Fallos del tipo CWE-287

2435 resultados

Autenticação inadequada ou ausente

A aplicação não valida ou valida de forma insuficiente a identidade de quem tenta acessá-la. Quando um usuário diz ser quem é, o sistema acredita sem verificar corretamente, permitindo que atacantes se façam passar por outros usuários ou contas legítimas.

Ejemplo

Um sistema que aceita login apenas com nome de usuário, sem senha. Ou uma API que confia no header 'User-ID' enviado pelo cliente sem validar se aquele usuário realmente existe ou tem sessão ativa. Um atacante simplesmente altera o header e acessa dados de outra conta.

Cómo mitigar

Implemente autenticação robusta: exija múltiplos fatores (senha forte + MFA), valide credenciais contra base de dados segura, use sessões com token assinado e com expiração, nunca confie em dados enviados pelo cliente como prova de identidade. Revise regularmente logs de acesso para detectar abusos.

CVE-2026-77000CRITICALWP Social Media Login <= 1.0.6 - Unauthenticated Account Takeover via Twitter Login FlowEPSS 0.5%CVE-2023-38534HIGHImproper authentication vulnerability in OpenText™ Exceed Turbo X affecting versions 12.5.0 and 12.5.1. The vulnerability could allow discloEPSS 0.5%CVE-2026-14182CRITICALCustomer Email Verification for WooCommerce < 3.2.6 - Unauthenticated Account Takeover via Type-Juggling Authentication BypassEPSS 0.5%CVE-2026-18031CRITICALTabaPay Gateway <= 1.4.0 - Unauthenticated Account Takeover via Payment CallbackEPSS 0.5%CVE-2024-37367HIGHRockwell Automation FactoryTalk® View SE v12 Information Leakage Vulnerability via Authentication RestrictionEPSS 0.5%CVE-2023-22663MEDIUMImproper authentication for some Intel Unison software may allow an authenticated user to potentially enable escalation of privilege via netEPSS 0.5%CVE-2023-46172MEDIUMIBM DS8900F security bypassEPSS 0.5%CVE-2026-95676HIGHAuthPoint Gateway Improper Authentication in LDAP Sync Allows First-Factor Authentication BypassEPSS 0.5%CVE-2025-12374CRITICALEmail Verification, Email OTP, Block Spam Email, Passwordless login, Hide Login, Magic Login – User Verification <= 2.0.44 - Authentication Bypass to Account TakeoverEPSS 0.5%CVE-2026-33117CRITICALAzure SDK for Java Security Feature Bypass VulnerabilityEPSS 0.5%CVE-2022-34331MEDIUMIBM Power FW security bypassEPSS 0.5%CVE-2026-10288MEDIUMcode-projects Hotel and Tourism Reservation System Admin Login login.php password_verify improper authenticationEPSS 0.5%CVE-2026-17197HIGHIBM i is Affected By Multiple Vulnerabilities in Host ServersEPSS 0.5%CVE-2026-86721HIGHAVideo through c3edcc274c Authorization Bypass via Session CookieEPSS 0.5%CVE-2024-35184MEDIUMpaperless-ngx's remote user auth via header works even when disabling it for APIEPSS 0.5%CVE-2023-4677HIGHUnauthenticated Admin Account Takeover Via Cron Log File BackupsEPSS 0.5%CVE-2024-22441CRITICALHPE Cray Parallel Application Launch Service (PALS) is subject to an authentication bypass.EPSS 0.5%CVE-2026-55761HIGHPortainer: Unauthenticated Restore Endpoint Allows Admin Takeover on Uninitialised Portainer InstancesEPSS 0.5%CVE-2022-46316CRITICALA thread security vulnerability exists in the authentication process. Successful exploitation of this vulnerability may affect data integritEPSS 0.5%CVE-2022-39238MEDIUMImproper Authentication in Arvados when using PAM as identity providerEPSS 0.5%