Fallos del tipo CWE-287

2445 resultados

Autenticação inadequada ou ausente

A aplicação não valida ou valida de forma insuficiente a identidade de quem tenta acessá-la. Quando um usuário diz ser quem é, o sistema acredita sem verificar corretamente, permitindo que atacantes se façam passar por outros usuários ou contas legítimas.

Ejemplo

Um sistema que aceita login apenas com nome de usuário, sem senha. Ou uma API que confia no header 'User-ID' enviado pelo cliente sem validar se aquele usuário realmente existe ou tem sessão ativa. Um atacante simplesmente altera o header e acessa dados de outra conta.

Cómo mitigar

Implemente autenticação robusta: exija múltiplos fatores (senha forte + MFA), valide credenciais contra base de dados segura, use sessões com token assinado e com expiração, nunca confie em dados enviados pelo cliente como prova de identidade. Revise regularmente logs de acesso para detectar abusos.

CVE-2026-19971MEDIUMLB-Link WR1210M Backup Endpoint backup.cgi main missing authenticationEPSS 0.4%CVE-2020-8097HIGHImproper authentication vulnerability in Bitdefender Endpoint Security Tools and Endpoint Security SDK (VA-8646)EPSS 0.4%CVE-2026-1305MEDIUMJapanized for WooCommerce <= 2.8.4 - Missing Authorization to Unauthenticated Paidy Order ManipulationEPSS 0.4%CVE-2026-12877CRITICALSoftware Issue Manager < 5.1.0 - Unauthenticated SQL Injection via Search ParameterEPSS 0.4%CVE-2026-93984MEDIUMOpenPanel API Authentication Bypass via Unverified Client SecretEPSS 0.4%CVE-2025-53889MEDIUMDirectus missing permission checks for manual trigger FlowsEPSS 0.4%CVE-2026-57134HIGHPraisonAI MCPSecurity Basic/OAuth authentication policies accept invalid credentials without validationEPSS 0.4%CVE-2025-67822CRITICALA vulnerability in the Provisioning Manager component of Mitel MiVoice MX-ONE 7.3 (7.3.0.0.50) through 7.8 SP1 (7.8.1.0.14) could allow an uEPSS 0.4%CVE-2026-60327HIGHVulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that EPSS 0.4%CVE-2026-11345MEDIUMImproper Authentication Bypass in linqi CDN File AccessEPSS 0.4%CVE-2025-70833CRITICALAn Authentication Bypass vulnerability in Smanga 3.2.7 allows an unauthenticated attacker to reset the password of any user (including the aEPSS 0.4%CVE-2026-18074HIGHIBM Financial Transaction Manager (FTM) is Impacted by Multiple VulnerabilitiesEPSS 0.4%CVE-2022-47976HIGHThe DMSDP module of the distributed hardware has a vulnerability that may cause imposter control connections.Successful exploitation of thisEPSS 0.4%CVE-2026-44961NONEThe XML‑RPC API addUser method has a validation bypass introduced in the fix for CVE‑2025‑55129. As a result, API users could create usernamEPSS 0.4%CVE-2026-4583LOWShenzhen HCC Technology MPOS M6 PLUS Bluetooth authentication replayEPSS 0.4%CVE-2026-10281MEDIUMEnderfga claw-orchestrator API Endpoint embedded-server.ts EmbeddedServer missing authenticationEPSS 0.4%CVE-2026-13690HIGHUsersWP < 1.2.67 - Two-Factor Authentication BypassEPSS 0.4%CVE-2026-2756LOWOmniPEMF NeoRhythm BLE missing authenticationEPSS 0.4%CVE-2021-22943—A vulnerability found in UniFi Protect application V1.18.1 and earlier permits a malicious actor who has already gained access to a network EPSS 0.4%CVE-2026-75807HIGHSAML Single Sign On <= 5.4.6 - Unauthenticated Authentication Bypass via X.509 Certificate PoisoningEPSS 0.4%