Falhas do tipo CWE-287

2.453 resultados

Autenticação Insuficiente ou Ausente

Quando um usuário ou sistema afirma ser quem diz que é, a aplicação não valida (ou valida mal) essa identidade antes de conceder acesso. Isso permite que um atacante se passe por outra pessoa sem fornecer credenciais válidas, obtendo privilégios indevidos.

Exemplo

Um sistema que aceita login apenas verificando um campo de e-mail na sessão (sem senha), ou uma API que confia em um identificador de usuário enviado no header HTTP sem validar um token assinado. Um atacante simplesmente muda o valor e acessa dados de terceiros.

Como mitigar

Implemente autenticação robusta: exija senha forte + MFA quando possível, valide tokens com assinatura criptográfica, revoque sessões expiradas, e nunca confie em dados controlados pelo cliente. Teste autenticação em cada endpoint crítico.

CVE-2026-3194LOWChia Blockchain RPC Server Master Passphrase get_private_key missing authenticationEPSS 0.2%CVE-2026-33246MEDIUMNATS: Leafnode connections allow spoofing of Nats-Request-Info identity headersEPSS 0.2%CVE-2023-32453MEDIUM Dell BIOS contains an improper authentication vulnerability. A malicious user with physical access to the system may potentially exploit thEPSS 0.2%CVE-2026-75973HIGHApache Tomcat: Cross-context authentication mix-up with Jakarta Authentication configuredEPSS 0.2%CVE-2021-3519MEDIUMA vulnerability was reported in some Lenovo Desktop models that could allow unauthorized access to the boot menu, when the "BIOS Password AtEPSS 0.2%CVE-2025-15484CRITICALOrder Notification for WooCommerce < 3.6.3 - Unauthenticated WooCommerce REST Permission BypassEPSS 0.2%CVE-2023-21419MEDIUMAn improper implementation logic in Secure Folder prior to SMR Jan-2023 Release 1 allows the Secure Folder container remain unlocked under cEPSS 0.2%CVE-2024-52968MEDIUMAn improper authentication in Fortinet FortiClientMac 7.0.11 through 7.2.4 allows attacker to gain improper access to MacOS via empty passwoEPSS 0.2%CVE-2025-24904HIGHlibsignal-service-rs doesn't sanity check plaintext envelopes are not sanity-checkedEPSS 0.2%CVE-2022-39245HIGHMist vulnerable to user providing a Sudo binary for authentication checksEPSS 0.2%CVE-2022-27874MEDIUMImproper authentication in some Intel(R) XMM(TM) 7560 Modem software before version M2_7560_R_01.2146.00 may allow a privileged user to poteEPSS 0.2%CVE-2026-55962MEDIUMTLS 1.3 post-handshake authentication: server accepts Finished without client Certificate/CertificateVerifyEPSS 0.2%CVE-2026-12526HIGHAdvanced Custom Fields: Extended < 0.9.2.7 - Unauthenticated Administrator Account Takeover via Front-End User Update ActionEPSS 0.2%CVE-2025-2230HIGHPhilips Intellispace Cardiovascular (ISCV) Improper AuthenticationEPSS 0.2%CVE-2026-34123HIGHWhitelist Validation Bypass in TP-Link Tapo C520WSEPSS 0.2%CVE-2025-27425MEDIUMQR code user confirmation bypass with invalid protocolEPSS 0.2%CVE-2025-53013MEDIUMHimmelblau offline auth permits authentication with invalid Hello PINEPSS 0.2%CVE-2021-25451LOWA PendingIntent hijacking in NetworkPolicyManagerService prior to SMR Sep-2021 Release 1 allows attackers to get IMSI data.EPSS 0.2%CVE-2023-28646MEDIUMApp lockout in nextcloud Android app can be bypassed via thirdparty appsEPSS 0.2%CVE-2026-57175MEDIUMsocial-auth-core has an Improper Authentication issueEPSS 0.2%