Falhas do tipo CWE-287

2.451 resultados

Autenticação Insuficiente ou Ausente

Quando um usuário ou sistema afirma ser quem diz que é, a aplicação não valida (ou valida mal) essa identidade antes de conceder acesso. Isso permite que um atacante se passe por outra pessoa sem fornecer credenciais válidas, obtendo privilégios indevidos.

Exemplo

Um sistema que aceita login apenas verificando um campo de e-mail na sessão (sem senha), ou uma API que confia em um identificador de usuário enviado no header HTTP sem validar um token assinado. Um atacante simplesmente muda o valor e acessa dados de terceiros.

Como mitigar

Implemente autenticação robusta: exija senha forte + MFA quando possível, valide tokens com assinatura criptográfica, revoque sessões expiradas, e nunca confie em dados controlados pelo cliente. Teste autenticação em cada endpoint crítico.

CVE-2022-42463HIGHSoftbus_server in communication subsystem has a authenication bypass vulnerability in a callback handler function. Attackers can launch attacks on distributed networks by sending Bluetooth rfcomm packets to any remote device and executing arbitrary co ...EPSS 0.3%CVE-2023-30560MEDIUM PCU Configuration Lacks AuthenticationEPSS 0.3%CVE-2025-21450CRITICALImproper Authentication in GPS_GNSSEPSS 0.3%CVE-2026-44810HIGHMicrosoft Cryptographic Services Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-79974MEDIUMDell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper AuthentiEPSS 0.3%CVE-2026-60908HIGHVulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: Create Item Instance). Supported versions that arEPSS 0.3%CVE-2026-82980MEDIUMAny authenticated user can lock or unlock files they do not own by targeting absolute WebDAV paths of other users. The DAV plugin resolves fEPSS 0.3%CVE-2026-22099HIGHMissing authentication for Bluetooth communicationEPSS 0.3%CVE-2026-34389MEDIUMFleet's user account creation via invite does not enforce invited email addressEPSS 0.3%CVE-2026-19273MEDIUMThe Dashboard of IBM Sterling B2B Integrator and IBM Sterling File Gateway are Vulnerable to Improper Access ControlEPSS 0.3%CVE-2025-53545MEDIUMPress has a potential 2FA bypassEPSS 0.3%CVE-2026-61049HIGHVulnerability in the Oracle Production Scheduling product of Oracle E-Business Suite (component: Internal Operations). Supported versions tEPSS 0.3%CVE-2026-26141HIGHHybrid Worker Extension (Arc‑enabled Windows VMs) Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-57107HIGHWindows Admin Center Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2023-29062LOWUnsecure Identity VerificationEPSS 0.3%CVE-2024-47174MEDIUMCredential leak when credentials are used with `<nix/fetchurl.nix>`EPSS 0.3%CVE-2026-10283MEDIUMBottelet DaybydayCRM Setting missing authenticationEPSS 0.3%CVE-2023-20012MEDIUMCisco Nexus 9300-FX3 Series Fabric Extender for UCS Fabric Interconnects Authentication Bypass VulnerabilityEPSS 0.3%CVE-2025-29627MEDIUMAn issue in KeeperChat IOS Application v.5.8.8 allows a physically proximate attacker to escalate privileges via the Biometric AuthenticatioEPSS 0.3%CVE-2024-40778LOWAn authentication issue was addressed with improved state management. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadEPSS 0.3%