Falhas do tipo CWE-287

2.452 resultados

Autenticação Insuficiente ou Ausente

Quando um usuário ou sistema afirma ser quem diz que é, a aplicação não valida (ou valida mal) essa identidade antes de conceder acesso. Isso permite que um atacante se passe por outra pessoa sem fornecer credenciais válidas, obtendo privilégios indevidos.

Exemplo

Um sistema que aceita login apenas verificando um campo de e-mail na sessão (sem senha), ou uma API que confia em um identificador de usuário enviado no header HTTP sem validar um token assinado. Um atacante simplesmente muda o valor e acessa dados de terceiros.

Como mitigar

Implemente autenticação robusta: exija senha forte + MFA quando possível, valide tokens com assinatura criptográfica, revoque sessões expiradas, e nunca confie em dados controlados pelo cliente. Teste autenticação em cada endpoint crítico.

CVE-2020-7276MEDIUMUnrestricted Policy Management using MfeUpgradeTool.exeEPSS 0.3%CVE-2024-40648MEDIUM`UserIdentity::is_verified` not checking verification status of own user identity while performing the check in matrix-rust-sdkEPSS 0.3%CVE-2024-45347CRITICALMi Connect Service APP protocol flaws lead to unauthorized accessEPSS 0.3%CVE-2023-28647MEDIUMApp pin of the iOS app can be bypassed in Nextcloud iOSEPSS 0.3%CVE-2026-14563CRITICALAdvanced Customized Prompts <= 1.0.1 - Unauthenticated Account TakeoverEPSS 0.3%CVE-2023-52111HIGHAuthorization vulnerability in the BootLoader module. Successful exploitation of this vulnerability may affect service integrity.EPSS 0.3%CVE-2026-77244CRITICAL[mcp-atlassian] Authentication bypass in HTTP transport: AtlassianOpaqueTokenVerifier accepts any non-empty tokenEPSS 0.3%CVE-2026-14559CRITICALTeddy Bear Customize Addon <= 1.0.5 - Unauthenticated Account TakeoverEPSS 0.3%CVE-2026-90623MEDIUMandreashappe cochise SSH Host Key ssh_connection.py asyncssh.connect certificate validationEPSS 0.3%CVE-2026-53512CRITICALBetter Auth: OAuth refresh-token replay via missing client authentication on oidc-provider and mcp pluginsEPSS 0.3%CVE-2025-65128HIGHA missing authentication mechanism in the web management API components of Shenzhen Zhibotong Electronics ZBT WE2001 23.09.27 allows unautheEPSS 0.3%CVE-2022-42453MEDIUMHCL BigFix Platform is affected by insufficient warningsEPSS 0.3%CVE-2026-14561MEDIUMAuthora - Easy Login with Mobile Number < 1.7.7 - Unauthenticated Account Takeover via OTP DisclosureEPSS 0.3%CVE-2025-54573MEDIUMCVAT vulnerable to email verification bypass by use of basic authenticationEPSS 0.3%CVE-2026-39324CRITICALRack::Session::Cookie secrets: decrypt failure fallback enables secretless session forgery and Marshal deserializationEPSS 0.3%CVE-2024-37408HIGHfprintd through 1.94.3 lacks a security attention mechanism, and thus unexpected actions might be authorized by "auth sufficient pam_fprintdEPSS 0.3%CVE-2022-29838MEDIUMAuthentication issue with the encrypted volumes and auto mount feature in My Cloud devicesEPSS 0.3%CVE-2026-35261MEDIUMVulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that EPSS 0.3%CVE-2025-7095MEDIUMComodo Internet Security Premium Update certificate validationEPSS 0.3%CVE-2026-60434MEDIUMVulnerability in the Oracle Transportation Management product of Oracle Supply Chain (component: Authentication). The supported version thEPSS 0.3%