Fallos del tipo CWE-287

2443 resultados

Autenticação inadequada ou ausente

A aplicação não valida ou valida de forma insuficiente a identidade de quem tenta acessá-la. Quando um usuário diz ser quem é, o sistema acredita sem verificar corretamente, permitindo que atacantes se façam passar por outros usuários ou contas legítimas.

Ejemplo

Um sistema que aceita login apenas com nome de usuário, sem senha. Ou uma API que confia no header 'User-ID' enviado pelo cliente sem validar se aquele usuário realmente existe ou tem sessão ativa. Um atacante simplesmente altera o header e acessa dados de outra conta.

Cómo mitigar

Implemente autenticação robusta: exija múltiplos fatores (senha forte + MFA), valide credenciais contra base de dados segura, use sessões com token assinado e com expiração, nunca confie em dados enviados pelo cliente como prova de identidade. Revise regularmente logs de acesso para detectar abusos.

CVE-2025-50901CRITICALJeeWMS 771e4f5d0c01ffdeae1671be4cf102b73a3fe644 (2025-05-19) contains incorrect authentication bypass vulnerability, which can lead to arbitEPSS 0.4%CVE-2026-12183CRITICALNefteprodukttekhnika BUK TS-G Gas Station Automation System Authentication Bypass via ajax-login.php Accepting Arbitrary CredentialsEPSS 0.4%CVE-2022-46829HIGHIn JetBrains JetBrains Gateway before 2022.3 a client could connect without a valid token if the host consented.EPSS 0.4%CVE-2021-25424—Improper authentication vulnerability in Tizen bluetooth-frwk prior to Firmware update JUN-2021 Release allows bluetooth attacker to take ovEPSS 0.4%CVE-2026-21508HIGHWindows Storage Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2024-34093MEDIUMAn issue was discovered in Archer Platform 6 before 2024.03. There is an X-Forwarded-For Header Bypass vulnerability. An unauthenticated attEPSS 0.4%CVE-2026-26077MEDIUMDiscourse doesn't ensure webhooks require a tokenEPSS 0.4%CVE-2022-22237MEDIUMJunos OS: Peers not configured for TCP-AO can establish a BGP or LDP session even if authentication is configured locallyEPSS 0.4%CVE-2026-17075MEDIUMIBM i is Affected By Multiple Vulnerabilities in Digital Certificate ManagerEPSS 0.4%CVE-2025-37107HIGHAn authentication bypass vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.18.EPSS 0.4%CVE-2024-44843MEDIUMAn issue in the web socket handshake process of SteVe v3.7.1 allows attackers to bypass authentication and execute arbitrary coammands via sEPSS 0.4%CVE-2026-55955MEDIUMApache Tomcat: EncryptInterceptor not protected against replay attacksEPSS 0.4%CVE-2025-6926HIGHSecurity Authentication Bypass in CentralAuthEPSS 0.4%CVE-2026-33124HIGHFrigate has insecure password change functionalityEPSS 0.4%CVE-2026-85596HIGHTraefik v3.7 Authentication Bypass via TLS Option ConflictEPSS 0.4%CVE-2020-3216MEDIUMCisco IOS XE SD-WAN Software Authentication Bypass VulnerabilityEPSS 0.4%CVE-2026-45691MEDIUMNextcloud: Bypass of second factor authentication on DAV endpointsEPSS 0.4%CVE-2026-27856HIGHDoveadm credentials are verified using direct comparison which is susceptible to timing oracle attack. An attacker can use this to determineEPSS 0.4%CVE-2025-62349HIGHSalt Master authentication protocol downgrade may enable minion impersonationEPSS 0.4%CVE-2026-45690MEDIUMNextcloud: Two-Factor Authentication Bypass via Pending Session Token ReplayEPSS 0.4%