Fallos del tipo CWE-287

2431 resultados

Autenticação inadequada ou ausente

A aplicação não valida ou valida de forma insuficiente a identidade de quem tenta acessá-la. Quando um usuário diz ser quem é, o sistema acredita sem verificar corretamente, permitindo que atacantes se façam passar por outros usuários ou contas legítimas.

Ejemplo

Um sistema que aceita login apenas com nome de usuário, sem senha. Ou uma API que confia no header 'User-ID' enviado pelo cliente sem validar se aquele usuário realmente existe ou tem sessão ativa. Um atacante simplesmente altera o header e acessa dados de outra conta.

Cómo mitigar

Implemente autenticação robusta: exija múltiplos fatores (senha forte + MFA), valide credenciais contra base de dados segura, use sessões com token assinado e com expiração, nunca confie em dados enviados pelo cliente como prova de identidade. Revise regularmente logs de acesso para detectar abusos.

CVE-2023-37226CRITICALLoftware Spectrum before 4.6 HF14 has Missing Authentication for a Critical Function.EPSS 0.6%CVE-2026-75774MEDIUMkarakeep-app karakeep OAuth Sign-In auth.ts improper authenticationEPSS 0.6%CVE-2018-8862—In ATI Systems Emergency Mass Notification Systems (HPSS16, HPSS32, MHPSS, and ALERT4000) devices, an improper authentication vulnerability EPSS 0.6%CVE-2026-41070CRITICALopenvpn-auth-oauth2 returns FUNC_SUCCESS on client-deny, allowing unauthenticated VPN accessEPSS 0.6%CVE-2026-93960MEDIUMPixelfed OAuth Scope ApiV1Controller.php instancePeers missing authenticationEPSS 0.6%CVE-2026-27197CRITICALSentry: Improper Authentication on SAML SSO process allows user identity linkingEPSS 0.6%CVE-2025-27138HIGHDataEase has an improper authentication vulnerabilityEPSS 0.6%CVE-2026-2065MEDIUMFlycatcher Toys smART Pixelator Bluetooth Low Energy missing authenticationEPSS 0.6%CVE-2026-52827HIGHKimai: Two-factor authentication bypass on the Kimai APIEPSS 0.6%CVE-2024-45106HIGHApache Ozone: Improper authentication when generating S3 secretsEPSS 0.6%CVE-2026-0589MEDIUMcode-projects Online Product Reservation System Administration Backend improper authenticationEPSS 0.6%CVE-2026-48087CRITICALOpenReception: WebAuthn passkey injection allows account takeoverEPSS 0.6%CVE-2026-82906MEDIUMsdcb chats Signed File Download Endpoint FileController.cs DownloadPublic missing authenticationEPSS 0.6%CVE-2023-48312CRITICALAuthentication bypass using an empty token in capsule-proxyEPSS 0.6%CVE-2026-59955HIGHApollo ConfigService access key authentication bypass via raw config file appId parsingEPSS 0.6%CVE-2026-33716CRITICALAVideo Allows Unauthenticated Live Stream Control via Token Verification URL Override in control.json.phpEPSS 0.6%CVE-2026-59954HIGHApollo ConfigService access key authentication bypass via appId parsing and non-canonical matchingEPSS 0.6%CVE-2022-0985—Insufficient capability checks could allow users with the moodle/site:uploadusers capability to delete users, without having the necessary mEPSS 0.6%CVE-2025-68717CRITICALKAYSUS KS-WR3600 routers with firmware 1.0.5.9.1 allow authentication bypass during session validation. If any user is logged in, endpoints EPSS 0.6%CVE-2024-7050HIGHImproper Authentication vulnerability in OpenText OpenText Directory Services may allow Multi-factor Authentication Bypass in particular sceEPSS 0.6%