Fallos del tipo CWE-287

2434 resultados

Autenticação inadequada ou ausente

A aplicação não valida ou valida de forma insuficiente a identidade de quem tenta acessá-la. Quando um usuário diz ser quem é, o sistema acredita sem verificar corretamente, permitindo que atacantes se façam passar por outros usuários ou contas legítimas.

Ejemplo

Um sistema que aceita login apenas com nome de usuário, sem senha. Ou uma API que confia no header 'User-ID' enviado pelo cliente sem validar se aquele usuário realmente existe ou tem sessão ativa. Um atacante simplesmente altera o header e acessa dados de outra conta.

Cómo mitigar

Implemente autenticação robusta: exija múltiplos fatores (senha forte + MFA), valide credenciais contra base de dados segura, use sessões com token assinado e com expiração, nunca confie em dados enviados pelo cliente como prova de identidade. Revise regularmente logs de acesso para detectar abusos.

CVE-2022-46773MEDIUMIBM Robotic Process Automation security bypassEPSS 0.5%CVE-2025-56333CRITICALAn issue in Fossorial fosrl/pangolin v.1.6.2 and before allows a remote attacker to escalate privileges via the 2FA componentEPSS 0.5%CVE-2018-25236CRITICALHirschmann HiOS HiSecOS Authentication Bypass via HTTP ManagementEPSS 0.5%CVE-2025-22375CRITICALAuthentication Bypass in CyberAudit-WebEPSS 0.5%CVE-2026-7876CRITICALAuthentication bypass vulnerability found in Aspera High-Speed Transfer Server for Cloud Pak for IntegrationEPSS 0.5%CVE-2026-62669HIGHGrav Login Plugin: 2FA Bypass via 'login.regenerate2FASecret' - Secret Rotation During Pending ChallengeEPSS 0.5%CVE-2026-56675HIGH9router: Reverse proxy locality collapse allows unauthenticated access to 9router /v1 APIsEPSS 0.5%CVE-2024-44202MEDIUMAn authentication issue was addressed with improved state management. This issue is fixed in Safari 18, iOS 18 and iPadOS 18. Private BrowsiEPSS 0.5%CVE-2026-55727HIGHA flaw in the authentication mechanism for video stream requests in Genetec Security Center 5.14.0.0 prior to build 5.14.178.18 may allow anEPSS 0.5%CVE-2025-3222CRITICALSmallworld SWMFS Improper AuthenticationEPSS 0.5%CVE-2026-59500CRITICALPriority - CWE-287: Improper AuthenticationEPSS 0.5%CVE-2026-16299CRITICALSingle Sign On For TNG < 2.2.0 - Unauthenticated Arbitrary Password ResetEPSS 0.5%CVE-2024-37367HIGHRockwell Automation FactoryTalk® View SE v12 Information Leakage Vulnerability via Authentication RestrictionEPSS 0.5%CVE-2026-86710CRITICALLogin with QR <= 1.0.0 - Unauthenticated Authentication Bypass via 'autologin_code' ParameterEPSS 0.5%CVE-2026-14182CRITICALCustomer Email Verification for WooCommerce < 3.2.6 - Unauthenticated Account Takeover via Type-Juggling Authentication BypassEPSS 0.5%CVE-2024-37368HIGHRockwell Automation FactoryTalk® View SE v11 Information Leakage Vulnerability via Authentication RestrictionEPSS 0.5%CVE-2026-77000CRITICALWP Social Media Login <= 1.0.6 - Unauthenticated Account Takeover via Twitter Login FlowEPSS 0.5%CVE-2026-18031CRITICALTabaPay Gateway <= 1.4.0 - Unauthenticated Account Takeover via Payment CallbackEPSS 0.5%CVE-2026-86707CRITICALPrivate Feed Key <= 0.1 - Unauthenticated Authentication Bypass via 'feedkey' ParameterEPSS 0.5%CVE-2026-12492CRITICALHappy Coders OTP Login for WooCommerce < 2.8 - Unauthenticated Account Takeover via hcotp_auto_login_userEPSS 0.5%