Fallos del tipo CWE-287

2432 resultados

Autenticação inadequada ou ausente

A aplicação não valida ou valida de forma insuficiente a identidade de quem tenta acessá-la. Quando um usuário diz ser quem é, o sistema acredita sem verificar corretamente, permitindo que atacantes se façam passar por outros usuários ou contas legítimas.

Ejemplo

Um sistema que aceita login apenas com nome de usuário, sem senha. Ou uma API que confia no header 'User-ID' enviado pelo cliente sem validar se aquele usuário realmente existe ou tem sessão ativa. Um atacante simplesmente altera o header e acessa dados de outra conta.

Cómo mitigar

Implemente autenticação robusta: exija múltiplos fatores (senha forte + MFA), valide credenciais contra base de dados segura, use sessões com token assinado e com expiração, nunca confie em dados enviados pelo cliente como prova de identidade. Revise regularmente logs de acesso para detectar abusos.

CVE-2026-54547HIGHMeta Ads MCP: X-Pipeboard-Token Header Auth Bypass Reuses Operator Meta TokenEPSS 0.5%CVE-2026-61436HIGHPraisonAI before 4.6.78 Missing Webhook Signature VerificationEPSS 0.5%CVE-2025-64055CRITICALAn issue was discovered in Fanvil x210 V2 2.12.20 allowing unauthenticated attackers on the local network to access administrative functionsEPSS 0.5%CVE-2026-50338HIGHAzure Spring Apps Elevation of Privilege VulnerabilityEPSS 0.5%CVE-2026-56237CRITICALCapgo - Unauthenticated API Key Generation via Client-Side Parameter ManipulationEPSS 0.5%CVE-2024-10620MEDIUMknightliao Disconf Configuration Center list improper authenticationEPSS 0.5%CVE-2024-38523HIGHHush Line OTP issueEPSS 0.5%CVE-2023-1980MEDIUMTwo factor authentication bypass on login in Devolutions Remote Desktop Manager 2022.3.35 and earlier allow user to cancel the two factorEPSS 0.5%CVE-2026-15372HIGHWP 2FA < 4.1.0 - Two-Factor Authentication Bypass via Passkeys ProviderEPSS 0.5%CVE-2024-11917HIGHJobSearch WP Job Board <= 2.9.2 - Authentication Bypass via Social LoginsEPSS 0.5%CVE-2024-36444HIGHcgi-bin/fdmcgiwebv2.cgi on Swissphone DiCal-RED 4009 devices allows an unauthenticated attacker to gain access to device logs.EPSS 0.5%CVE-2026-14557CRITICALSoftMarket <= 1.0.0 - Unauthenticated Account Takeover via Email Verification BypassEPSS 0.5%CVE-2021-32738MEDIUMUtils.readChallengeTx does not verify the server account signatureEPSS 0.5%CVE-2024-41929HIGHImproper authentication vulnerability in multiple digital video recorders provided by TAKENAKA ENGINEERING CO., LTD. allows a remote authentEPSS 0.5%CVE-2024-11293HIGHRegistration Forms – User Registration Forms, Invitation-Based Registrations, Front-end User Profile, Login Form & Content Restriction Social Sites Login <= 1.7.9 - Authentication Bypass via WordPress.com OAuth providerEPSS 0.5%CVE-2025-15581MEDIUMOrthanc versions before 1.12.10 are affected by an authorisation logic flaw in the application's HTTP Basic Authentication implementation. EPSS 0.5%CVE-2025-23116CRITICALAn Authentication Bypass vulnerability on UniFi Protect Application with Auto-Adopt Bridge Devices enabled could allow a malicious actor witEPSS 0.5%CVE-2022-39231LOWParse Server subject to Improper Authentication allowing Auth adapter app ID validation to be circumventedEPSS 0.5%CVE-2026-87806CRITICALParse Server 9.0.0 Authentication Bypass via LDAP Empty PasswordEPSS 0.5%CVE-2023-32081MEDIUMVert.x STOMP server process client frames that would not send initially a connect frameEPSS 0.5%