Fallos del tipo CWE-287

2431 resultados

Autenticação inadequada ou ausente

A aplicação não valida ou valida de forma insuficiente a identidade de quem tenta acessá-la. Quando um usuário diz ser quem é, o sistema acredita sem verificar corretamente, permitindo que atacantes se façam passar por outros usuários ou contas legítimas.

Ejemplo

Um sistema que aceita login apenas com nome de usuário, sem senha. Ou uma API que confia no header 'User-ID' enviado pelo cliente sem validar se aquele usuário realmente existe ou tem sessão ativa. Um atacante simplesmente altera o header e acessa dados de outra conta.

Cómo mitigar

Implemente autenticação robusta: exija múltiplos fatores (senha forte + MFA), valide credenciais contra base de dados segura, use sessões com token assinado e com expiração, nunca confie em dados enviados pelo cliente como prova de identidade. Revise regularmente logs de acesso para detectar abusos.

CVE-2023-4242MEDIUMFULL - Customer <= 2.2.3 - Authenticated(Subscriber+) Information Disclosure via Health CheckEPSS 0.5%CVE-2022-46172MEDIUMauthentik allows existing authenticated users to create arbitrary accountsEPSS 0.5%CVE-2026-82107CRITICALDataStage on Cloud Pak for Data has several vulnerabilities due to open source softwareEPSS 0.5%CVE-2026-31377HIGHApache Doris: Improper Authentication Allows Unauthorized Access to FE Meta ServiceEPSS 0.5%CVE-2024-52518MEDIUMNextcloud Server is missing password confirmation when changing external storage optionsEPSS 0.5%CVE-2026-9371MEDIUMItzCrazyKns Vane API route.ts missing authenticationEPSS 0.5%CVE-2025-47275CRITICALBrute Force Authentication Tags of CookieStore Sessions in Auth0-PHP SDKEPSS 0.5%CVE-2026-4349MEDIUMDuende IdentityServer4 Token Renewal Endpoint authorize improper authenticationEPSS 0.5%CVE-2026-58423HIGHLFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositoriesEPSS 0.5%CVE-2022-36071HIGHRecovery codes abuse in SFTPGoEPSS 0.5%CVE-2021-4197—An unprivileged write to the file handler flaw in the Linux kernel's control groups and namespaces subsystem was found in the way users haveEPSS 0.5%CVE-2026-22236CRITICALImproper Authentication Vulnerability in BLUVOYIXEPSS 0.5%CVE-2026-2249CRITICALUnauthenticated Remote Command Execution via Web Console in METIS DFSEPSS 0.5%CVE-2026-2248CRITICALUnauthenticated Remote Root Shell Access via Web Console in METIS WICEPSS 0.5%CVE-2026-59151CRITICALProwler: SAML Domain Claiming Enables Cross-Tenant Account TakeoverEPSS 0.5%CVE-2024-9947HIGHProfilePress - Pro <= 4.11.1 - Authentication Bypass via WordPress.com OAuth providerEPSS 0.5%CVE-2025-32879HIGHAn issue was discovered on COROS PACE 3 devices through 3.0808.0. It starts advertising if no device is connected via Bluetooth. This allowsEPSS 0.5%CVE-2026-56793HIGHDell OpenManage Server Administrator, versions prior to 11.1.0.2, contains an Improper Authentication vulnerability. An unauthenticated attaEPSS 0.5%CVE-2022-23540MEDIUMjsonwebtoken vulnerable to signature validation bypass due to insecure default algorithm in jwt.verify()EPSS 0.5%CVE-2026-9373MEDIUMJeecgBoot OpenAPI Endpoint call improper authenticationEPSS 0.5%