Fallos del tipo CWE-287

2431 resultados

Autenticação inadequada ou ausente

A aplicação não valida ou valida de forma insuficiente a identidade de quem tenta acessá-la. Quando um usuário diz ser quem é, o sistema acredita sem verificar corretamente, permitindo que atacantes se façam passar por outros usuários ou contas legítimas.

Ejemplo

Um sistema que aceita login apenas com nome de usuário, sem senha. Ou uma API que confia no header 'User-ID' enviado pelo cliente sem validar se aquele usuário realmente existe ou tem sessão ativa. Um atacante simplesmente altera o header e acessa dados de outra conta.

Cómo mitigar

Implemente autenticação robusta: exija múltiplos fatores (senha forte + MFA), valide credenciais contra base de dados segura, use sessões com token assinado e com expiração, nunca confie em dados enviados pelo cliente como prova de identidade. Revise regularmente logs de acesso para detectar abusos.

CVE-2026-4831MEDIUMkalcaddle kodbox Password-protected Share auth.class.php can improper authenticationEPSS 0.6%CVE-2022-27839LOWImproper authentication vulnerability in SecretMode in Samsung Internet prior to version 16.2.1 allows attackers to access bookmark tab withEPSS 0.6%CVE-2026-4664MEDIUMCustomer Reviews for WooCommerce <= 5.103.0 - Unauthenticated Authentication Bypass to Arbitrary Review Submission via 'key' ParameterEPSS 0.6%CVE-2024-27253CRITICALIBM Engineering Requirements Management DOORS Next is impacted by vulnerability in Reviews delete requestEPSS 0.6%CVE-2026-70482HIGHOpen WebUI: Account takeover via OAuth token exchange accepting tokens issued to any clientEPSS 0.6%CVE-2024-47070CRITICALauthentik vulnerable to password authentication bypass via X-Forwarded-For HTTP headerEPSS 0.6%CVE-2026-46389CRITICALUDS Identity Config has a client authentication bypass in `ClientIdAndKubernetesSecretAuthenticator`EPSS 0.6%CVE-2026-12597HIGHLoginPress Pro <= 6.2.3 - Unauthenticated Authentication Bypass via Unverified OAuth Email via GitHub OAuth CallbackEPSS 0.6%CVE-2024-41198CRITICALAn issue in Ocuco Innovation - REPORTS.EXE v2.10.24.13 allows attackers to bypass authentication and escalate privileges to Administrator viEPSS 0.6%CVE-2024-41197CRITICALAn issue in Ocuco Innovation - INVCLIENT.EXE v2.10.24.5 allows attackers to bypass authentication and escalate privileges to Administrator vEPSS 0.6%CVE-2024-41195CRITICALAn issue in Ocuco Innovation - INNOVASERVICEINTF.EXE v2.10.24.17 allows attackers to bypass authentication and escalate privileges to AdminiEPSS 0.6%CVE-2022-38982CRITICALThe fingerprint module has service logic errors.Successful exploitation of this vulnerability will cause the phone lock to be cracked.EPSS 0.6%CVE-2023-6155MEDIUMQuiz Maker < 6.4.9.5 - Unauthenticated Email Address DisclosureEPSS 0.6%CVE-2026-44476MEDIUMDoorkeeper OpenID Connect: Dynamic Client Registration feature creates public clients with client_secretEPSS 0.6%CVE-2026-89093MEDIUMBetter Messages <= 2.15.33 - Unauthenticated Information Exposure Spoofing via 'X-Real-IP' Header via /guests/registerEPSS 0.6%CVE-2023-51471HIGHWordPress Checkout Mestres WP plugin <= 7.1.9.7 - Unauthenticated Arbitrary Options Update vulnerabilityEPSS 0.6%CVE-2025-11287MEDIUMsamanhappy MCPHub sseService.ts handleSseConnectionfunction improper authenticationEPSS 0.6%CVE-2023-28962MEDIUMJunos OS: Unauthenticated access vulnerability in J-WebEPSS 0.6%CVE-2023-3127HIGHImproper Authentication in iSTAREPSS 0.6%CVE-2025-52395CRITICALAn issue in Roadcute API v.1 allows a remote attacker to execute arbitrary code via the application exposing a password reset API endpoint tEPSS 0.6%