Fallos del tipo CWE-287

2445 resultados

Autenticação inadequada ou ausente

A aplicação não valida ou valida de forma insuficiente a identidade de quem tenta acessá-la. Quando um usuário diz ser quem é, o sistema acredita sem verificar corretamente, permitindo que atacantes se façam passar por outros usuários ou contas legítimas.

Ejemplo

Um sistema que aceita login apenas com nome de usuário, sem senha. Ou uma API que confia no header 'User-ID' enviado pelo cliente sem validar se aquele usuário realmente existe ou tem sessão ativa. Um atacante simplesmente altera o header e acessa dados de outra conta.

Cómo mitigar

Implemente autenticação robusta: exija múltiplos fatores (senha forte + MFA), valide credenciais contra base de dados segura, use sessões com token assinado e com expiração, nunca confie em dados enviados pelo cliente como prova de identidade. Revise regularmente logs de acesso para detectar abusos.

CVE-2026-46937HIGHVulnerability in the Oracle iSetup product of Oracle E-Business Suite (component: General Ledger Update Transform, Reports). Supported versEPSS 0.4%CVE-2026-46827HIGHVulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Self Service Manager). Supported versions that are affecEPSS 0.4%CVE-2021-44458HIGHLack of websocket authentication in Lens causes remote code execution when visiting a malicious websiteEPSS 0.4%CVE-2025-12998HIGHBroken Authentication in extension “Modules” (modules)EPSS 0.4%CVE-2025-57278HIGHThe LB-Link BL-CPE300M AX300 4G LTE Router firmware version BL-R8800_B10_ALK_SL_V01.01.02P42U14_06 does not implement proper session handlinEPSS 0.4%CVE-2026-32253CRITICALSunshine: Authentication bypass via improper client certificate validationEPSS 0.4%CVE-2023-28540CRITICALImproper Authentication in Data ModemEPSS 0.4%CVE-2024-50641HIGHAn authentication bypass vulnerability in PandoraNext-TokensTool v0.6.8 and before. An attacker can exploit this vulnerability to access APIEPSS 0.4%CVE-2026-18816LOWBaserow 2FA Verify Endpoint views.py verify improper authenticationEPSS 0.4%CVE-2025-2859MEDIUMImproper Authentication vulnerability in saTECH BCUEPSS 0.4%CVE-2026-67327HIGHbetter-auth before 1.6.22 Account Takeover via Magic-Link Email-OTPEPSS 0.4%CVE-2026-73302CRITICALBudibase: OIDC SSO account takeover: incoming identity linked by email without checking email_verifiedEPSS 0.4%CVE-2026-48526HIGHPyJWT: Public-key JWK accepted as HMAC secret enables forged HS256 tokens when mixed families are allowedEPSS 0.4%CVE-2026-41671MEDIUMAdmidio: OIDC Token Introspection Endpoint Returns Active for All Tokens Without ValidationEPSS 0.4%CVE-2026-16036HIGHminiOrange 2FA < 6.2.7 - 2FA Bypass via Password-Only Second-Factor RebindingEPSS 0.4%CVE-2026-9830HIGHBookingPress Pro < 5.7.3 - Unauthenticated Customer PII Disclosure and Booking Tampering via Permission Callback BugEPSS 0.4%CVE-2026-17203HIGHIBM Application Runtime Expert (ARE) for IBM i is vulnerable to a user gaining elevated privileges and sensitive information [, ].EPSS 0.4%CVE-2025-27422HIGHFACTION Allows Authentication Bypass via User CreationEPSS 0.4%CVE-2022-39892LOWImproper access control in Samsung Pass prior to version 4.0.05.1 allows attackers to unauthenticated access via keep open feature.EPSS 0.4%CVE-2026-83104CRITICALVulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). Supported versions that aEPSS 0.4%