Fallos del tipo CWE-287

2442 resultados

Autenticação inadequada ou ausente

A aplicação não valida ou valida de forma insuficiente a identidade de quem tenta acessá-la. Quando um usuário diz ser quem é, o sistema acredita sem verificar corretamente, permitindo que atacantes se façam passar por outros usuários ou contas legítimas.

Ejemplo

Um sistema que aceita login apenas com nome de usuário, sem senha. Ou uma API que confia no header 'User-ID' enviado pelo cliente sem validar se aquele usuário realmente existe ou tem sessão ativa. Um atacante simplesmente altera o header e acessa dados de outra conta.

Cómo mitigar

Implemente autenticação robusta: exija múltiplos fatores (senha forte + MFA), valide credenciais contra base de dados segura, use sessões com token assinado e com expiração, nunca confie em dados enviados pelo cliente como prova de identidade. Revise regularmente logs de acesso para detectar abusos.

CVE-2025-5872MEDIUMeGauge EG3000 Energy Monitor Setting missing authenticationEPSS 0.5%CVE-2026-73655HIGHTrigger.dev: Account Takeover via Cross-Provider OAuth Email Matching in Google LoginEPSS 0.5%CVE-2026-73771HIGHImproper Authentication Handling in AOS-CX Management Interface and APIEPSS 0.5%CVE-2025-5876MEDIUMLucky LM-520-SC/LM-520-FSC/LM-520-FSC-SAM missing authenticationEPSS 0.5%CVE-2026-84831HIGHMandatory MFA bypass before enrollmentEPSS 0.5%CVE-2023-39303MEDIUMQTS, QuTS hero, QuTScloudEPSS 0.5%CVE-2025-27416MEDIUMAsking For Scratch Username And PasswordEPSS 0.5%CVE-2026-76338HIGHImproper Authentication through REST API Distributed Search Token Requests in Splunk EnterpriseEPSS 0.5%CVE-2026-13600HIGHAutoNetTV Relay < 3.0.14 - Unauthenticated Privilege Escalation via Scheduled Sync CronEPSS 0.5%CVE-2026-12255HIGHMainWP Child < 6.1.2 - Unauthenticated Administrator Authentication Bypass via Passwordless Site RegistrationEPSS 0.5%CVE-2026-21854CRITICALTarkov Data Manager Authentication Bypass vulnerabilityEPSS 0.5%CVE-2026-76793HIGHFirebase Authentication < 1.7.1 - Unauthenticated Account Takeover via Firebase Email ClaimEPSS 0.5%CVE-2024-49376HIGHAutolab Has Misconfigured Reset Password PermissionsEPSS 0.5%CVE-2025-62376CRITICALpwn.college DOJO vulnerable to improper authentication in workspace endpoint allowing unauthorized Windows VM accessEPSS 0.5%CVE-2023-38691MEDIUMmatrix-appservice-bridge doesn't verify the sub parameter of an openId token exhange, allowing unauthorized access to provisioning APIsEPSS 0.5%CVE-2026-49186HIGHLack of MQTT Broker Topic Access Control ListsEPSS 0.5%CVE-2025-64717HIGHZITADEL vulnerable to Account Takeover with deactivated Instance IdPEPSS 0.5%CVE-2026-10845HIGHIBM WebSphere Application Server is affected by an authentication bypass vulnerabilityEPSS 0.5%CVE-2024-9927HIGHWooCommerce Order Proposal <= 2.0.5 - Authenticated (Shop Manager+) Privilege Escalation via Order ProposalEPSS 0.5%CVE-2025-14097HIGHRemote Code Execution Vulnerability in Radiometer ProductsEPSS 0.5%