Falhas do tipo CWE-1390

95 resultados

Autenticação fraca

Fraqueza em que o mecanismo de autenticação não valida suficientemente a identidade do usuário, aceitando credenciais insuficientes, previsíveis ou sem proteção adequada. Um atacante consegue contornar a autenticação com pouco esforço, obtendo acesso não autorizado ao sistema.

Exemplo

Um app que permite login apenas com username (sem senha), ou um serviço que usa tokens de autenticação hardcoded que nunca expiram, ou ainda uma API que valida acesso só verificando se um campo numérico simples está presente na requisição.

Como mitigar

Implemente autenticação multifatorial, use hashing forte para senhas (bcrypt, Argon2), enforce expiração de tokens, valide credenciais contra armazenamento seguro sem padrões previsíveis, e aplique rate limiting em tentativas de login. Considere OAuth 2.0 ou SAML para delegação segura.

CVE-2026-44237HIGHFreePBX: Authenticated Access can lead to Subsequent OAuth2 Authentication Bypass in API ModuleEPSS 0.2%CVE-2025-62844MEDIUMQuRouterEPSS 0.2%CVE-2026-27478CRITICALUnity Catalog has a JWT Issuer Validation Bypass Allows Complete User ImpersonationEPSS 0.2%CVE-2024-52541HIGHDell Client Platform BIOS contains a Weak Authentication vulnerability. A high privileged attacker with local access could potentially exploEPSS 0.2%CVE-2025-11084HIGHFactoryTalk® DataMosaix™ Private Cloud – Authentication BypassEPSS 0.1%CVE-2024-41722MEDIUMgoTenna Pro ATAK Plugin Weak AuthenticationEPSS 0.1%CVE-2024-6580LOW/n software IPWorks SSH insufficient file access verificationEPSS 0.1%CVE-2025-29991LOWYubico YubiKey 5.4.1 through 5.7.3 before 5.7.4 has an incorrect FIDO CTAP PIN/UV Auth Protocol Two implementation. It uses the signature leEPSS 0.1%CVE-2024-47127MEDIUMWeak Authentication in goTenna ProEPSS 0.1%CVE-2026-10714HIGHRockwell Automation FactoryTalk® Services Platform FTSP - Weak Authentication via JWT Validation BypassEPSS 0.1%CVE-2024-45551MEDIUMWeak Authentication in HLOSEPSS 0.1%CVE-2026-49323MEDIUMIndian Scout Bobber 2025 WCM-to-ECM weak authenticationEPSS 0.1%CVE-2026-49322MEDIUMIndian Scout Bobber 2025 Infotainment-to-WCM weak authentication allows recovery of user PIN from observed exchangeEPSS 0.1%CVE-2025-15595MEDIUMPrivilege escalation via dll hijacking in Inno SetupEPSS 0.1%CVE-2026-94455HIGHUnauthenticated /enterprise/create-user mints lifetime top-tier organizations and discloses their API keyEPSS