Falhas do tipo CWE-287

2.450 resultados

Autenticação Insuficiente ou Ausente

Quando um usuário ou sistema afirma ser quem diz que é, a aplicação não valida (ou valida mal) essa identidade antes de conceder acesso. Isso permite que um atacante se passe por outra pessoa sem fornecer credenciais válidas, obtendo privilégios indevidos.

Exemplo

Um sistema que aceita login apenas verificando um campo de e-mail na sessão (sem senha), ou uma API que confia em um identificador de usuário enviado no header HTTP sem validar um token assinado. Um atacante simplesmente muda o valor e acessa dados de terceiros.

Como mitigar

Implemente autenticação robusta: exija senha forte + MFA quando possível, valide tokens com assinatura criptográfica, revoque sessões expiradas, e nunca confie em dados controlados pelo cliente. Teste autenticação em cada endpoint crítico.

CVE-2025-49012MEDIUMHimmelblau's Name-Based Group Matching in `pam_allow_groups` Leads to Potential Security BypassEPSS 0.3%CVE-2025-67507HIGHFilament's multi-factor authentication (app) recovery codes can be used multiple timesEPSS 0.3%CVE-2026-49502HIGHDell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Authentication vulnerability. An unauthenticated attacker with aEPSS 0.3%CVE-2024-51997HIGHThe Attestation Results Token can be arbitrarily modified without being detected in TrusteeEPSS 0.3%CVE-2024-5798LOWVault Incorrectly Validated JSON Web Tokens (JWT) Audience ClaimsEPSS 0.3%CVE-2024-58363MEDIUMSurrealDB before 1.5.4 Authentication Bypass via Database SwitchEPSS 0.3%CVE-2026-14568MEDIUMWP User Frontend < 4.3.8 - Unauthenticated Author-less Attachment DeletionEPSS 0.3%CVE-2026-18056HIGHHivePress Authentication <= 1.1.4 - Unauthenticated Authentication Bypass via 'access_token' Parameter to Facebook AuthenticatorEPSS 0.3%CVE-2022-4001HIGHAn authentication bypass vulnerability could allow an attacker to access API functions without authentication.EPSS 0.3%CVE-2025-65781HIGHAn issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Attachment upload API treats the AEPSS 0.3%CVE-2025-64423HIGHCoolify has a Privilege Escalation - low privileged users can see and use admin invitation linksEPSS 0.3%CVE-2026-89080HIGHReally Simple Security < 9.8.1 - Unauthenticated 2FA Bypass via Email Provider State DemotionEPSS 0.3%CVE-2026-63238MEDIUMAuthentication bypass vulnerabilityEPSS 0.3%CVE-2024-0130HIGHNVIDIA UFM Enterprise, UFM Appliance, and UFM CyberAI contain a vulnerability where an attacker can cause an improper authentication issue bEPSS 0.3%CVE-2023-42554MEDIUMImproper Authentication vulnerabiity in Samsung Pass prior to version 4.3.00.17 allows physical attackers to bypass authentication.EPSS 0.3%CVE-2025-24292MEDIUMA misconfigured query in UniFi Network (v9.1.120 and earlier) could allow users to authenticate to Enterprise WiFi or VPN Server (l2tp and OEPSS 0.3%CVE-2025-65127MEDIUMA lack of session validation in the web API component of Shenzhen Zhibotong Electronics ZBT WE2001 23.09.27 allows remote unauthenticated atEPSS 0.3%CVE-2025-7699HIGHAn improper access control vulnerability was found in the EZ Sync Manager of ADMEPSS 0.3%CVE-2026-18221HIGHIBM i is Affected By Improper Authorization and Authentication Vulnerabilities in DDM / DRDA [, ]EPSS 0.3%CVE-2026-53561HIGHApache Hive: Unauthenticated authentication bypass in HiveServer2 HTTP SAML bearer-token validation allows impersonation of any Hive userEPSS 0.3%