Fallos del tipo CWE-287

2449 resultados

Autenticação inadequada ou ausente

A aplicação não valida ou valida de forma insuficiente a identidade de quem tenta acessá-la. Quando um usuário diz ser quem é, o sistema acredita sem verificar corretamente, permitindo que atacantes se façam passar por outros usuários ou contas legítimas.

Ejemplo

Um sistema que aceita login apenas com nome de usuário, sem senha. Ou uma API que confia no header 'User-ID' enviado pelo cliente sem validar se aquele usuário realmente existe ou tem sessão ativa. Um atacante simplesmente altera o header e acessa dados de outra conta.

Cómo mitigar

Implemente autenticação robusta: exija múltiplos fatores (senha forte + MFA), valide credenciais contra base de dados segura, use sessões com token assinado e com expiração, nunca confie em dados enviados pelo cliente como prova de identidade. Revise regularmente logs de acesso para detectar abusos.

CVE-2026-28787HIGHOneUptime has WebAuthn 2FA bypass: server accepts client-supplied challenge instead of server-stored value, allowing credential replayEPSS 0.4%CVE-2026-34917MEDIUMLow‑privileged session IDs generated for the web admin console could be reused in the XML‑RPC API, whose authentication is normally restrictEPSS 0.4%CVE-2023-35154HIGHKnowage-Server vulnerable to account validation bypassEPSS 0.4%CVE-2024-0879MEDIUMAuthentication bypass in vector-admin domain restrictionEPSS 0.4%CVE-2024-39830HIGHTiming attack during remote cluster token comparison when shared channels are enabledEPSS 0.4%CVE-2024-6078HIGHRockwell Automation Authentication Bypass Vulnerability in DataMosaix™EPSS 0.4%CVE-2025-47790MEDIUMNextcloud Server doesn't request second factor after session timeoutEPSS 0.4%CVE-2023-4985MEDIUMSupcon InPlant SCADA Project.xml improper authenticationEPSS 0.4%CVE-2020-3388HIGHCisco SD-WAN vManage Software Command Injection VulnerabilityEPSS 0.4%CVE-2026-56312MEDIUMCapgo - Account Creation Before CAPTCHA Validation in accept_invitation EndpointEPSS 0.4%CVE-2026-2812MEDIUMImproper Authentication issue in ArcGIS ServerEPSS 0.4%CVE-2026-53591HIGHFreeScout Vulnerable to Unauthenticated Conversation Thread Injection via HMAC Length Bypass in FetchEmailsEPSS 0.4%CVE-2025-67791CRITICALAn issue was discovered in DriveLock 24.1 through 24.1.*, 24.2 through 24.2.*, and 25.1 through 25.1.*. An incomplete configuration (agent aEPSS 0.4%CVE-2024-23251MEDIUMAn authentication issue was addressed with improved state management. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadEPSS 0.4%CVE-2023-51511MEDIUMWordPress Booster Elite for WooCommerce plugin < 7.1.3 - Authenticated Production Creation/Modification VulnerabilityEPSS 0.4%CVE-2024-5201HIGHDimensions RM - Privilege EscalationEPSS 0.4%CVE-2026-18052HIGHManageWP Worker < 4.9.37 - Unauthenticated Authentication Bypass via Unsigned Auto-Login ParametersEPSS 0.4%CVE-2026-33042MEDIUMParse Server affected by empty authData bypassing credential requirement on signupEPSS 0.4%CVE-2026-33473MEDIUMVikunja has TOTP Reuse During Validity WindowEPSS 0.4%CVE-2025-6524LOW70mai 1S Video Services improper authenticationEPSS 0.4%