Fallos del tipo CWE-287

2431 resultados

Autenticação inadequada ou ausente

A aplicação não valida ou valida de forma insuficiente a identidade de quem tenta acessá-la. Quando um usuário diz ser quem é, o sistema acredita sem verificar corretamente, permitindo que atacantes se façam passar por outros usuários ou contas legítimas.

Ejemplo

Um sistema que aceita login apenas com nome de usuário, sem senha. Ou uma API que confia no header 'User-ID' enviado pelo cliente sem validar se aquele usuário realmente existe ou tem sessão ativa. Um atacante simplesmente altera o header e acessa dados de outra conta.

Cómo mitigar

Implemente autenticação robusta: exija múltiplos fatores (senha forte + MFA), valide credenciais contra base de dados segura, use sessões com token assinado e com expiração, nunca confie em dados enviados pelo cliente como prova de identidade. Revise regularmente logs de acesso para detectar abusos.

CVE-2026-14291HIGHSecurity Ninja (Premium) < 5.290 - Two-Factor Authentication Bypass via secnin_skip_2faEPSS 0.5%CVE-2025-8838MEDIUMWinterChenS my-site Backend admin preHandle improper authenticationEPSS 0.5%CVE-2024-57432HIGHmacrozheng mall-tiny 1.0.1 suffers from Insecure Permissions. The application's JWT signing keys are hardcoded and do not change. User inforEPSS 0.5%CVE-2025-6979HIGHCaptive Portal can allow authentication bypassEPSS 0.5%CVE-2025-6172CRITICALPermission vulnerability in the mobile application (com.afmobi.boomplayer) may lead to the risk of unauthorized operation.EPSS 0.5%CVE-2026-36727CRITICALAn insecure authentication vulnerability in the /api/social-sign-in endpoint of bookcars v8.3 allows attackers to bypass authentication via EPSS 0.5%CVE-2026-44196CRITICALPingvin Share X: TOTP Authentication Bypass via Password-only LoginEPSS 0.5%CVE-2025-8348MEDIUMKehua Charging Pile Cloud Platform home improper authenticationEPSS 0.5%CVE-2025-56752CRITICALA vulnerability in the Ruijie RG-ES series switch firmware ESW_1.0(1)B1P39 enables remote attackers to fully bypass authentication mechanismEPSS 0.5%CVE-2026-32815MEDIUMSiYuan: Cross-Origin WebSocket Hijacking via Authentication Bypass — Unauthenticated Information DisclosureEPSS 0.5%CVE-2020-5224MEDIUMSession key exposure through session list in Django User SessionsEPSS 0.5%CVE-2024-11671MEDIUMImproper authentication in SQL data source MFA validation in Devolutions Remote Desktop Manager 2024.3.17 and earlier on Windows allows an aEPSS 0.5%CVE-2026-49872MEDIUMApache APISIX: Improper authentication in cas-auth pluginEPSS 0.5%CVE-2026-68569HIGHApache Tomcat: Principal lookup can fail open in some casesEPSS 0.5%CVE-2026-61641HIGHWallos: OIDC account takeover via email-based account linking without `email_verified` checkEPSS 0.5%CVE-2025-9994CRITICALAmp’ed RF BT-AP 111 Bluetooth access point's HTTP admin interface does not require authenticationEPSS 0.5%CVE-2026-49197CRITICALPredator Connect W6x: Improper AuthenticationEPSS 0.5%CVE-2026-49191CRITICALExposed Hard-coded M3WebServer Backend API KeyEPSS 0.5%CVE-2026-17175HIGHIBM Db2 Mirror for i is affected by multiple vulnerabilitiesEPSS 0.5%CVE-2025-41023MEDIUMAuthentication bypass in AutoGPT de ThesamurEPSS 0.5%