Fallos del tipo CWE-287

2445 resultados

Autenticação inadequada ou ausente

A aplicação não valida ou valida de forma insuficiente a identidade de quem tenta acessá-la. Quando um usuário diz ser quem é, o sistema acredita sem verificar corretamente, permitindo que atacantes se façam passar por outros usuários ou contas legítimas.

Ejemplo

Um sistema que aceita login apenas com nome de usuário, sem senha. Ou uma API que confia no header 'User-ID' enviado pelo cliente sem validar se aquele usuário realmente existe ou tem sessão ativa. Um atacante simplesmente altera o header e acessa dados de outra conta.

Cómo mitigar

Implemente autenticação robusta: exija múltiplos fatores (senha forte + MFA), valide credenciais contra base de dados segura, use sessões com token assinado e com expiração, nunca confie em dados enviados pelo cliente como prova de identidade. Revise regularmente logs de acesso para detectar abusos.

CVE-2024-44821MEDIUMZZCMS 2023 contains a vulnerability in the captcha reuse logic located in /inc/function.php. The checkyzm function does not properly refreshEPSS 0.4%CVE-2026-34873CRITICALAn issue was discovered in Mbed TLS 3.5.0 through 4.0.0. Client impersonation can occur while resuming a TLS 1.3 session.EPSS 0.4%CVE-2023-31279HIGHImproper AuthenticationEPSS 0.4%CVE-2026-71277CRITICALrust-iot-platform Authentication Bypass via Non-Validated Authorization HeaderEPSS 0.4%CVE-2026-46485HIGHDash: Users can write to config despire permissions (OIDC tested)EPSS 0.4%CVE-2026-58075HIGHA vulnerability allowing an unauthenticated attacker to read arbitrary files from the host, which can be further leveraged toescalate privilEPSS 0.4%CVE-2026-10157MEDIUMOpen5GS NGAP PathSwitchRequest Message ngap-handler.c improper authenticationEPSS 0.4%CVE-2024-37233MEDIUMWordPress Play.ht plugin <= 3.6.4 - Broken Access Control vulnerabilityEPSS 0.4%CVE-2024-3487LOWBroken Authentication vulnerability in iManagerEPSS 0.4%CVE-2022-46313MEDIUMThe sensor privacy module has an authentication vulnerability. Successful exploitation of this vulnerability may cause unavailability of theEPSS 0.4%CVE-2026-16055HIGHContest Gallery < 30.0.7 - Unauthenticated Login-Protection and 2FA Bypass via post_cg_loginEPSS 0.4%CVE-2026-15210CRITICALLogin/Signup with Phone Number, OTP Verification < 1.8.71 - Unauthenticated Account Takeover via OTP Brute ForceEPSS 0.4%CVE-2026-19714CRITICALSimple JWT Login < 3.6.8 - Unauthenticated Account Takeover via Missing Google id_token Audience ValidationEPSS 0.4%CVE-2026-9398LOWBesen BS20 EV Charging Station BLE/WiFi authentication replayEPSS 0.4%CVE-2026-83961HIGHColdFusion | Improper Authentication (CWE-287)EPSS 0.4%CVE-2026-13332CRITICALMasteriyo LMS < 2.3.1 - Unauthenticated Arbitrary User Session Termination (Denial of Service)EPSS 0.4%CVE-2026-34727HIGHVikunja ahs a TOTP Two-Factor Authentication Bypass via OIDC Login PathEPSS 0.4%CVE-2022-48294HIGHThe IHwAttestationService interface has a defect in authentication. Successful exploitation of this vulnerability may affect data confidentiEPSS 0.4%CVE-2026-49194CRITICALSCREEN_CLICK Authentication BypassEPSS 0.4%CVE-2025-7115MEDIUMrowboatlabs rowboat Session route.ts PUT missing authenticationEPSS 0.4%