Fallos del tipo CWE-287

2449 resultados

Autenticação inadequada ou ausente

A aplicação não valida ou valida de forma insuficiente a identidade de quem tenta acessá-la. Quando um usuário diz ser quem é, o sistema acredita sem verificar corretamente, permitindo que atacantes se façam passar por outros usuários ou contas legítimas.

Ejemplo

Um sistema que aceita login apenas com nome de usuário, sem senha. Ou uma API que confia no header 'User-ID' enviado pelo cliente sem validar se aquele usuário realmente existe ou tem sessão ativa. Um atacante simplesmente altera o header e acessa dados de outra conta.

Cómo mitigar

Implemente autenticação robusta: exija múltiplos fatores (senha forte + MFA), valide credenciais contra base de dados segura, use sessões com token assinado e com expiração, nunca confie em dados enviados pelo cliente como prova de identidade. Revise regularmente logs de acesso para detectar abusos.

CVE-2026-80192HIGHbetter-auth SSO before 1.6.27 Domain Ownership Authentication BypassEPSS 0.4%CVE-2026-44547CRITICALChurchCRM: Incomplete fix for CVE-2026-40582: public API login still bypasses 2FA and account lockout in ChurchCRM 7.2.2EPSS 0.4%CVE-2022-20662MEDIUMCisco Duo for macOS Authentication Bypass VulnerabilityEPSS 0.4%CVE-2026-16269MEDIUMNewsletters < 4.16 - Unauthenticated API Authentication Bypass via Type JugglingEPSS 0.4%CVE-2026-48896HIGHJoomla! Core - [20260511] - MFA Authentication BypassEPSS 0.4%CVE-2024-6107CRITICALDue to insufficient verification, an attacker could use a malicious client to bypass authentication checks and run RPC commands in a region.EPSS 0.4%CVE-2026-46705MEDIUMrussh server userauth state is not reset when authentication principal changesEPSS 0.4%CVE-2025-69822HIGHAn issue in Atomberg Atomberg Erica Smart Fan Firmware Version: V1.0.36 allows an attacker to obtain sensitive information and escalate privEPSS 0.4%CVE-2026-45283MEDIUMNextcloud: Files Lock app allows users to lock and unlock files of other usersEPSS 0.4%CVE-2024-5174MEDIUMBroken Authentication in GliffyEPSS 0.4%CVE-2023-33054CRITICALImproper Authentication in GPS HLOS DriverEPSS 0.4%CVE-2025-69197MEDIUMPterodactyl TOTPs can be reused during validity windowEPSS 0.4%CVE-2026-16257HIGHArvow AI SEO Writer < 1.5.4 - Unauthenticated Arbitrary Post Creation via Webhook Secret Type-JugglingEPSS 0.4%CVE-2025-25504MEDIUMAn issue in the /usr/local/bin/jncs.sh script of Gefen WebFWC (In AV over IP products) v1.85h, v1.86v, and v1.70 allows attackers with netwoEPSS 0.4%CVE-2025-45583CRITICALIncorrect access control in the FTP protocol of Audi UTR 2.0 Universal Traffic Recorder 2.0 allows attackers to authenticate into the servicEPSS 0.4%CVE-2026-11703MEDIUMMissing SNI/ALPN binding on stateful (session-ID) TLS session resumptionEPSS 0.4%CVE-2026-14830HIGHFlxWoo < 3.1.1 - Unauthenticated Payment BypassEPSS 0.4%CVE-2025-46573HIGHpassport-wsfed-saml2 Has SAML Authentication Bypass via Attribute SmugglingEPSS 0.4%CVE-2023-25556HIGH A CWE-287: Improper Authentication vulnerability exists that could allow a device to be compromised when a key of less than seven digits isEPSS 0.4%CVE-2022-32935MEDIUMA lock screen issue was addressed with improved state management. This issue is fixed in iOS 15.7.1 and iPadOS 15.7.1, iOS 16.1 and iPadOS 1EPSS 0.4%