Fallos del tipo CWE-287

2442 resultados

Autenticação inadequada ou ausente

A aplicação não valida ou valida de forma insuficiente a identidade de quem tenta acessá-la. Quando um usuário diz ser quem é, o sistema acredita sem verificar corretamente, permitindo que atacantes se façam passar por outros usuários ou contas legítimas.

Ejemplo

Um sistema que aceita login apenas com nome de usuário, sem senha. Ou uma API que confia no header 'User-ID' enviado pelo cliente sem validar se aquele usuário realmente existe ou tem sessão ativa. Um atacante simplesmente altera o header e acessa dados de outra conta.

Cómo mitigar

Implemente autenticação robusta: exija múltiplos fatores (senha forte + MFA), valide credenciais contra base de dados segura, use sessões com token assinado e com expiração, nunca confie em dados enviados pelo cliente como prova de identidade. Revise regularmente logs de acesso para detectar abusos.

CVE-2026-40138CRITICALCritical Pre-Authentication Vulnerability in BeyondTrust Remote Support and Privileged Remote AccessEPSS 0.5%CVE-2026-84114MEDIUMCleo Harmony SAML Authentication LocalUserUtil.getNativeUserByAssertions improper authenticationEPSS 0.5%CVE-2026-47718MEDIUMFUXA provides guest and invalid-token access to protected read APIs in secure modeEPSS 0.5%CVE-2025-59280LOWWindows SMB Client Tampering VulnerabilityEPSS 0.5%CVE-2024-11087HIGHminiOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) Pro Addon <= 200.3.9 - Authentication BypassEPSS 0.5%CVE-2023-26150MEDIUMVersions of the package asyncua before 0.9.96 are vulnerable to Improper Authentication such that it is possible to access Address Space witEPSS 0.5%CVE-2024-38810MEDIUMMissing Authorization When Using @AuthorizeReturnObjectEPSS 0.5%CVE-2025-53845MEDIUMAn improper authentication vulnerability [CWE-287] in Fortinet FortiAnalyzer version 7.6.0 through 7.6.3 and before 7.4.6 allows an unauthenEPSS 0.5%CVE-2025-27621HIGHUpTrain has a Constant Default API KeyEPSS 0.5%CVE-2023-35901LOWIBM Robotic Process Automation security bypassEPSS 0.5%CVE-2026-16905MEDIUMIBM Db2 Mirror for i is affected by multiple vulnerabilitiesEPSS 0.5%CVE-2026-73777HIGHAuthorization Bypass Vulnerabilities Leading to Privilege Escalation in AOS-CX API EndpointEPSS 0.5%CVE-2026-68760MEDIUMPotential remember-me authentication bypass in JFrog ArtifactoryEPSS 0.5%CVE-2026-76684HIGHAuthentication Bypass Vulnerabilities in HPE Networking EdgeConnect SD-WAN Orchestrator APIEPSS 0.5%CVE-2024-14034CRITICALHirschmann HiEOS Authentication Bypass via HTTP Management ModuleEPSS 0.5%CVE-2026-79938HIGHDell PowerProtect Cyber Recovery, versions prior to 20.3, contain an Improper Authentication vulnerability. A low privileged attacker with rEPSS 0.5%CVE-2026-79787CRITICALAlluxio through 2.9.5 S3 REST Proxy Authentication Bypass via Unverified Request SignatureEPSS 0.5%CVE-2026-32879MEDIUMNew API has passkey-based secure step-up verification bypass for root-only channel secret disclosureEPSS 0.5%CVE-2026-44707MEDIUMChatwoot: Pre-Account Takeover via OAuth on Unconfirmed AccountsEPSS 0.5%CVE-2026-93964MEDIUMNginxProxyManager nginx-proxy-manager Validate Route certificate.js internalCertificate.validate missing authenticationEPSS 0.5%