Fallos del tipo CWE-287

2430 resultados

Autenticação inadequada ou ausente

A aplicação não valida ou valida de forma insuficiente a identidade de quem tenta acessá-la. Quando um usuário diz ser quem é, o sistema acredita sem verificar corretamente, permitindo que atacantes se façam passar por outros usuários ou contas legítimas.

Ejemplo

Um sistema que aceita login apenas com nome de usuário, sem senha. Ou uma API que confia no header 'User-ID' enviado pelo cliente sem validar se aquele usuário realmente existe ou tem sessão ativa. Um atacante simplesmente altera o header e acessa dados de outra conta.

Cómo mitigar

Implemente autenticação robusta: exija múltiplos fatores (senha forte + MFA), valide credenciais contra base de dados segura, use sessões com token assinado e com expiração, nunca confie em dados enviados pelo cliente como prova de identidade. Revise regularmente logs de acesso para detectar abusos.

CVE-2022-29237MEDIUMLimited Authentication Bypass for Media Files in OpencastEPSS 0.6%CVE-2026-31387MEDIUMApache OFBiz: Cookie Manipulation Allows Authenticated JWT Forgery and Account ImpersonationEPSS 0.6%CVE-2026-87016HIGHOpen WebUI: Sign-in as another user via wildcard characters in the OAuth subject claim on SQLiteEPSS 0.6%CVE-2024-24771HIGHOpen Forms potential multi-factor authentication bypassEPSS 0.6%CVE-2026-16857HIGHVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.6%CVE-2026-53761HIGHFrappe CRM: Authentication Bypass via Logged Invitation Keys in crm/apiEPSS 0.6%CVE-2025-22228HIGHCVE-2025-22228: Spring Security BCryptPasswordEncoder does not enforce maximum password lengthEPSS 0.6%CVE-2022-39254HIGHWhen matrix-nio receives forwarded room keys, the receiver doesn't check if it requested the key from the forwarderEPSS 0.6%CVE-2026-41145HIGHMinIO has an Unauthenticated Object Write via Query-String Credential Signature Bypass in Unsigned-Trailer UploadsEPSS 0.6%CVE-2024-0002CRITICALA condition exists in FlashArray Purity whereby an attacker can employ a privileged account allowing remote access to the array.EPSS 0.6%CVE-2025-60772CRITICALImproper authentication in the web-based management interface of NETLINK HG322G V1.0.00-231017, allows a remote unauthenticated attacker to EPSS 0.6%CVE-2026-10697HIGHMFA Bypass in MOVEit TransferEPSS 0.6%CVE-2024-2450HIGHMattermost versions 8.1.x before 8.1.10, 9.2.x before 9.2.6, 9.3.x before 9.3.2, and 9.4.x before 9.4.3 fail to correctly verify account ownEPSS 0.6%CVE-2024-37893MEDIUMMFA bypass in oauth flow in Firefly IIIEPSS 0.6%CVE-2019-1758MEDIUMCisco IOS Software Catalyst 6500 Series 802.1x Authentication Bypass VulnerabilityEPSS 0.6%CVE-2025-5149MEDIUMWCMS Login getallcon getMemberByUid improper authenticationEPSS 0.6%CVE-2026-2165MEDIUMdetronetdip E-commerce Account Creation Endpoint add_seller.php missing authenticationEPSS 0.6%CVE-2025-30215CRITICALNATS-Server Fails to Authorize Certain Jetstream Admin APIsEPSS 0.6%CVE-2024-45404HIGHOpenCTI's lack of Rate Limit lead to OTP brute forcingEPSS 0.6%CVE-2024-25652HIGHIn Delinea PAM Secret Server 11.4, it is possible for a user assigned "Administer Reports" permission and/or with access to Report functionaEPSS 0.6%