Falhas do tipo CWE-287

2.453 resultados

Autenticação Insuficiente ou Ausente

Quando um usuário ou sistema afirma ser quem diz que é, a aplicação não valida (ou valida mal) essa identidade antes de conceder acesso. Isso permite que um atacante se passe por outra pessoa sem fornecer credenciais válidas, obtendo privilégios indevidos.

Exemplo

Um sistema que aceita login apenas verificando um campo de e-mail na sessão (sem senha), ou uma API que confia em um identificador de usuário enviado no header HTTP sem validar um token assinado. Um atacante simplesmente muda o valor e acessa dados de terceiros.

Como mitigar

Implemente autenticação robusta: exija senha forte + MFA quando possível, valide tokens com assinatura criptográfica, revoque sessões expiradas, e nunca confie em dados controlados pelo cliente. Teste autenticação em cada endpoint crítico.

CVE-2025-0981HIGHSession Hijacking via Stored Cross-Site Scripting (XSS) in ChurchCRM GroupEditor.php Description FieldEPSS 0.2%CVE-2025-10672HIGHwhuan132 AIBattery com.collweb.AIBatteryHelper BatteryXPCService.swift missing authenticationEPSS 0.2%CVE-2026-56294MEDIUMcapacitor-native-biometric - Authentication Bypass via Unvalidated CryptoObject in onAuthenticationSucceededEPSS 0.2%CVE-2026-12112HIGHForeman-mcp-server: mcp server: active session hijacking via insecure session state reuseEPSS 0.2%CVE-2024-22247MEDIUMVMware SD-WAN Edge contains a missing authentication and protection mechanism vulnerability. A malicious actor with physical access to the EPSS 0.2%CVE-2026-54510HIGHSpeakr: CSRF bypass via unauthenticated API token parameter in csrf_exempt_for_api_tokens hookEPSS 0.2%CVE-2025-0672LOWAuthentication Bypass in Multiple WSO2 Products via Stale FIDO Credential AssociationEPSS 0.2%CVE-2023-42935MEDIUMAn authentication issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.6.4. A local attacker may be aEPSS 0.2%CVE-2025-0249LOWHCL IEM is affected by an improper invalidation of access or JWT token vulnerabilityEPSS 0.2%CVE-2026-0633LOWMetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor <= 4.1.0 - Unauthenticated Form Submission Exposure via Forgeable Cookie ValueEPSS 0.2%CVE-2023-31189MEDIUMImproper authentication in some Intel(R) Server Product OpenBMC firmware before version egs-1.09 may allow an authenticated user to enable eEPSS 0.2%CVE-2022-48254MEDIUMThere is a data processing error vulnerability in Leia-B29 2.0.0.49(M03). Successful exploitation could bypass lock screen authentication.EPSS 0.2%CVE-2026-44711HIGHpam_usb: Symlink attacks on pad directory and pad files enable authentication bypass and root file corruptionEPSS 0.2%CVE-2026-86890MEDIUMA logic issue was addressed with improved checks. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27. An attacker with phEPSS 0.2%CVE-2021-25377LOWIntent redirection in Samsung Experience Service versions 10.8.0.4 in Android P(9.0) below, and 12.2.0.5 in Android Q(10.0) above allows attEPSS 0.2%CVE-2025-67859MEDIUMPolkit Authorization Check can be Bypassed in the TLP power daemonEPSS 0.2%CVE-2025-52294MEDIUMInsufficient validation of the screen lock mechanism in Trust Wallet v8.45 allows physically proximate attackers to bypass the lock screen aEPSS 0.2%CVE-2024-39767MEDIUMSpoofed push notifications from malicious serverEPSS 0.2%CVE-2022-28790MEDIUMImproper authentication in Link to Windows Service prior to version 2.3.04.1 allows attacker to lock the device. The patch adds proper calleEPSS 0.2%CVE-2026-34204HIGHMinIO is Vulnerable to SSE Metadata Injection via Replication HeadersEPSS 0.2%