Fallos del tipo CWE-287

2437 resultados

Autenticação inadequada ou ausente

A aplicação não valida ou valida de forma insuficiente a identidade de quem tenta acessá-la. Quando um usuário diz ser quem é, o sistema acredita sem verificar corretamente, permitindo que atacantes se façam passar por outros usuários ou contas legítimas.

Ejemplo

Um sistema que aceita login apenas com nome de usuário, sem senha. Ou uma API que confia no header 'User-ID' enviado pelo cliente sem validar se aquele usuário realmente existe ou tem sessão ativa. Um atacante simplesmente altera o header e acessa dados de outra conta.

Cómo mitigar

Implemente autenticação robusta: exija múltiplos fatores (senha forte + MFA), valide credenciais contra base de dados segura, use sessões com token assinado e com expiração, nunca confie em dados enviados pelo cliente como prova de identidade. Revise regularmente logs de acesso para detectar abusos.

CVE-2026-83020CRITICALVulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). SupporEPSS 0.5%CVE-2026-83462CRITICALVulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server). Supported versioEPSS 0.5%CVE-2022-47209HIGHA support user exists on the device and appears to be a backdoor for Technical Support staff. The default password for this account is “suppEPSS 0.5%CVE-2026-15611CRITICALUnverified email-based SSO account linkingEPSS 0.5%CVE-2026-34121HIGHAuthentication Bypass in DS Configuration Service via HTTP Request Parsing Differential of TP-Link Tapo C520WSEPSS 0.5%CVE-2026-52893CRITICALWekan: OIDC Account Takeover via Unconditional Email-Based Account Merge in onCreateUser hookEPSS 0.5%CVE-2026-5076CRITICALARMember Premium <= 7.3.1 - Insecure Password Reset Mechanism to Unauthenticated Privilege EscalationEPSS 0.5%CVE-2025-15586CRITICALOGP-Website installs prior git commit 52f865a4fba763594453068acf8fa9e3fc38d663 are affected by a type juggling flaw which if exploited can rEPSS 0.5%CVE-2025-43936HIGHDell ObjectScale, versions prior to ObjectScale 4.4.0.0, contains an Improper Authentication vulnerability. An unauthenticated attacker withEPSS 0.5%CVE-2024-21654MEDIUMrubygems.org MFA Bypass through password reset function could allow account takeover EPSS 0.5%CVE-2026-34531MEDIUMFlask-HTTPAuth invokes token verification callback when missing or empty token was given by clientEPSS 0.5%CVE-2026-22752CRITICALSpring Security Authorization Server Dynamic Client Registration endpoints perform insufficient validation of client metadataEPSS 0.5%CVE-2024-4129HIGHAuthentication bypass in Snow License ManagerEPSS 0.5%CVE-2026-55075HIGHCoder vulnerable to OIDC account takeover via email-based user matching and email_verified bypassEPSS 0.5%CVE-2024-13804CRITICALUnauthenticated RCE in HPE Insight Cluster Management UtilityEPSS 0.5%CVE-2026-41571CRITICALNote Mark: OIDC-registered users authenticated by submitting password "null"EPSS 0.5%CVE-2025-2388MEDIUMKeytop 路内停车收费系统 API getParks improper authenticationEPSS 0.5%CVE-2025-3062MEDIUMDrupal Admin LTE theme - Critical - Unsupported - SA-CONTRIB-2025-010EPSS 0.5%CVE-2023-21027HIGHIn multiple functions of PasspointXmlUtils.java, there is a possible authentication misconfiguration due to a logic error in the code. This EPSS 0.5%CVE-2026-72922HIGHAutoGPT: Webhook provider path confusion bypasses generic webhook secret verificationEPSS 0.5%