Fallos del tipo CWE-287

2430 resultados

Autenticação inadequada ou ausente

A aplicação não valida ou valida de forma insuficiente a identidade de quem tenta acessá-la. Quando um usuário diz ser quem é, o sistema acredita sem verificar corretamente, permitindo que atacantes se façam passar por outros usuários ou contas legítimas.

Ejemplo

Um sistema que aceita login apenas com nome de usuário, sem senha. Ou uma API que confia no header 'User-ID' enviado pelo cliente sem validar se aquele usuário realmente existe ou tem sessão ativa. Um atacante simplesmente altera o header e acessa dados de outra conta.

Cómo mitigar

Implemente autenticação robusta: exija múltiplos fatores (senha forte + MFA), valide credenciais contra base de dados segura, use sessões com token assinado e com expiração, nunca confie em dados enviados pelo cliente como prova de identidade. Revise regularmente logs de acesso para detectar abusos.

CVE-2023-51717CRITICALDataiku DSS before 11.4.5 and 12.4.1 has Incorrect Access Control that could lead to a full authentication bypass.EPSS 0.6%CVE-2025-24894CRITICALSAML Response Signature Verification Bypass in SPID.AspNetCore.AuthenticationEPSS 0.6%CVE-2025-24895CRITICALSAML Response Signature Verification Bypass in CIE.AspNetCore.AuthenticationEPSS 0.6%CVE-2023-22650HIGHRancher does not automatically clean up a user deleted or disabled from the configured Authentication ProviderEPSS 0.6%CVE-2019-15617—A missing check in Nextcloud Server 17.0.0 allowed an attacker to set up a new second factor when trying to login.EPSS 0.6%CVE-2025-9064HIGHRockwell Automation FactoryTalk View Machine Edition Path TraversalEPSS 0.6%CVE-2025-22146CRITICALImproper authentication on SAML SSO process allows user impersonation in sentryEPSS 0.6%CVE-2026-9695CRITICALImproper Authentication vulnerability affecting DELMIA Apriso from Release 2020 through Release 2026EPSS 0.6%CVE-2026-76673CRITICALAuthentication Bypass Vulnerabilities in API of EdgeConnect SD-WAN OrchestratorEPSS 0.6%CVE-2026-33322CRITICALMinIO: JWT Algorithm Confusion in OIDC AuthenticationEPSS 0.6%CVE-2026-30831HIGHRocket.Chat: 2FA bypass and login of deactivated users via EE ddp-streamerEPSS 0.6%CVE-2025-5906MEDIUMcode-projects Laundry System data missing authenticationEPSS 0.6%CVE-2026-92792HIGHOpenNHP through 1.0.2 Authentication Bypass via Fallback VerifierEPSS 0.6%CVE-2023-3597MEDIUMKeycloak: secondary factor bypass in step-up authenticationEPSS 0.6%CVE-2022-26845HIGHImproper authentication in firmware for Intel(R) AMT before versions 11.8.93, 11.22.93, 11.12.93, 12.0.92, 14.1.67, 15.0.42, 16.1.25 may allEPSS 0.6%CVE-2024-45113HIGHColdFusion | Improper Authentication (CWE-287)EPSS 0.6%CVE-2026-34500MEDIUMApache Tomcat: OCSP checks sometimes soft-fail with FFM even when soft-fail is disabledEPSS 0.6%CVE-2020-22657CRITICALIn Ruckus R310 10.5.1.0.199, Ruckus R500 10.5.1.0.199, Ruckus R600 10.5.1.0.199, Ruckus T300 10.5.1.0.199, Ruckus T301n 10.5.1.0.199, RuckusEPSS 0.6%CVE-2022-4041MEDIUMPrivilege Escalation Vulnerability in Hitachi Storage Plug-in for VMware vCenterEPSS 0.6%CVE-2026-88007CRITICALTraefik HTTP/3 Backend NTLM Connection ReuseEPSS 0.6%