Fallos del tipo CWE-287

2430 resultados

Autenticação inadequada ou ausente

A aplicação não valida ou valida de forma insuficiente a identidade de quem tenta acessá-la. Quando um usuário diz ser quem é, o sistema acredita sem verificar corretamente, permitindo que atacantes se façam passar por outros usuários ou contas legítimas.

Ejemplo

Um sistema que aceita login apenas com nome de usuário, sem senha. Ou uma API que confia no header 'User-ID' enviado pelo cliente sem validar se aquele usuário realmente existe ou tem sessão ativa. Um atacante simplesmente altera o header e acessa dados de outra conta.

Cómo mitigar

Implemente autenticação robusta: exija múltiplos fatores (senha forte + MFA), valide credenciais contra base de dados segura, use sessões com token assinado e com expiração, nunca confie em dados enviados pelo cliente como prova de identidade. Revise regularmente logs de acesso para detectar abusos.

CVE-2024-25652HIGHIn Delinea PAM Secret Server 11.4, it is possible for a user assigned "Administer Reports" permission and/or with access to Report functionaEPSS 0.6%CVE-2021-25505LOWImproper authentication in Samsung Pass prior to 3.0.02.4 allows to use app without authentication when lockscreen is unlocked.EPSS 0.6%CVE-2020-8236—A wrong configuration in Nextcloud Server 19.0.1 incorrectly made the user feel the passwordless WebAuthn is also a two factor verification EPSS 0.6%CVE-2026-73501CRITICALkin-openapi: ValidationHandler.Load() Fail-Open Authentication Bypass via NoopAuthenticationFunc DefaultEPSS 0.6%CVE-2025-15097MEDIUMAlteryx Server status improper authenticationEPSS 0.6%CVE-2022-24740MEDIUMImproper Authentication in VoltoEPSS 0.6%CVE-2026-48039CRITICALMeta Ads MCP: Unauthenticated HTTP MCP Tool Execution Leaks Operator Meta Access TokenEPSS 0.6%CVE-2026-63472CRITICALVendure: External-authentication account takeover: external login linked to a pre-existing account by email without verificationEPSS 0.6%CVE-2024-23813HIGHA vulnerability has been identified in Polarion ALM (All versions < V2404.0). The REST API endpoints of doorsconnector of the affected produEPSS 0.6%CVE-2024-44127MEDIUMThis issue was addressed through improved state management. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18. Private BEPSS 0.6%CVE-2023-39345HIGHUnauthorized Access to Private Fields in User Registration API in strapiEPSS 0.6%CVE-2025-27414MEDIUMMinIO SFTP authentication bypass due to improperly trusted SSH keyEPSS 0.6%CVE-2026-13543MEDIUMDocumenso Google OAuth Login handle-oauth-callback-url.ts improper authenticationEPSS 0.6%CVE-2026-19974MEDIUMtreefrogframework treefrog-framework Session Cookie tsessioncookiestore.cpp strncmp improper authenticationEPSS 0.6%CVE-2026-24241MEDIUMNVIDIA Delegated Licensing Service for all appliance platforms contains a vulnerability where an attacker could exploit an improper authentiEPSS 0.6%CVE-2024-48859MEDIUMQTS, QuTS heroEPSS 0.6%CVE-2026-15341CRITICALUser Session Synchronizer <= 1.4.0 - Unauthenticated Authentication Bypass to Account Takeover via 'ussync-key', 'ussync-token', and 'ussync-ref' ParametersEPSS 0.6%CVE-2026-7113MEDIUMNousResearch hermes-agent Webhooks Endpoint webhook.py missing authenticationEPSS 0.6%CVE-2024-45369CRITICALmySCADA myPRO Improper AuthenticationEPSS 0.6%CVE-2022-46411HIGHAn issue was discovered in Veritas NetBackup Flex Scale through 3.0 and Access Appliance through 8.0.100. A default password is persisted afEPSS 0.6%