Fallos del tipo CWE-290

607 resultados

Autenticação inadequada sujeita a falsificação de identidade

Ocorre quando o mecanismo de autenticação é implementado de forma fraca ou incompleta, permitindo que um atacante se faça passar por outro usuário ou sistema sem precisar das credenciais legítimas. O risco é grave: qualquer um pode ganhar acesso não autorizado simplesmente contornando ou falsificando a identidade.

Ejemplo

Um app que autentica usuários apenas verificando um header HTTP customizado (tipo 'X-User-ID: 123') sem validação criptográfica real. Um atacante muda esse header para 'X-User-ID: admin' e consegue acesso à conta administrativa. Ou um serviço que aceita requisições apenas porque vêm de um IP específico, sem verificar certificados ou assinaturas.

Cómo mitigar

Use protocolos de autenticação estabelecidos (OAuth 2.0, JWT com assinatura, SAML) em vez de inventar o seu. Sempre valide credenciais no servidor com mecanismos criptográficos (hash, assinatura digital, certificados). Nunca confie em headers HTTP, IPs ou tokens não assinados como prova única de identidade.

CVE-2025-36753HIGHSWD Interface Open on Growatt ShineLan-XEPSS 0.3%CVE-2023-4566HIGHVulnerability of trust relationships being inaccurate in distributed scenarios. Successful exploitation of this vulnerability may affect serEPSS 0.3%CVE-2025-32275MEDIUMWordPress Survey Maker plugin <= 5.1.6.3 - Bypass vulnerabilityEPSS 0.3%CVE-2026-84479CRITICALWWBN AVideo Authentication Bypass via User-Agent HeaderEPSS 0.3%CVE-2025-59802HIGHFoxit PDF Editor and Reader before 2025.2.1 allow signature spoofing via OCG. When Optional Content Groups (OCG) are supported, the state prEPSS 0.3%CVE-2026-42662MEDIUMWordPress Event Tickets plugin <= 5.27.5 - Bypass Vulnerability vulnerabilityEPSS 0.3%CVE-2025-56608MEDIUMThe SourceCodester Android application "Corona Virus Tracker App India" 1.0 uses MD5 for digest authentication in `OkHttpClientWrapper.java`EPSS 0.3%CVE-2022-32747HIGHA CWE-290: Authentication Bypass by Spoofing vulnerability exists that could cause legitimate users to be locked out of devices or facilitatEPSS 0.3%CVE-2026-56357MEDIUMn8n - Webhook Forgery via Missing HMAC-SHA256 Signature Verification in GitHub Webhook TriggerEPSS 0.3%CVE-2026-56360MEDIUMn8n - Webhook Forgery via Unsigned POST Requests in ZendeskTriggerEPSS 0.3%CVE-2026-35656MEDIUMOpenClaw < 2026.3.22 - XFF Loopback Spoofing Bypass in Canvas Authentication and Rate LimiterEPSS 0.3%CVE-2026-18677MEDIUMKong Mesh: a dataplane token without a workload binding can claim any workload's SPIFFE identityEPSS 0.3%CVE-2026-14199HIGHSession takeover via Auth Proxy cache key collisionEPSS 0.3%CVE-2026-2800CRITICALSpoofing issue in the WebAuthn component in Firefox for AndroidEPSS 0.3%CVE-2026-18065MEDIUMIBM i is Affected By Multiple Vulnerabilities in Navigator for i and Digital Certificate Manager for i.EPSS 0.3%CVE-2026-64665HIGHStatamic: Account takeover via OAuth email matching without email-verification checkEPSS 0.3%CVE-2024-8273HIGHAuthentication Bypass by Spoofing vulnerability in HYPR Server allows Identity Spoofing.This issue affects Server: before 10.1.EPSS 0.3%CVE-2025-11843HIGHTherefore™ Online and Therefore™ On-Premises contains an account impersonation issue, which could potentially allow the attacker to access all the stored dataEPSS 0.3%CVE-2025-32227MEDIUMWordPress Asgaros Forum plugin <= 3.0.0 - File Upload Numbers Bypass vulnerabilityEPSS 0.3%CVE-2025-12430HIGHObject lifecycle issue in Media in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to perform UI spoofing via a crafted HTML EPSS 0.3%