Fallos del tipo CWE-287

2446 resultados

Autenticação inadequada ou ausente

A aplicação não valida ou valida de forma insuficiente a identidade de quem tenta acessá-la. Quando um usuário diz ser quem é, o sistema acredita sem verificar corretamente, permitindo que atacantes se façam passar por outros usuários ou contas legítimas.

Ejemplo

Um sistema que aceita login apenas com nome de usuário, sem senha. Ou uma API que confia no header 'User-ID' enviado pelo cliente sem validar se aquele usuário realmente existe ou tem sessão ativa. Um atacante simplesmente altera o header e acessa dados de outra conta.

Cómo mitigar

Implemente autenticação robusta: exija múltiplos fatores (senha forte + MFA), valide credenciais contra base de dados segura, use sessões com token assinado e com expiração, nunca confie em dados enviados pelo cliente como prova de identidade. Revise regularmente logs de acesso para detectar abusos.

CVE-2023-48747MEDIUMWordPress Booster for WooCommerce plugin <= 7.1.2 - Authenticated Production Creation/Modification VulnerabilityEPSS 0.4%CVE-2026-10777MEDIUMealpha072 Student-Management-System Administrative Backend config.php improper authenticationEPSS 0.4%CVE-2026-15089CRITICALCommerce guest registration - Critical - Unsupported - SA-CONTRIB-2026-079EPSS 0.4%CVE-2026-18215MEDIUMKeycloak-services: keycloak-services: microsoft external access-token exchange bypasses configured tenantEPSS 0.4%CVE-2026-4476MEDIUMYi Technology YI Home Camera CGI Endpoint ipc missing authenticationEPSS 0.4%CVE-2026-45567HIGHRoxy-WI: Authentication bypass via 'api' substring in URL + unauthenticated /api/gptEPSS 0.4%CVE-2023-21455MEDIUMImproper authorization implementation in Exynos baseband prior to SMR Mar-2023 Release 1 allows incorrect handling of unencrypted message.EPSS 0.4%CVE-2018-16877HIGHA flaw was found in the way pacemaker's client-server authentication was implemented in versions up to and including 2.0.0. A local attackerEPSS 0.4%CVE-2025-58065MEDIUMFlask App Builder has an Authentication Bypass vulnerability when using non AUTH_DB methodsEPSS 0.4%CVE-2025-31271HIGHThis issue was addressed through improved state management. This issue is fixed in macOS Tahoe 26. Incoming FaceTime calls can appear or be EPSS 0.4%CVE-2023-38367MEDIUMIBM Cloud Pak for Automation authentication bypassEPSS 0.4%CVE-2026-56223CRITICALCapgo - Account Takeover via Cross-Domain SSO Email Assertion in provision-userEPSS 0.4%CVE-2024-42336HIGHServision - CWE-287: Improper AuthenticationEPSS 0.4%CVE-2026-8185MEDIUMUGREEN CM933 Administrative missing authenticationEPSS 0.4%CVE-2024-37313HIGHNextcloud server allows the by-pass the second factorEPSS 0.4%CVE-2026-28471MEDIUMOpenClaw 2026.1.14-1 < 2026.2.2 - Allowlist Bypass via displayName and Cross-Homeserver localpart Matching in Matrix PluginEPSS 0.4%CVE-2026-11618MEDIUMDTStack Taier Source Connection Test Endpoint LoginInterceptor.java preHandle improper authenticationEPSS 0.4%CVE-2025-68640MEDIUMThe Apple Find My backend service through 2025-12-17 allows an attacker in possession of a valid PET (Private Endpoint Token) to enumerate dEPSS 0.4%CVE-2026-56737HIGHphpMyFAQ's two-factor authentication login bypasses the password factorEPSS 0.4%CVE-2026-10617MEDIUMnextlevelbuilder GoClaw Webhook Verification auth.go resolveAuth missing authenticationEPSS 0.4%