Fallos del tipo CWE-287

2450 resultados

Autenticação inadequada ou ausente

A aplicação não valida ou valida de forma insuficiente a identidade de quem tenta acessá-la. Quando um usuário diz ser quem é, o sistema acredita sem verificar corretamente, permitindo que atacantes se façam passar por outros usuários ou contas legítimas.

Ejemplo

Um sistema que aceita login apenas com nome de usuário, sem senha. Ou uma API que confia no header 'User-ID' enviado pelo cliente sem validar se aquele usuário realmente existe ou tem sessão ativa. Um atacante simplesmente altera o header e acessa dados de outra conta.

Cómo mitigar

Implemente autenticação robusta: exija múltiplos fatores (senha forte + MFA), valide credenciais contra base de dados segura, use sessões com token assinado e com expiração, nunca confie em dados enviados pelo cliente como prova de identidade. Revise regularmente logs de acesso para detectar abusos.

CVE-2025-14716MEDIUMUnauthorized access to informationEPSS 0.4%CVE-2026-58029MEDIUMFull Account Takeover from BotPasswords and OAuth via action=changeauthenticationdataEPSS 0.4%CVE-2022-40966HIGHAuthentication bypass vulnerability in multiple Buffalo network devices allows a network-adjacent attacker to bypass authentication and acceEPSS 0.4%CVE-2025-1231MEDIUMImproper password reset in PAM Module in Devolutions Server 2024.3.10.0 and earlier allows an authenticated user to reuse the oracle user paEPSS 0.4%CVE-2025-66174MEDIUMThere is an improper authentication vulnerability in some Hikvision DVR products. Due to the improper implementation of authentication for tEPSS 0.4%CVE-2025-24949MEDIUMIn JotUrl 2.0, is possible to bypass security requirements during the password change process.EPSS 0.3%CVE-2024-57491HIGHAuthentication Bypass vulnerability in jobx up to v1.0.1-RELEASE allows an attacker can exploit this vulnerability to access sensitive API wEPSS 0.3%CVE-2025-14908MEDIUMJeecgBoot Multi-Tenant Management SysTenantController.java improper authenticationEPSS 0.3%CVE-2023-0228HIGHImproper authentication vulnerability in S+ OperationsEPSS 0.3%CVE-2023-0863HIGHAuthentication to access the AC wallbox via its Bluetooth Low Energy (BLE) channel can be bypassed, EPSS 0.3%CVE-2025-11192HIGHFabric Engine (VOSS) AutoSense Authentication BypassEPSS 0.3%CVE-2026-72917MEDIUMAnythingLLM: Password recovery accepts one recovery code twice after whitespace normalizationEPSS 0.3%CVE-2026-30851HIGHCaddy forward_auth copy_headers Does Not Strip Client-Supplied Headers, Allowing Identity Injection and Privilege EscalationEPSS 0.3%CVE-2026-32804HIGHDell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Authentication vulnerability. An unauthenticated attacker with aEPSS 0.3%CVE-2026-78308CRITICALAuthentication Bypass in DIAEnergieEPSS 0.3%CVE-2022-30421HIGHImproper Authentication vulnerability in Toshiba Storage Security Software V1.2.0.7413 is that allows for sensitive information to be obtainEPSS 0.3%CVE-2026-73840MEDIUMOpenChoreo: Unauthenticated build/workflow trigger via git-provider confusion (webhook signature bypass)EPSS 0.3%CVE-2025-49012MEDIUMHimmelblau's Name-Based Group Matching in `pam_allow_groups` Leads to Potential Security BypassEPSS 0.3%CVE-2026-6729MEDIUMHKUDS OpenHarness Session Key Collision Privilege EscalationEPSS 0.3%CVE-2024-23792MEDIUMInsufficient access controlEPSS 0.3%