Fallos del tipo CWE-287

2442 resultados

Autenticação inadequada ou ausente

A aplicação não valida ou valida de forma insuficiente a identidade de quem tenta acessá-la. Quando um usuário diz ser quem é, o sistema acredita sem verificar corretamente, permitindo que atacantes se façam passar por outros usuários ou contas legítimas.

Ejemplo

Um sistema que aceita login apenas com nome de usuário, sem senha. Ou uma API que confia no header 'User-ID' enviado pelo cliente sem validar se aquele usuário realmente existe ou tem sessão ativa. Um atacante simplesmente altera o header e acessa dados de outra conta.

Cómo mitigar

Implemente autenticação robusta: exija múltiplos fatores (senha forte + MFA), valide credenciais contra base de dados segura, use sessões com token assinado e com expiração, nunca confie em dados enviados pelo cliente como prova de identidade. Revise regularmente logs de acesso para detectar abusos.

CVE-2025-62376CRITICALpwn.college DOJO vulnerable to improper authentication in workspace endpoint allowing unauthorized Windows VM accessEPSS 0.5%CVE-2025-64717HIGHZITADEL vulnerable to Account Takeover with deactivated Instance IdPEPSS 0.5%CVE-2025-14097HIGHRemote Code Execution Vulnerability in Radiometer ProductsEPSS 0.5%CVE-2026-73085MEDIUMAudiobookshelf: Refresh Token Accepted on Resource EndpointsEPSS 0.5%CVE-2026-73337HIGHJoomla! Core - [20260807] - MFA Authentication Bypass in Joomla 4.0.0-5.4.7 and 6.0.0-6.1.2EPSS 0.5%CVE-2020-7295LOWWeb Gateway (MWG) - Privilege Escalation vulnerabilityEPSS 0.5%CVE-2026-46488CRITICALmotionEye: Authentication possible via password hashEPSS 0.5%CVE-2026-55377HIGHLogto: Account Center MFA management step-up bypass via WebAuthn registration verificationEPSS 0.5%CVE-2024-47078HIGHMeshtastic firmware Authentication/Authorization Bypass via MQTTEPSS 0.5%CVE-2026-48114CRITICALMetacat has an unauthenticated SQL injection vulnerabilityEPSS 0.5%CVE-2026-83327CRITICALVulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Personalization). Supported versions thatEPSS 0.5%CVE-2023-23761HIGHImproper authentication vulnerability in GitHub Enterprise Server leading to modification of secret gistsEPSS 0.5%CVE-2026-21582HIGHThis High severity BASM (Broken Authentication & Session Management) vulnerability known as CVE-2026-21582 was introduced in version 7.2.1 oEPSS 0.5%CVE-2021-25910HIGHZIV AUTOMATION 4CCT vulnerable to improper authenticationEPSS 0.5%CVE-2026-44847HIGHMaxKB: Webhook Trigger Authentication BypassEPSS 0.5%CVE-2025-5870MEDIUMTRENDnet TV-IP121W Web Interface setup.cgi improper authenticationEPSS 0.5%CVE-2026-27939HIGHStatamic allows Authenticated Control Panel users to escalate privileges via elevated session bypassEPSS 0.5%CVE-2026-17099HIGHIBM i is Affected By Multiple Vulnerabilities in Navigator for iEPSS 0.5%CVE-2026-40138CRITICALCritical Pre-Authentication Vulnerability in BeyondTrust Remote Support and Privileged Remote AccessEPSS 0.5%CVE-2024-41800MEDIUMCraft CMS Allows TOTP Token To Stay Valid After UseEPSS 0.5%