Fallos del tipo CWE-287

2442 resultados

Autenticação inadequada ou ausente

A aplicação não valida ou valida de forma insuficiente a identidade de quem tenta acessá-la. Quando um usuário diz ser quem é, o sistema acredita sem verificar corretamente, permitindo que atacantes se façam passar por outros usuários ou contas legítimas.

Ejemplo

Um sistema que aceita login apenas com nome de usuário, sem senha. Ou uma API que confia no header 'User-ID' enviado pelo cliente sem validar se aquele usuário realmente existe ou tem sessão ativa. Um atacante simplesmente altera o header e acessa dados de outra conta.

Cómo mitigar

Implemente autenticação robusta: exija múltiplos fatores (senha forte + MFA), valide credenciais contra base de dados segura, use sessões com token assinado e com expiração, nunca confie em dados enviados pelo cliente como prova de identidade. Revise regularmente logs de acesso para detectar abusos.

CVE-2025-3062MEDIUMDrupal Admin LTE theme - Critical - Unsupported - SA-CONTRIB-2025-010EPSS 0.5%CVE-2023-21027HIGHIn multiple functions of PasspointXmlUtils.java, there is a possible authentication misconfiguration due to a logic error in the code. This EPSS 0.5%CVE-2026-86722HIGHAVideo Authentication Bypass via SQL Cache InvalidationEPSS 0.5%CVE-2023-42662CRITICALJFrog Artifactory Improper SSO Mechanism may lead to Exposure of Access TokensEPSS 0.5%CVE-2024-1609HIGHOPPO Store APP has a WebView component privilege escalation vulnerability.EPSS 0.5%CVE-2026-92914HIGHAVideo LoginControl PGP Second Factor Authentication BypassEPSS 0.5%CVE-2026-48528CRITICALMetacat has an unauthenticated SQL injection vulnerabilityEPSS 0.5%CVE-2025-61665HIGHWeGIA: Broken Access Control in `get_relatorios_socios.php` EndpointEPSS 0.5%CVE-2026-86723HIGHAVideo LoginControl PGP Authentication Bypass via verifyChallengeEPSS 0.5%CVE-2022-24885LOWImproper Authentication in Nextcloud Android FilesEPSS 0.5%CVE-2026-50191HIGH4gaBoards: Pre-Account Takeover via SSO Email LinkageEPSS 0.5%CVE-2026-32305HIGHTraefik mTLS bypass via fragmented ClientHello SNI extraction failureEPSS 0.5%CVE-2025-5871MEDIUMPapendorf SOL Connect Center Web Interface missing authenticationEPSS 0.5%CVE-2024-25618MEDIUMExternal OpenID Connect Account Takeover by E-Mail Change in mastodonEPSS 0.5%CVE-2025-9803CRITICALImproper Authentication in lunary-ai/lunaryEPSS 0.5%CVE-2025-13427MEDIUMAuthentication Bypass in Dialogflow CX MessengerEPSS 0.5%CVE-2023-5326MEDIUMSATO CL4NX-J Plus WebConfig improper authenticationEPSS 0.5%CVE-2023-5328MEDIUMSATO CL4NX-J Plus Cookie improper authenticationEPSS 0.5%CVE-2024-45346HIGHGetApps application has code execution vulnerabilityEPSS 0.5%CVE-2025-27403HIGHRatify Azure authentication providers can leak authentication tokens to non-Azure container registriesEPSS 0.5%