Falhas do tipo CWE-1390

95 resultados

Autenticação fraca

Fraqueza em que o mecanismo de autenticação não valida suficientemente a identidade do usuário, aceitando credenciais insuficientes, previsíveis ou sem proteção adequada. Um atacante consegue contornar a autenticação com pouco esforço, obtendo acesso não autorizado ao sistema.

Exemplo

Um app que permite login apenas com username (sem senha), ou um serviço que usa tokens de autenticação hardcoded que nunca expiram, ou ainda uma API que valida acesso só verificando se um campo numérico simples está presente na requisição.

Como mitigar

Implemente autenticação multifatorial, use hashing forte para senhas (bcrypt, Argon2), enforce expiração de tokens, valide credenciais contra armazenamento seguro sem padrões previsíveis, e aplique rate limiting em tentativas de login. Considere OAuth 2.0 ou SAML para delegação segura.

CVE-2024-47397HIGHWeak authentication issue exists in AE1021 firmware versions 2.0.10 and earlier and AE1021PE firmware versions 2.0.10 and earlier. If this vEPSS 0.4%CVE-2025-30468MEDIUMThis issue was addressed through improved state management. This issue is fixed in iOS 26 and iPadOS 26. Private Browsing tabs may be accessEPSS 0.4%CVE-2024-29038MEDIUMtpm2 does not detect if quote was not generated by TPMEPSS 0.4%CVE-2025-1293HIGHHashiCorp Hermes Improperly Validates AWS ALB JWTs, which May Lead to Authentication BypassEPSS 0.3%CVE-2025-47479MEDIUMWordPress WP Compress plugin <= 6.30.30 - Broken Authentication VulnerabilityEPSS 0.3%CVE-2026-4924HIGHImproper authentication in the two-factor authentication (2FA) feature in Devolutions Server 2026.1.11 and earlier allows a remote attackeEPSS 0.3%CVE-2024-32119MEDIUMAn improper authentication vulnerability [CWE-287] in Fortinet FortiClientEMS version 7.4.0 and before 7.2.4 allows an unauthenticated attacEPSS 0.3%CVE-2026-44476MEDIUMDoorkeeper OpenID Connect: Dynamic Client Registration feature creates public clients with client_secretEPSS 0.3%CVE-2026-59135MEDIUMMicrosoft Windows Search Component Information Disclosure VulnerabilityEPSS 0.3%CVE-2026-1693MEDIUMUse of vulnerable Resource Owner Password Credentials flowEPSS 0.3%CVE-2026-68067CRITICALMira Hormone Monitor, Mira Android App Weak AuthenticationEPSS 0.3%CVE-2025-0605MEDIUMWeak Authentication in GitLabEPSS 0.3%CVE-2026-0274HIGHCortex XSOAR: Improper Validation of Credentials in CommvaultSecurityIQ integrationEPSS 0.3%CVE-2025-70994HIGHYadea T5 Electric Bicycles (models manufactured in/after 2024) have a weak authentication mechanism in their keyless entry system. The systeEPSS 0.3%CVE-2026-40417HIGHMicrosoft Dynamics 365 Business Central Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-57352MEDIUMWordPress ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce plugin <= 2.2.0 - Broken Authentication vulnerabilityEPSS 0.3%CVE-2026-4828HIGHImproper authentication in the OAuth login functionality in Devolutions Server 2026.1.11 and earlier allows a remote attacker with valid creEPSS 0.3%CVE-2024-5891MEDIUMQuay: unauthorized user may authenticate via oauth application tokenEPSS 0.2%CVE-2025-32885MEDIUMAn issue was discovered on goTenna v1 devices with app 5.5.3 and firmware 0.25.5. The app there makes it possible to inject any custom messaEPSS 0.2%CVE-2026-32497MEDIUMWordPress User Verification plugin <= 2.0.45 - Email Verification Bypass vulnerabilityEPSS 0.2%