Fallos del tipo CWE-287

2437 resultados

Autenticação inadequada ou ausente

A aplicação não valida ou valida de forma insuficiente a identidade de quem tenta acessá-la. Quando um usuário diz ser quem é, o sistema acredita sem verificar corretamente, permitindo que atacantes se façam passar por outros usuários ou contas legítimas.

Ejemplo

Um sistema que aceita login apenas com nome de usuário, sem senha. Ou uma API que confia no header 'User-ID' enviado pelo cliente sem validar se aquele usuário realmente existe ou tem sessão ativa. Um atacante simplesmente altera o header e acessa dados de outra conta.

Cómo mitigar

Implemente autenticação robusta: exija múltiplos fatores (senha forte + MFA), valide credenciais contra base de dados segura, use sessões com token assinado e com expiração, nunca confie em dados enviados pelo cliente como prova de identidade. Revise regularmente logs de acesso para detectar abusos.

CVE-2022-23501MEDIUMTYPO3 vulnerable to Improper Authentication in Frontend LoginEPSS 0.5%CVE-2022-39238MEDIUMImproper Authentication in Arvados when using PAM as identity providerEPSS 0.5%CVE-2025-5247MEDIUMGowabby HFish url.go LoadUrl improper authenticationEPSS 0.5%CVE-2025-66698HIGHAn issue in Semantic machines v5.4.8 allows attackers to bypass authentication via sending a crafted HTTP request to various API endpoints.EPSS 0.5%CVE-2025-2344MEDIUMIROAD Dash Cam X5/Dash Cam X6 API Endpoint missing authenticationEPSS 0.5%CVE-2026-24038HIGHHorilla HR has 2FA Bypass through its OTP Handling LogicEPSS 0.5%CVE-2026-46715MEDIUMFlask-Security-Too OAuth reauthentication freshness bypass via cross- user OAuth identity acceptanceEPSS 0.5%CVE-2025-57434HIGHCreacast Creabox Manager contains a critical authentication flaw that allows an attacker to bypass login validation. The system grants accesEPSS 0.5%CVE-2026-7844MEDIUMchatchat-space Langchain-Chatchat Compatible File Service openai_routes.py delete_file missing authenticationEPSS 0.5%CVE-2025-15224LOWlibssh key passphrase bypass without agent setEPSS 0.5%CVE-2025-49146HIGHpgjdbc Client Allows Fallback to Insecure Authentication Despite channelBinding=require ConfigurationEPSS 0.5%CVE-2024-25106CRITICALOpenObserve Unauthorized Access Vulnerability in Users APIEPSS 0.5%CVE-2023-28963MEDIUMJunos OS: User-controlled input vulnerability in J-WebEPSS 0.5%CVE-2024-28006MEDIUMImproper authentication vulnerability in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WEPSS 0.5%CVE-2025-52553MEDIUMauthentik has Insufficient Session verification for Remote Access Control endpoint accessEPSS 0.5%CVE-2023-40020CRITICALImproper Authentication in PrivateUploaderEPSS 0.5%CVE-2026-55533HIGHPraisonAI: Authentication fail-open in Recipe server allows unauthenticated access when API key or JWT auth is configured without a secretEPSS 0.5%CVE-2026-32730HIGHApostropheCMS MFA/TOTP Bypass via Incorrect MongoDB Query in Bearer Token MiddlewareEPSS 0.5%CVE-2024-13528HIGHCustomer Email Verification for WooCommerce <= 2.9.5 - Authentication Bypass via ShortcodeEPSS 0.5%CVE-2026-10560HIGHUnauthenticated Access to Private Flow Build Events and Cancellation in Langflow OSSEPSS 0.5%