Fallos del tipo CWE-287

2432 resultados

Autenticação inadequada ou ausente

A aplicação não valida ou valida de forma insuficiente a identidade de quem tenta acessá-la. Quando um usuário diz ser quem é, o sistema acredita sem verificar corretamente, permitindo que atacantes se façam passar por outros usuários ou contas legítimas.

Ejemplo

Um sistema que aceita login apenas com nome de usuário, sem senha. Ou uma API que confia no header 'User-ID' enviado pelo cliente sem validar se aquele usuário realmente existe ou tem sessão ativa. Um atacante simplesmente altera o header e acessa dados de outra conta.

Cómo mitigar

Implemente autenticação robusta: exija múltiplos fatores (senha forte + MFA), valide credenciais contra base de dados segura, use sessões com token assinado e com expiração, nunca confie em dados enviados pelo cliente como prova de identidade. Revise regularmente logs de acesso para detectar abusos.

CVE-2026-61131CRITICALVulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version EPSS 0.5%CVE-2026-71133CRITICALVulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that EPSS 0.5%CVE-2026-83094CRITICALVulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). Supported versions that aEPSS 0.5%CVE-2026-70913CRITICALVulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: Core). Supported versions that are affected arEPSS 0.5%CVE-2026-61233CRITICALVulnerability in the PeopleSoft Enterprise FIN Common Objects Brazil product of Oracle PeopleSoft (component: Integration). The supported EPSS 0.5%CVE-2025-67158HIGHAn authentication bypass in the /cgi-bin/jvsweb.cgi endpoint of Revotech I6032W-FHW v1.0.0014 - 20210517 allows attackers to access sensitivEPSS 0.5%CVE-2026-93532MEDIUMgedelumbung HospitalManagement Password Change password.php simpan improper authenticationEPSS 0.5%CVE-2026-78863MEDIUMliketrek TREK Pre-2FA mfa_token authService.ts loginUser improper authenticationEPSS 0.5%CVE-2026-19607MEDIUMKeycloak-services: keycloak-services: broker-originated username collision causes account lockoutEPSS 0.5%CVE-2026-1740MEDIUMEFM ipTIME A8004T Hidden Hiddenloginsetup timepro.cgi httpcon_check_session_url improper authenticationEPSS 0.5%CVE-2025-14002HIGHWPCOM Member <= 1.7.16 - Authentication Bypass via Weak OTPEPSS 0.5%CVE-2026-18216MEDIUMBackup Migration < 2.1.7 - Admin+ Privilege Escalation via Post-Restore Auto-LoginEPSS 0.5%CVE-2026-5557MEDIUMbadlogic pi-mono pi-mom Slack Bot slack.ts authentication bypassEPSS 0.5%CVE-2026-16076MEDIUMAstrBotDevs AstrBot API open_api.py OpenApiRoute.chat_send authentication spoofingEPSS 0.5%CVE-2024-45750HIGHAn issue in TheGreenBow Windows Standard VPN Client 6.87.108 (and older), Windows Enterprise VPN Client 6.87.109 (and older), Windows EnterpEPSS 0.5%CVE-2024-55954HIGHOpenObserve Improper Authorization Allows Admin User to Remove Root UserEPSS 0.5%CVE-2019-3825MEDIUMA vulnerability was discovered in gdm before 3.31.4. When timed login is enabled in configuration, an attacker could bypass the lock screen EPSS 0.5%CVE-2025-61922CRITICALPrestaShop Checkout allows customer account takeover via emailEPSS 0.5%CVE-2026-16686HIGHVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.5%CVE-2022-46773MEDIUMIBM Robotic Process Automation security bypassEPSS 0.5%