Falhas do tipo CWE-287

2.451 resultados

Autenticação Insuficiente ou Ausente

Quando um usuário ou sistema afirma ser quem diz que é, a aplicação não valida (ou valida mal) essa identidade antes de conceder acesso. Isso permite que um atacante se passe por outra pessoa sem fornecer credenciais válidas, obtendo privilégios indevidos.

Exemplo

Um sistema que aceita login apenas verificando um campo de e-mail na sessão (sem senha), ou uma API que confia em um identificador de usuário enviado no header HTTP sem validar um token assinado. Um atacante simplesmente muda o valor e acessa dados de terceiros.

Como mitigar

Implemente autenticação robusta: exija senha forte + MFA quando possível, valide tokens com assinatura criptográfica, revoque sessões expiradas, e nunca confie em dados controlados pelo cliente. Teste autenticação em cada endpoint crítico.

CVE-2026-19709MEDIUMMembership For WooCommerce < 3.1.2 - Unauthenticated Member Data Disclosure via REST Consumer Secret BypassEPSS 0.3%CVE-2026-77771HIGHminiOrange 2FA (Free & Pro) - 2FA Bypass via Session-Scoped OTP LockoutEPSS 0.3%CVE-2026-11923HIGHSecurity vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify AccessEPSS 0.3%CVE-2026-55759HIGHRocket.Chat: Apple Sign-In skips JWT claims validation, allowing expired and cross-audience token replayEPSS 0.3%CVE-2025-10224MEDIUMIncorrect Evaluation of LDAP Nested Groups during Login in AxxonSoft Axxon One (C-Werk)EPSS 0.3%CVE-2023-29117HIGHAuthentication Bypass in JuiceBox Web Manager interfaceEPSS 0.3%CVE-2026-76548HIGHProfile Builder < 4.0.1 - Unauthenticated Unpublished Content and Media Modification via Front-End Upload Auth BypassEPSS 0.3%CVE-2024-41589HIGHDrayTek Vigor310 devices through 4.3.2.6 use unencrypted HTTP for authentication requests.EPSS 0.3%CVE-2026-65121HIGHNVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause an improper authentication issue. A succeEPSS 0.3%CVE-2026-18891HIGHLangflow is affected by multiple authentication bypass, path traversal, authorization, and server-side request forgery vulnerabilitiesEPSS 0.3%CVE-2025-15069HIGHPrivilege Escalation in Gmission Web FAXEPSS 0.3%CVE-2025-54761HIGHAn issue was discovered in PPress 0.0.9 allowing attackers to gain escilated privlidges via crafted session cookie.EPSS 0.3%CVE-2024-38351MEDIUMPassword auth and OAuth2 unverified email linkingEPSS 0.3%CVE-2026-80128MEDIUMDell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper AuthentiEPSS 0.3%CVE-2026-44166MEDIUMPocketbase: Account pre-hijacking via OAuth2 unverfied->verified autolinking upgradeEPSS 0.3%CVE-2025-52054MEDIUMAn issue was discovered in Tenda AC8 v4.0 AC1200 Dual-band Gigabit Wireless Router AC8v4.0 Firmware 16.03.33.05. The root password of the deEPSS 0.3%CVE-2023-5502HIGHOn affected platforms running Arista EOS with 802.1x authentication configured on the access/trunk ports, a malicious supplicant may bypass authentication.EPSS 0.3%CVE-2026-33512HIGHAVideo has an unauthenticated decrypt oracle leaking any ciphertextEPSS 0.3%CVE-2026-8508MEDIUMAn improper authentication vulnerability in the "social_login.cgi" CGI program in Zyxel WAX650S firmware versions through 7.10(ABRM.4)C0 couEPSS 0.3%CVE-2026-24170HIGHNVIDIA UFM Enterprise contains a vulnerability in the web interface authorization component, where an authenticated user could cause impropeEPSS 0.3%