Fallos del tipo CWE-287

2446 resultados

Autenticação inadequada ou ausente

A aplicação não valida ou valida de forma insuficiente a identidade de quem tenta acessá-la. Quando um usuário diz ser quem é, o sistema acredita sem verificar corretamente, permitindo que atacantes se façam passar por outros usuários ou contas legítimas.

Ejemplo

Um sistema que aceita login apenas com nome de usuário, sem senha. Ou uma API que confia no header 'User-ID' enviado pelo cliente sem validar se aquele usuário realmente existe ou tem sessão ativa. Um atacante simplesmente altera o header e acessa dados de outra conta.

Cómo mitigar

Implemente autenticação robusta: exija múltiplos fatores (senha forte + MFA), valide credenciais contra base de dados segura, use sessões com token assinado e com expiração, nunca confie em dados enviados pelo cliente como prova de identidade. Revise regularmente logs de acesso para detectar abusos.

CVE-2025-70841CRITICALDokans Multi-Tenancy Based eCommerce Platform SaaS 3.9.2 allows unauthenticated remote attackers to obtain sensitive application configuratiEPSS 0.4%CVE-2025-30168MEDIUMParse Server has an OAuth login vulnerabilityEPSS 0.4%CVE-2025-62717LOWEmlog Pro session verification code error due to clearing logic errorEPSS 0.4%CVE-2025-14942CRITICALAuthentication BypassEPSS 0.4%CVE-2025-46630MEDIUMImproper access controls in the web management portal of the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated remote attacker to enable 'EPSS 0.4%CVE-2025-30733MEDIUMVulnerability in the RDBMS Listener component of Oracle Database Server. Supported versions that are affected are 19.3-19.26, 21.3-21.17 anEPSS 0.4%CVE-2026-53958HIGH4gaBoards: SSO Pre-Account Takeover / Hijacking via Mass AssignmentEPSS 0.4%CVE-2026-19806HIGHSupport Genix <= 1.4.52 - Authenticated (Subscriber+) Authentication Bypass to Administrator Account Takeover via 'p' Parameter Forged Guest TokenEPSS 0.4%CVE-2026-12196HIGHHestiaCP Admin TakeoverEPSS 0.4%CVE-2026-12341HIGHSailPoint IdentityIQ Improper Bearer Token Validation VulnerabilityEPSS 0.4%CVE-2023-52540HIGHVulnerability of improper authentication in the Iaware module. Impact: Successful exploitation of this vulnerability will affect availabilitEPSS 0.4%CVE-2026-39976HIGHLaravel Passport's TokenGuard Authenticates Unrelated User for Client Credentials TokensEPSS 0.4%CVE-2026-40910MEDIUMfrp: Authentication bypass in frp HTTP vhost routing when routeByHTTPUser is used for access controlEPSS 0.4%CVE-2022-41738HIGHIBM Spectrum Scale security bypassEPSS 0.4%CVE-2025-25227HIGH[20250402] - Joomla Core - MFA Authentication BypassEPSS 0.4%CVE-2018-10597—IntelliVue Patient Monitors MP Series (including MP2/X2/MP30/MP50/MP70/NP90/MX700/800) Rev B-M, IntelliVue Patient Monitors MX (MX400-550) REPSS 0.4%CVE-2022-39019MEDIUMBroken access controls on PDFtron WebviewerUI in M-Files HubshareEPSS 0.4%CVE-2026-8293HIGHReally Simple Security < 9.5.10.1 - Authentication Bypass via Two-Factor OTP SkipEPSS 0.4%CVE-2024-42172MEDIUMHCL MyXalytics is affected by broken authenticationEPSS 0.4%CVE-2026-61225HIGHVulnerability in the Oracle Communications Converged Application Server product of Oracle Communications (component: Core). Supported versiEPSS 0.4%