Falhas do tipo CWE-287

2.453 resultados

Autenticação Insuficiente ou Ausente

Quando um usuário ou sistema afirma ser quem diz que é, a aplicação não valida (ou valida mal) essa identidade antes de conceder acesso. Isso permite que um atacante se passe por outra pessoa sem fornecer credenciais válidas, obtendo privilégios indevidos.

Exemplo

Um sistema que aceita login apenas verificando um campo de e-mail na sessão (sem senha), ou uma API que confia em um identificador de usuário enviado no header HTTP sem validar um token assinado. Um atacante simplesmente muda o valor e acessa dados de terceiros.

Como mitigar

Implemente autenticação robusta: exija senha forte + MFA quando possível, valide tokens com assinatura criptográfica, revoque sessões expiradas, e nunca confie em dados controlados pelo cliente. Teste autenticação em cada endpoint crítico.

CVE-2023-31015MEDIUMNVIDIA DGX H100 BMC contains a vulnerability in the REST service where a host user may cause as improper authentication issue. A successful EPSS 0.2%CVE-2025-37731MEDIUMElasticsearch Improper AuthenticationEPSS 0.2%CVE-2022-43451HIGHMultiple path traversal in appspawn and nwebspawn services.EPSS 0.2%CVE-2023-3028HIGHImproper backend communication allows access and manipulation of the telemetry dataEPSS 0.2%CVE-2025-0217HIGHPrivileged Remote Access Authentication BypassEPSS 0.2%CVE-2026-39411MEDIUMLobeHub has an unauthenticated authentication bypass on `webapi` routes via forgeable `X-lobe-chat-auth` headerEPSS 0.2%CVE-2023-28377MEDIUMImproper authentication in some Intel(R) NUC Kit NUC11PH USB firmware installation software before version 1.1 for Windows may allow an authEPSS 0.2%CVE-2026-20683HIGHAn authentication issue was addressed with improved state management. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, macEPSS 0.2%CVE-2026-55626HIGHxrdp: No authentication required with Xvnc backend on RHEL 9EPSS 0.2%CVE-2026-12504HIGHLoytec LINX firmware: Improper Authentication in PAM configurationEPSS 0.2%CVE-2026-82843CRITICALWP OAuth Server < 6.4.0 - Subscriber+ Cross-User Account Takeover via OIDC ID Token SubstitutionEPSS 0.2%CVE-2023-26455MEDIUMRMI was not requiring authentication when calling ChronosRMIService:setEventOrganizer. Attackers with local or adjacent network access couldEPSS 0.2%CVE-2025-31267MEDIUMAn authentication issue was addressed with improved state management. This issue is fixed in App Store Connect 3.0. An attacker with physicaEPSS 0.2%CVE-2025-64434MEDIUMKubeVirt Improper TLS Certificate Management Handling Allows API Identity SpoofingEPSS 0.2%CVE-2026-11718CRITICALAn authentication bypass vulnerability exists in the generic opaque token validation path (validateOpaqueToken) of googleapis/mcp-toolbox. EPSS 0.2%CVE-2026-33314MEDIUMpyload-ng: Improper Authentication and Origin Validation ErrorEPSS 0.2%CVE-2026-48991MEDIUMXianYuLauncher: Legacy Microsoft account OAuth sign-in flow lacks PKCE and state validationEPSS 0.2%CVE-2021-33159HIGHImproper authentication in subsystem for Intel(R) AMT before versions 11.8.93, 11.22.93, 11.12.93, 12.0.92, 14.1.67, 15.0.42, 16.1.25 may alEPSS 0.2%CVE-2022-2752MEDIUMPotential vulnerabilities in GM login processEPSS 0.2%CVE-2023-0036MEDIUMplatform_callback_stub in misc subsystem has an authentication bypass vulnerability which allows an "SA relay attack".EPSS 0.2%