Fallos del tipo CWE-287

2450 resultados

Autenticação inadequada ou ausente

A aplicação não valida ou valida de forma insuficiente a identidade de quem tenta acessá-la. Quando um usuário diz ser quem é, o sistema acredita sem verificar corretamente, permitindo que atacantes se façam passar por outros usuários ou contas legítimas.

Ejemplo

Um sistema que aceita login apenas com nome de usuário, sem senha. Ou uma API que confia no header 'User-ID' enviado pelo cliente sem validar se aquele usuário realmente existe ou tem sessão ativa. Um atacante simplesmente altera o header e acessa dados de outra conta.

Cómo mitigar

Implemente autenticação robusta: exija múltiplos fatores (senha forte + MFA), valide credenciais contra base de dados segura, use sessões com token assinado e com expiração, nunca confie em dados enviados pelo cliente como prova de identidade. Revise regularmente logs de acesso para detectar abusos.

CVE-2026-14830HIGHFlxWoo < 3.1.1 - Unauthenticated Payment BypassEPSS 0.4%CVE-2022-25667HIGHInformation disclosure in kernel due to improper handling of ICMP requests in Snapdragon Wired Infrastructure and NetworkingEPSS 0.4%CVE-2025-31122CRITICALscratch-coding-hut.github.io Login Links Generation vulnerabilityEPSS 0.4%CVE-2026-75907HIGHCVE-2026-75907EPSS 0.4%CVE-2024-42164MEDIUMDisabling MFA without AuthenticationEPSS 0.4%CVE-2026-84458CRITICALZammad: Account takeover via unverified email matching during SSO auto-linkEPSS 0.4%CVE-2026-61067HIGHVulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that EPSS 0.4%CVE-2023-39531MEDIUMSentry vulnerable to incorrect credential validation on OAuth token requestsEPSS 0.4%CVE-2025-31478HIGHZulip Authentication Backend Configuration BypassEPSS 0.4%CVE-2025-41064CRITICALIncorrect authentication in GTT´s group OpenSIACEPSS 0.4%CVE-2025-10293HIGHKeyy Two Factor Authentication (like Clef) <= 1.2.3 - Authenticated (Subscriber+) Privilege Escalation via Account TakeoverEPSS 0.4%CVE-2025-46641MEDIUMDell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 8.4 through 8.5 contain an improper authEPSS 0.4%CVE-2018-0362—A vulnerability in BIOS authentication management of Cisco 5000 Series Enterprise Network Compute System and Cisco Unified Computing (UCS) EEPSS 0.4%CVE-2023-44096— Vulnerability of brute-force attacks on the device authentication module.Successful exploitation of this vulnerability may affect service cEPSS 0.4%CVE-2026-10611HIGHOTP bypass via plugin-based LDAP authentication in MISP when LDAP mixed authentication is enabledEPSS 0.4%CVE-2026-34736MEDIUMOpen edX Platform: Account Activation Bypass via activation_key Exposure in REST APIEPSS 0.4%CVE-2026-60615HIGHVulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Security). The supported version tEPSS 0.4%CVE-2026-54320HIGHDaytona: Cross-tenant organization takeover via invitation acceptance with an unverified emailEPSS 0.4%CVE-2026-44460HIGHFileRise: TOTP Bypass via Setup Endpoint Disclosing Existing SecretEPSS 0.4%CVE-2025-69273HIGHSpectrum broken authenticationEPSS 0.4%