Fallos del tipo CWE-287

2430 resultados

Autenticação inadequada ou ausente

A aplicação não valida ou valida de forma insuficiente a identidade de quem tenta acessá-la. Quando um usuário diz ser quem é, o sistema acredita sem verificar corretamente, permitindo que atacantes se façam passar por outros usuários ou contas legítimas.

Ejemplo

Um sistema que aceita login apenas com nome de usuário, sem senha. Ou uma API que confia no header 'User-ID' enviado pelo cliente sem validar se aquele usuário realmente existe ou tem sessão ativa. Um atacante simplesmente altera o header e acessa dados de outra conta.

Cómo mitigar

Implemente autenticação robusta: exija múltiplos fatores (senha forte + MFA), valide credenciais contra base de dados segura, use sessões com token assinado e com expiração, nunca confie em dados enviados pelo cliente como prova de identidade. Revise regularmente logs de acesso para detectar abusos.

CVE-2026-2174MEDIUMcode-projects Contact Management System CRUD Endpoint improper authenticationEPSS 0.6%CVE-2022-46411HIGHAn issue was discovered in Veritas NetBackup Flex Scale through 3.0 and Access Appliance through 8.0.100. A default password is persisted afEPSS 0.6%CVE-2026-54600HIGHWallos: Unauthenticated database replacement via import endpoint on fresh installEPSS 0.6%CVE-2022-40616MEDIUMIBM Maximo Asset Management 7.6.1.1, 7.6.1.2, and 7.6.1.3 could allow a user to bypass authentication and obtain sensitive information or peEPSS 0.6%CVE-2025-11852MEDIUMApeman ID71 ONVIF Service device_service missing authenticationEPSS 0.6%CVE-2026-77194MEDIUMSimple Membership <= 4.8.1 - Unauthenticated Authentication Bypass to Administrator Account Takeover via Multisite Identity BindingEPSS 0.6%CVE-2024-47218CRITICALAn issue was discovered in vesoft NebulaGraph through 3.8.0. It allows bypassing authentication.EPSS 0.6%CVE-2025-15458MEDIUMbg5sbk MiniCMS Article post-edit.php improper authenticationEPSS 0.6%CVE-2023-42818MEDIUMSSH public key login without private key challenge if mfa is enabled in jumpserverEPSS 0.6%CVE-2026-65633HIGHPurpose-limited JWT accepted as full bearer authentication in AshAuthenticationEPSS 0.6%CVE-2024-37019CRITICALNorthern.tech Mender Enterprise before 3.6.4 and 3.7.x before 3.7.4 has Weak Authentication.EPSS 0.6%CVE-2026-25804HIGHAntrea has invalid enforcement order for network policy rules caused by integer overflowEPSS 0.6%CVE-2025-15457MEDIUMbg5sbk MiniCMS Trash File Restore post.php improper authenticationEPSS 0.6%CVE-2022-30124MEDIUMAn improper authentication vulnerability exists in Rocket.Chat Mobile App <4.14.1.22788 that allowed an attacker with physical access to a mEPSS 0.6%CVE-2026-15348MEDIUMPremium Packages <= 7.0.4 - Authentication Bypass to Non-Admin via 'wpdmppdl' ParameterEPSS 0.6%CVE-2026-78885MEDIUMliketrek TREK OIDC Service oidcService.ts findOrCreateUser improper authenticationEPSS 0.6%CVE-2026-7112MEDIUMNousResearch hermes-agent API_SERVER_KEY api_server.py _check_auth improper authenticationEPSS 0.6%CVE-2024-12287CRITICALBiagiotti Membership <= 1.0.2 - Authentication Bypass via biagiotti_membership_check_facebook_userEPSS 0.6%CVE-2026-16015MEDIUMpoco-ai poco-claw executor_manager API tasks.py create_task missing authenticationEPSS 0.6%CVE-2026-42560CRITICALauth: Patreon provider assigns the same local user ID to every authenticated Patreon account, enabling cross‑user impersonationEPSS 0.6%