Fallos del tipo CWE-287

2443 resultados

Autenticação inadequada ou ausente

A aplicação não valida ou valida de forma insuficiente a identidade de quem tenta acessá-la. Quando um usuário diz ser quem é, o sistema acredita sem verificar corretamente, permitindo que atacantes se façam passar por outros usuários ou contas legítimas.

Ejemplo

Um sistema que aceita login apenas com nome de usuário, sem senha. Ou uma API que confia no header 'User-ID' enviado pelo cliente sem validar se aquele usuário realmente existe ou tem sessão ativa. Um atacante simplesmente altera o header e acessa dados de outra conta.

Cómo mitigar

Implemente autenticação robusta: exija múltiplos fatores (senha forte + MFA), valide credenciais contra base de dados segura, use sessões com token assinado e com expiração, nunca confie em dados enviados pelo cliente como prova de identidade. Revise regularmente logs de acesso para detectar abusos.

CVE-2026-93964MEDIUMNginxProxyManager nginx-proxy-manager Validate Route certificate.js internalCertificate.validate missing authenticationEPSS 0.5%CVE-2025-8546MEDIUMatjiu pybbs Verification Code login CaptchaEPSS 0.5%CVE-2026-13597CRITICALQRcode Login for WeChat <= 1.3 - Unauthenticated Account TakeoverEPSS 0.5%CVE-2021-45035MEDIUMVelneo vClient Improper authenticationEPSS 0.5%CVE-2026-56345CRITICALAVideo - Arbitrary User Session Hijacking via Meet Plugin uploadRecordedVideo EndpointEPSS 0.5%CVE-2025-5437MEDIUMMultilaser Sirius RE016 Password Change cstecgi.cgi improper authenticationEPSS 0.5%CVE-2022-35629—Velociraptor Client ID SpoofingEPSS 0.5%CVE-2025-10423MEDIUMnewbee-mall kaptcha mallKaptcha CaptchaEPSS 0.5%CVE-2025-12810MEDIUMFailure in Password Rotation and Check-in Mechanism in Secret Server Allows Reuse of CredentialsEPSS 0.5%CVE-2021-45917HIGHSUN & MOON RISE CO., LTD. Shockwall - Improper AuthenticationEPSS 0.5%CVE-2017-20235CRITICALProSoft Technology ICX35-HWC Authentication BypassEPSS 0.5%CVE-2025-71279CRITICALXenForo Passkey Security BypassEPSS 0.5%CVE-2023-47189MEDIUMWordPress Defender Security plugin <= 4.2.0 - Masked Login Area View Bypass vulnerabilityEPSS 0.5%CVE-2024-7870MEDIUMPixelYourSite – Your smart PIXEL (TAG) & API Manager <= 9.7.1 and PixelYourSite PRO <= 10.4.2 - Unauthenticated Information Exposure and Log DeletionEPSS 0.4%CVE-2026-49202HIGHUnverified Meeting Recording Endpoints & Permissive CORSEPSS 0.4%CVE-2025-64175HIGHGogs Vulnerable to 2FA Bypass via Recovery CodeEPSS 0.4%CVE-2022-0916HIGHBroken authentication on Logitech Options due to misvalidation of Oauth state parameterEPSS 0.4%CVE-2026-21633HIGHA malicious actor with access to the adjacent network could obtain unauthorized access to a UniFi Protect Camera by exploiting a discovery pEPSS 0.4%CVE-2026-56219HIGHCapgo - Unauthenticated RBAC Bindings and Email Disclosure via get_org_user_access_rbac NULL-auth BypassEPSS 0.4%CVE-2023-46630HIGHWordPress Admin and Site Enhancements (ASE) plugin <= 5.7.1 - Password Protected View Bypass Vulnerability vulnerabilityEPSS 0.4%