Fallos del tipo CWE-287

2449 resultados

Autenticação inadequada ou ausente

A aplicação não valida ou valida de forma insuficiente a identidade de quem tenta acessá-la. Quando um usuário diz ser quem é, o sistema acredita sem verificar corretamente, permitindo que atacantes se façam passar por outros usuários ou contas legítimas.

Ejemplo

Um sistema que aceita login apenas com nome de usuário, sem senha. Ou uma API que confia no header 'User-ID' enviado pelo cliente sem validar se aquele usuário realmente existe ou tem sessão ativa. Um atacante simplesmente altera o header e acessa dados de outra conta.

Cómo mitigar

Implemente autenticação robusta: exija múltiplos fatores (senha forte + MFA), valide credenciais contra base de dados segura, use sessões com token assinado e com expiração, nunca confie em dados enviados pelo cliente como prova de identidade. Revise regularmente logs de acesso para detectar abusos.

CVE-2026-28606CRITICALIn handleBondStateChanged of AdapterService.java, there is a possible way to skip pairing due to a logic error in the code. This could lead EPSS 0.4%CVE-2025-9063HIGHRockwell Automation PanelView Plus 7 Performance Series B Authentication BypassEPSS 0.4%CVE-2026-49447MEDIUMCosmos-Server's constellation public-devices endpoint accepts arbitrary bearer tokensEPSS 0.4%CVE-2025-51451CRITICALIn TOTOLINK EX1200T firmware 4.1.2cu.5215, an attacker can bypass login by sending a specific request through formLoginAuth.htm.EPSS 0.4%CVE-2026-14836HIGHLogin/Signup Popup < 3.2.5 - Unauthenticated Account Takeover via Password Reset Rate Limit BypassEPSS 0.4%CVE-2026-12281HIGHShibboleth < 2.5.4 - Unauthenticated Administrator Account Creation via Identity Header SpoofingEPSS 0.4%CVE-2026-18469HIGHLogin & Register Forms < 4.0.2 - Unauthenticated Account Takeover via Password Reset Code Brute ForceEPSS 0.4%CVE-2026-14309HIGHChat On Desk < 1.0.9 - Unauthenticated Account Takeover via Password Reset OTP BypassEPSS 0.4%CVE-2026-16030HIGHMStore API < 4.21.0 - Unauthenticated Account Takeover via Firebase Phone AuthenticationEPSS 0.4%CVE-2026-97231MEDIUMvolotat Anagnorisis Socket.IO Connect app.py missing authenticationEPSS 0.4%CVE-2026-76688HIGHAuthentication Bypass Vulnerabilities in the Web-Based Management Interface of EdgeConnect SD-WAN OrchestratorEPSS 0.4%CVE-2026-1743LOWDJI Mavic Mini/Air/Spark/Mini SE Enhanced Wi-Fi Pairing authentication replayEPSS 0.4%CVE-2026-82183HIGHOAuth Single Sign On 6.25.0 - 7.0.0 - Unauthenticated Account Takeover via Unverified Steam OpenID AssertionEPSS 0.4%CVE-2026-14300HIGHminiOrange Social Login and Register < 7.8.0 - Unauthenticated Account TakeoverEPSS 0.4%CVE-2026-12585HIGHAbandoned Cart Lite for WooCommerce < 6.8.2 - Unauthenticated Account Takeover via Malleable Recovery-Link TokenEPSS 0.4%CVE-2026-18468HIGHLogin & Register Forms < 4.0.2 - Unauthenticated Account Takeover via Password Reset Verification State Keyed on a Client-Supplied Address HeaderEPSS 0.4%CVE-2026-58066CRITICALRocket.Chat's SAML SSO before versions 8.7.0, 8.6.1, 8.5.2, 8.4.5, 8.3.7, 8.2.7, 8.1.7, 8.0.8, and 7.10.14 verified XML signatures but did nEPSS 0.4%CVE-2025-21618HIGHNiceGUI On Air authentication issueEPSS 0.4%CVE-2026-28787HIGHOneUptime has WebAuthn 2FA bypass: server accepts client-supplied challenge instead of server-stored value, allowing credential replayEPSS 0.4%CVE-2026-0842MEDIUMFlycatcher Toys smART Sketcher Bluetooth Low Energy missing authenticationEPSS 0.4%