Falhas do tipo CWE-287

2.453 resultados

Autenticação Insuficiente ou Ausente

Quando um usuário ou sistema afirma ser quem diz que é, a aplicação não valida (ou valida mal) essa identidade antes de conceder acesso. Isso permite que um atacante se passe por outra pessoa sem fornecer credenciais válidas, obtendo privilégios indevidos.

Exemplo

Um sistema que aceita login apenas verificando um campo de e-mail na sessão (sem senha), ou uma API que confia em um identificador de usuário enviado no header HTTP sem validar um token assinado. Um atacante simplesmente muda o valor e acessa dados de terceiros.

Como mitigar

Implemente autenticação robusta: exija senha forte + MFA quando possível, valide tokens com assinatura criptográfica, revoque sessões expiradas, e nunca confie em dados controlados pelo cliente. Teste autenticação em cada endpoint crítico.

CVE-2025-25452MEDIUMAn issue in TAAGSOLUTIONS GmbH MyTaag v.2024-11-24 and before allows a remote attacker to escalate privileges via the "/user" endpointEPSS 0.3%CVE-2026-19842HIGHSAML Single Sign On 4.8.85 - 5.4.6 - Unauthenticated Administrator Account Takeover via SAML Trust Anchor OverwriteEPSS 0.3%CVE-2025-11633MEDIUMTomofun Furbo 360/Furbo Mini HTTP Traffic collect_logs.sh upload_file_to_s3 certificate validationEPSS 0.3%CVE-2025-3634MEDIUMMoodle: moodle allows course self-enrolment before completing mfaEPSS 0.3%CVE-2026-17013MEDIUMWP Photo Album Plus < 9.2.07.002 - Reflected XSS via lbstartEPSS 0.3%CVE-2024-38822LOWCVE-2024-38822 Salt AdvisoryEPSS 0.3%CVE-2026-73726MEDIUMAuthentication Bypass in HPE Networking Fabric Composer allows Unauthorized Administrative AccessEPSS 0.3%CVE-2026-19766CRITICALAuthentication Bypass leads to Administrative control of adjacent network hosts in HPE Networking Fabric ComposerEPSS 0.3%CVE-2025-2572MEDIUMWhatsUp Gold NmConfigurationManager.exe database manipulation vulnerabilityEPSS 0.3%CVE-2023-43551CRITICALImproper Authentication in Multi-Mode Call ProcessorEPSS 0.3%CVE-2024-13309MEDIUMLogin Disable - Critical - Access bypass - SA-CONTRIB-2024-073EPSS 0.3%CVE-2025-65925MEDIUMAn issue was discovered in Zeroheight (SaaS) prior to 2025-06-13. A legacy user creation API pathway allowed accounts to be created without EPSS 0.3%CVE-2025-1880LOWi-Drive i11/i12 Device Pairing authentication bypassEPSS 0.3%CVE-2024-27835LOWThis issue was addressed through improved state management. This issue is fixed in iOS 17.5 and iPadOS 17.5. An attacker with physical accesEPSS 0.3%CVE-2025-31264MEDIUMAn authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS EPSS 0.3%CVE-2023-43660MEDIUMSSH key password bypassed in warpgateEPSS 0.3%CVE-2026-14541HIGHAuthentication Bypass and Audience Confusion in MCP Toolbox OAuth ProviderEPSS 0.3%CVE-2026-0408MEDIUMPath traversal vulnerability in Netgear WiFi Range ExtendersEPSS 0.3%CVE-2026-16892MEDIUMIBM i is Affected By An Improper Authentication Vulnerability in Network Authentication Service []EPSS 0.3%CVE-2025-41110HIGHImproper Authentication vulnerability in Ghost Robotics' Vision 60EPSS 0.3%