Fallos del tipo CWE-290

607 resultados

Autenticação inadequada sujeita a falsificação de identidade

Ocorre quando o mecanismo de autenticação é implementado de forma fraca ou incompleta, permitindo que um atacante se faça passar por outro usuário ou sistema sem precisar das credenciais legítimas. O risco é grave: qualquer um pode ganhar acesso não autorizado simplesmente contornando ou falsificando a identidade.

Ejemplo

Um app que autentica usuários apenas verificando um header HTTP customizado (tipo 'X-User-ID: 123') sem validação criptográfica real. Um atacante muda esse header para 'X-User-ID: admin' e consegue acesso à conta administrativa. Ou um serviço que aceita requisições apenas porque vêm de um IP específico, sem verificar certificados ou assinaturas.

Cómo mitigar

Use protocolos de autenticação estabelecidos (OAuth 2.0, JWT com assinatura, SAML) em vez de inventar o seu. Sempre valide credenciais no servidor com mecanismos criptográficos (hash, assinatura digital, certificados). Nunca confie em headers HTTP, IPs ou tokens não assinados como prova única de identidade.

CVE-2026-16101HIGHforced re-pairing with already bonded deviceEPSS 0.2%CVE-2026-33223MEDIUMNATS Server: Incomplete Stripping of Nats-Request-Info Header Allows Identity SpoofingEPSS 0.2%CVE-2026-19291HIGHBluetooth re-pairing can use a lower security level than previousEPSS 0.2%CVE-2026-5792MEDIUMAuthentication Bypass in Hedef Media's Related Marketing Cloud (RMC)EPSS 0.2%CVE-2026-28480MEDIUMOpenClaw < 2026.2.14 - Identity Spoofing via Mutable Username in Telegram Allowlist AuthorizationEPSS 0.2%CVE-2026-89327LOWFluentBoards < 2.0.15 - Board Member+ Comment Author Spoofing via 'comment_by' ParameterEPSS 0.2%CVE-2026-53823HIGHOpenClaw < 2026.5.3 - Privilege Escalation via Mutable Slack Display Names in allowFromEPSS 0.2%CVE-2026-54763HIGHTraefik: headerField underscore-variant identity spoofing in BasicAuth / DigestAuth / ForwardAuthEPSS 0.2%CVE-2025-48906HIGHAuthentication bypass vulnerability in the DSoftBus module Impact: Successful exploitation of this vulnerability may affect availability.EPSS 0.2%CVE-2026-88879MEDIUMTraefik before v2.11.56 Identity Spoofing via Header AliasEPSS 0.2%CVE-2026-72809HIGHSiYuan before v3.7.4 Authentication Bypass via Localhost TrustEPSS 0.2%CVE-2026-66674MEDIUMWordPress Simple Cloudflare Turnstile plugin <= 1.42.1 - Captcha Bypass vulnerabilityEPSS 0.2%CVE-2026-64797HIGHJoomla Extension - regularlabs.com - IP spoofing vulnerability in IP login extensionEPSS 0.2%CVE-2026-8676HIGHAn attacker is able to downgrade the security of a Bluetooth LE connection by deleting an existing bond, spoofing the bonded device and creaEPSS 0.2%CVE-2026-93511MEDIUMPremium Packages < 7.2.1 - Unauthenticated PayPal Webhook Signature Verification BypassEPSS 0.2%CVE-2025-66270MEDIUMThe KDE Connect protocol 8 before 2025-11-28 does not correlate device IDs across two packets. This affects KDE Connect before 25.12 on deskEPSS 0.2%CVE-2026-84766MEDIUMWordPress FluentBooking Pro plugin <= 2.2.1 - Bypass Vulnerability vulnerabilityEPSS 0.2%CVE-2025-36119HIGHIBM i authentication bypassEPSS 0.2%CVE-2024-39341MEDIUMEntrust Instant Financial Issuance (On Premise) Software (formerly known as Cardwizard) 6.10.0, 6.9.0, 6.9.1, 6.9.2, and 6.8.x and earlier lEPSS 0.2%CVE-2024-36557MEDIUMThe device ID is based on IMEI in Forever KidsWatch Call Me KW50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h and Forever KidsWatch CallEPSS 0.2%