Fallos del tipo CWE-287

2445 resultados

Autenticação inadequada ou ausente

A aplicação não valida ou valida de forma insuficiente a identidade de quem tenta acessá-la. Quando um usuário diz ser quem é, o sistema acredita sem verificar corretamente, permitindo que atacantes se façam passar por outros usuários ou contas legítimas.

Ejemplo

Um sistema que aceita login apenas com nome de usuário, sem senha. Ou uma API que confia no header 'User-ID' enviado pelo cliente sem validar se aquele usuário realmente existe ou tem sessão ativa. Um atacante simplesmente altera o header e acessa dados de outra conta.

Cómo mitigar

Implemente autenticação robusta: exija múltiplos fatores (senha forte + MFA), valide credenciais contra base de dados segura, use sessões com token assinado e com expiração, nunca confie em dados enviados pelo cliente como prova de identidade. Revise regularmente logs de acesso para detectar abusos.

CVE-2025-27086HIGHA vulnerability in the HPE Performance Cluster Manager (HPCM) GUI could allow an attacker to bypass authentication.EPSS 0.4%CVE-2024-35670MEDIUMWordPress Integrate Google Drive plugin <= 1.3.93 - Broken Access Control vulnerabilityEPSS 0.4%CVE-2025-5597CRITICALWF Steuerungstechnik GmbH - airleader MASTER - Authentication BypassEPSS 0.4%CVE-2022-39018HIGHBroken access controls on PDFtron data in M-Files HubshareEPSS 0.4%CVE-2026-10167MEDIUMOUSL-GROUP-BrinaryBrains School Student Management System MY_Controller Login.php sign_auth_cookie improper authenticationEPSS 0.4%CVE-2026-85716LOWAsyncHttpClient: SCRAM and Digest mutual-authentication responses are not verifiedEPSS 0.4%CVE-2026-77826HIGHRegistrationMagic 5.0.1.8 - 6.0.9.8 - Unauthenticated Authentication Bypass via Missing Facebook Token Audience ValidationEPSS 0.4%CVE-2026-28428MEDIUMTalishar: Authentication Bypass via Empty authKey Parameter Allows Unauthenticated Game ActionsEPSS 0.4%CVE-2026-40946CRITICALOxia: OIDC token audience validation bypass via SkipClientIDCheckEPSS 0.4%CVE-2026-14596HIGHDynamicKit for Elementor < 1.0.3 - Unauthenticated Account Takeover via Password Reset Link Host InjectionEPSS 0.4%CVE-2025-30214HIGHFrappe vulnerable to information disclosure leading to account takeoverEPSS 0.4%CVE-2026-55689MEDIUMOpenFGA: OIDC audience validation skipped when --authn-oidc-audience is unsetEPSS 0.4%CVE-2025-14738MEDIUMConfiguration Disclosure Vulnerability in TP-Link WA850REEPSS 0.4%CVE-2026-44478HIGHhoppscotch: Unauthenticated Onboarding Config Disclosure via Empty Recovery TokenEPSS 0.4%CVE-2024-23767HIGHAn issue was discovered on HMS Anybus X-Gateway AB7832-F firmware version 3. The HICP protocol allows unauthenticated changes to a device's EPSS 0.4%CVE-2026-55666CRITICALRocket.Chat: Email Parameter Fallback Leads To Account Takeover Within Apple OAuthEPSS 0.4%CVE-2026-15206HIGHSMS Alert Order Notifications – WooCommerce < 3.9.8 - Unauthenticated Account Takeover via Unbound OTP Verification in Signup-with-MobileEPSS 0.4%CVE-2026-84606HIGHA privacy issue was addressed with improved handling of identifiers. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, visiEPSS 0.4%CVE-2026-32072MEDIUMActive Directory Spoofing VulnerabilityEPSS 0.4%CVE-2025-46572CRITICALpassport-wsfed-saml2 Has SAML Authentication Bypass via Signature WrappingEPSS 0.4%