Falhas do tipo CWE-287

2.451 resultados

Autenticação Insuficiente ou Ausente

Quando um usuário ou sistema afirma ser quem diz que é, a aplicação não valida (ou valida mal) essa identidade antes de conceder acesso. Isso permite que um atacante se passe por outra pessoa sem fornecer credenciais válidas, obtendo privilégios indevidos.

Exemplo

Um sistema que aceita login apenas verificando um campo de e-mail na sessão (sem senha), ou uma API que confia em um identificador de usuário enviado no header HTTP sem validar um token assinado. Um atacante simplesmente muda o valor e acessa dados de terceiros.

Como mitigar

Implemente autenticação robusta: exija senha forte + MFA quando possível, valide tokens com assinatura criptográfica, revoque sessões expiradas, e nunca confie em dados controlados pelo cliente. Teste autenticação em cada endpoint crítico.

CVE-2024-37897MEDIUMInsufficient access control for password reset in sftpgoEPSS 0.3%CVE-2026-73764HIGHAuthentication Bypass Vulnerabilities Leading to Unauthorized Modification and Service Disruption in AOS-CXEPSS 0.3%CVE-2023-50804LOWAn issue was discovered in Samsung Mobile Processor, and Modem Exynos 9820, Exynos 9825, Exynos 980, Exynos 990, Exynos 850, Exynos 1080, ExEPSS 0.3%CVE-2026-14216MEDIUMAmelia < 2.4.7 - Unauthenticated Notification Queue DispatchEPSS 0.3%CVE-2024-35775MEDIUMWordPress Slider by Soliloquy plugin <= 2.7.6 - Broken Access Control to XSS vulnerabilityEPSS 0.3%CVE-2025-15671MEDIUMWelcart e-Commerce < 2.12.1 - Session Fixation via uscesid ParameterEPSS 0.3%CVE-2024-10474CRITICALFocus was incorrectly allowing internal links to utilize the app scheme used for deeplinking, which could result in links potentially circumEPSS 0.3%CVE-2026-16282MEDIUMAppointment Hour Booking < 1.5.88 - Unauthenticated Booking Price Manipulation via tcost ParameterEPSS 0.3%CVE-2026-14547MEDIUMEstatik Real Estate Plugin < 4.3.3 - Unauthenticated Arbitrary-Recipient Mail Relay via Request FormEPSS 0.3%CVE-2026-14305MEDIUMWP Delicious < 1.10.2 - Unauthenticated Arbitrary Post Meta Update via recipe_likesEPSS 0.3%CVE-2026-15315HIGHUnauthenticated Administrative Authentication Bypass via device_confirm Replay in TP-Link Tapo C120 and C200EPSS 0.3%CVE-2025-10463HIGHImproper Authentication in Birtech Information Technologies' SensawayEPSS 0.3%CVE-2022-43978MEDIUMLimited Authentication bypass due to hardcoded secretEPSS 0.3%CVE-2026-85350MEDIUMUpsellWP < 2.2.10 - Unauthenticated Price Manipulation via Frequently Bought TogetherEPSS 0.3%CVE-2022-42463HIGHSoftbus_server in communication subsystem has a authenication bypass vulnerability in a callback handler function. Attackers can launch attacks on distributed networks by sending Bluetooth rfcomm packets to any remote device and executing arbitrary co ...EPSS 0.3%CVE-2023-30560MEDIUM PCU Configuration Lacks AuthenticationEPSS 0.3%CVE-2026-54047CRITICALLaci Synchroni Backend Vulnerable to Account Takeover / User Impersonation via Client-Side Configuration ManipulationEPSS 0.3%CVE-2025-21450CRITICALImproper Authentication in GPS_GNSSEPSS 0.3%CVE-2026-79974MEDIUMDell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper AuthentiEPSS 0.3%CVE-2026-44810HIGHMicrosoft Cryptographic Services Elevation of Privilege VulnerabilityEPSS 0.3%