Falhas do tipo CWE-287

2.453 resultados

Autenticação Insuficiente ou Ausente

Quando um usuário ou sistema afirma ser quem diz que é, a aplicação não valida (ou valida mal) essa identidade antes de conceder acesso. Isso permite que um atacante se passe por outra pessoa sem fornecer credenciais válidas, obtendo privilégios indevidos.

Exemplo

Um sistema que aceita login apenas verificando um campo de e-mail na sessão (sem senha), ou uma API que confia em um identificador de usuário enviado no header HTTP sem validar um token assinado. Um atacante simplesmente muda o valor e acessa dados de terceiros.

Como mitigar

Implemente autenticação robusta: exija senha forte + MFA quando possível, valide tokens com assinatura criptográfica, revoque sessões expiradas, e nunca confie em dados controlados pelo cliente. Teste autenticação em cada endpoint crítico.

CVE-2026-0407MEDIUMAuthentication bypass in NETGEAR WiFi Range Extenders via network adjacent attacksEPSS 0.3%CVE-2026-11366LOWMonsterInsights < 11.1.0 - Unauthenticated Measurement Protocol Secret Update via Empty-Key HMAC BypassEPSS 0.2%CVE-2022-39901MEDIUMImproper authentication in Exynos baseband prior to SMR DEC-2022 Release 1 allows remote attacker to disable the network traffic encryption EPSS 0.2%CVE-2026-54781HIGHCoreWCF: SAML SubjectConfirmation methods and holder-of-key proof keys are not enforcedEPSS 0.2%CVE-2026-60357LOWVulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: Siebel Server Sync for Exchange). Supported versions tEPSS 0.2%CVE-2025-68663MEDIUMOutline has a suspended user authentication bypass via WebSocket connectionsEPSS 0.2%CVE-2026-22764MEDIUMDell OpenManage Network Integration, versions prior to 3.9, contains an Improper Authentication vulnerability. A low privileged attacker witEPSS 0.2%CVE-2020-12035—Baxter PrismaFlex all versions, PrisMax all versions prior to 3.x, The PrismaFlex device contains a hard-coded service password that provideEPSS 0.2%CVE-2025-62398MEDIUMMoodle: possible to bypass mfaEPSS 0.2%CVE-2024-38639MEDIUMQTSEPSS 0.2%CVE-2026-56727HIGHZammad: PGP signature spoofing via unvalidated verification returnEPSS 0.2%CVE-2025-7630MEDIUMOTP Password Brute Forcing in DorukNet's WispotterEPSS 0.2%CVE-2025-6083MEDIUMExtremeCloud Universal ZTNA Improper AuthorizationEPSS 0.2%CVE-2024-24554MEDIUMBludit - Insecure Token GenerationEPSS 0.2%CVE-2026-65329MEDIUMAn authentication issue was addressed with improved state management. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, iOS 27 and iPadOSEPSS 0.2%CVE-2026-96445MEDIUMKeycloak-services: keycloak-services: conditional otp skip-header policy evaluated against untrusted proxy headersEPSS 0.2%CVE-2025-9265CRITICALAPI Authentication Bypass via Header Spoofing vulnerability in Kiloview NDI N30 ProductsEPSS 0.2%CVE-2021-3458MEDIUMThe Motorola MM1000 device configuration portal can be accessed without authentication, which could allow adapter settings to be modified.EPSS 0.2%CVE-2022-3681MEDIUMA vulnerability has been identified in the MR2600 router v1.0.18 and earlier that could allow an attacker within range of the wireless netwoEPSS 0.2%CVE-2025-0663MEDIUMPotential cross-tenant account takeover vulnerability in Multiple WSO2 Products via Adaptive Authentication and Auto-LoginEPSS 0.2%