Fallos del tipo CWE-287

2431 resultados

Autenticação inadequada ou ausente

A aplicação não valida ou valida de forma insuficiente a identidade de quem tenta acessá-la. Quando um usuário diz ser quem é, o sistema acredita sem verificar corretamente, permitindo que atacantes se façam passar por outros usuários ou contas legítimas.

Ejemplo

Um sistema que aceita login apenas com nome de usuário, sem senha. Ou uma API que confia no header 'User-ID' enviado pelo cliente sem validar se aquele usuário realmente existe ou tem sessão ativa. Um atacante simplesmente altera o header e acessa dados de outra conta.

Cómo mitigar

Implemente autenticação robusta: exija múltiplos fatores (senha forte + MFA), valide credenciais contra base de dados segura, use sessões com token assinado e com expiração, nunca confie em dados enviados pelo cliente como prova de identidade. Revise regularmente logs de acesso para detectar abusos.

CVE-2025-52395CRITICALAn issue in Roadcute API v.1 allows a remote attacker to execute arbitrary code via the application exposing a password reset API endpoint tEPSS 0.6%CVE-2026-18922CRITICAL389-ds-base: 389-ds-base: sasl plain authentication allows privilege escalation to directory manager via stale identity in cyrus sasl auxiliary propertyEPSS 0.6%CVE-2021-25368LOWHijacking vulnerability in Samsung Cloud prior to version 4.7.0.3 allows attackers to intercept when the provider is executed.EPSS 0.6%CVE-2026-33432HIGHRoxy-WI has Pre-Authentication LDAP Injection that Leads to Authentication BypassEPSS 0.6%CVE-2023-48703HIGHSAML authentication bypass vulnerability in RobotsAndPencils/go-samlEPSS 0.6%CVE-2024-12919CRITICALPaid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction <= 2.13.7 - Authentication Bypass via pms_payment_idEPSS 0.6%CVE-2026-12598HIGHLoginPress Pro <= 6.2.3 - Unauthenticated Authentication Bypass via Unverified OAuth Email in Spotify OAuth CallbackEPSS 0.6%CVE-2026-12595HIGHLoginPress Pro <= 6.2.3 - Unauthenticated Authentication Bypass via Unverified OAuth Email via Discord OAuth CallbackEPSS 0.6%CVE-2025-49812HIGHApache HTTP Server: mod_ssl TLS upgrade attackEPSS 0.6%CVE-2026-20317CRITICALCisco Secure Workload Software Security Hardening Release August 2026 - Improper Authentication VulnerabilitiesEPSS 0.6%CVE-2023-48865MEDIUMAn issue discovered in Reportico Till 8.1.0 allows attackers to obtain sensitive information via execute_mode parameter of the URL.EPSS 0.6%CVE-2026-72533HIGHPortainer Portainer CE - Authentication BypassEPSS 0.6%CVE-2026-33409HIGHParse Server: Auth provider validation bypass on login via partial authDataEPSS 0.6%CVE-2022-37774MEDIUMThere is a broken access control vulnerability in the Maarch RM 2.8.3 solution. When accessing some specific document (pdf, email) from an aEPSS 0.6%CVE-2026-24898CRITICALOpenEMR has an Unauthenticated MedEx Token DisclosureEPSS 0.6%CVE-2026-47426HIGHOpenAM OAuth Client Impersonation via JWKS Resolver CacheEPSS 0.6%CVE-2026-4592MEDIUMkalcaddle kodbox Password Login index.class.php tfaVerify improper authenticationEPSS 0.6%CVE-2026-45156HIGHNextcloud: Authentication Bypass in ID4me handling via Missing JWT Signature Verification in User OIDCEPSS 0.6%CVE-2024-56329HIGHAccount Takeover Vulnerability in Social Account Linking in joelbutcher/socialstreamEPSS 0.6%CVE-2026-14627MEDIUMNousResearch hermes-agent Discord Platform Integration discord.py DiscordAdapter._is_allowed_user improper authenticationEPSS 0.6%