Fallos del tipo CWE-287

2431 resultados

Autenticação inadequada ou ausente

A aplicação não valida ou valida de forma insuficiente a identidade de quem tenta acessá-la. Quando um usuário diz ser quem é, o sistema acredita sem verificar corretamente, permitindo que atacantes se façam passar por outros usuários ou contas legítimas.

Ejemplo

Um sistema que aceita login apenas com nome de usuário, sem senha. Ou uma API que confia no header 'User-ID' enviado pelo cliente sem validar se aquele usuário realmente existe ou tem sessão ativa. Um atacante simplesmente altera o header e acessa dados de outra conta.

Cómo mitigar

Implemente autenticação robusta: exija múltiplos fatores (senha forte + MFA), valide credenciais contra base de dados segura, use sessões com token assinado e com expiração, nunca confie em dados enviados pelo cliente como prova de identidade. Revise regularmente logs de acesso para detectar abusos.

CVE-2024-47761HIGHGLPI vulnerable to account takeover via the password reset featureEPSS 0.5%CVE-2024-10020HIGHHeateor Social Login WordPress <= 1.1.35 - Authentication Bypass via Disqus OAuth providerEPSS 0.5%CVE-2026-6456HIGHAccount Switcher <= 1.0.2 - Authenticated (Subscriber+) Authentication Bypass to Privilege EscalationEPSS 0.5%CVE-2024-50640CRITICALjeewx-boot 1.3 has an authentication bypass vulnerability in the preHandle functionEPSS 0.5%CVE-2023-25790MEDIUMWordPress WoodMart theme <= 7.0.4 - Unauth Arbitrary Shortcodes InjectionEPSS 0.5%CVE-2022-39360MEDIUMMetabase SSO users able to circumvent IdP login by doing password resetEPSS 0.5%CVE-2026-44986CRITICALPenpot: Pre-authenticated account takeover via team-invitation token + prepare-register-profileEPSS 0.5%CVE-2026-4101HIGHSecurity Vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify AccessEPSS 0.5%CVE-2023-38735MEDIUMIBM Cognos Dashboards improper authenticationEPSS 0.5%CVE-2026-73241HIGHFreeRDP: RDSTLS server authentication bypass: a credential-less Capabilities PDU is accepted at the auth step (fail-open `resultCode`)EPSS 0.5%CVE-2022-39252HIGHWhen matrix-rust-sdk recieves forwarded room keys, the reciever doesn't check if it requested the key from the forwarderEPSS 0.5%CVE-2026-42210MEDIUMWebmin 2FA requirement bypassEPSS 0.5%CVE-2023-45669MEDIUMImproper signature counter value handling in webauthn4j-spring-security EPSS 0.5%CVE-2023-25559HIGHSystem account impersonation in DataHubEPSS 0.5%CVE-2024-23637MEDIUMOctoPrint Unverified Password Change via Access Control SettingsEPSS 0.5%CVE-2026-3739MEDIUMsuitenumerique messages ThreadAccess serializers.py ThreadAccessSerializer improper authenticationEPSS 0.5%CVE-2023-41089HIGHImproper Authentication in DEXMA DEXGateEPSS 0.5%CVE-2026-61436HIGHPraisonAI before 4.6.78 Missing Webhook Signature VerificationEPSS 0.5%CVE-2024-34399CRITICAL**UNSUPPORTED WHEN ASSIGNED** An issue was discovered in BMC Remedy Mid Tier 7.6.04. An unauthenticated remote attacker is able to access anEPSS 0.5%CVE-2025-64055CRITICALAn issue was discovered in Fanvil x210 V2 2.12.20 allowing unauthenticated attackers on the local network to access administrative functionsEPSS 0.5%