackEPSS 0.5%CVE-2022-3674HIGHSourceCodester Sanitization Management System missing authenticationEPSS 0.5%CVE-2023-36724MEDIUMWindows Power Management Service Information Disclosure VulnerabilityEPSS 0.5%CVE-2025-63210CRITICALThe Newtec Celox UHD (models: CELOXA504, CELOXA820) running firmware version celox-21.6.13 is vulnerable to an authentication bypass. An attEPSS 0.5%CVE-2020-16222—Philips Patient Monitoring Devices Improper AuthenticationEPSS 0.5%CVE-2024-36402MEDIUMUnauthenticated writes to the media repository allow planting of problematic content in Matrix Media RepoEPSS 0.5%CVE-2024-43240CRITICALWordPress Indeed Ultimate Membership Pro plugin <= 12.7 - Unauthenticated Privilege Escalation vulnerabilityEPSS 0.5%CVE-2026-60367CRITICALVulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). SupporEPSS 0.5%CVE-2025-9100MEDIUMzhenfeng13 My-Blog Frontend Blog Article Comment comment authentication replayEPSS 0.5%CVE-2023-37268MEDIUMUser login confusion with SSO in warpgateEPSS 0.5%CVE-2024-21543MEDIUMVersions of the package djoser before 2.3.0 are vulnerable to Authentication Bypass when the authenticate() function fails. This is because EPSS 0.5%CVE-2025-9965CRITICALUDP Service Weak AuthenticationEPSS 0.5%CVE-2025-11661MEDIUMProjectsAndPrograms School Management System missing authenticationEPSS 0.5%CVE-2023-44039CRITICALIn VeridiumID before 3.5.0, the WebAuthn API allows an internal unauthenticated attacker (who can pass enrollment verifications and is allowEPSS 0.5%CVE-2023-23857CRITICALImproper Access Control in SAP NetWeaver AS for JavaEPSS 0.5%CVE-2022-26508MEDIUMImproper authentication in the Intel(R) SDP Tool before version 3.0.0 may allow an unauthenticated user to potentially enable information diEPSS 0.5%