Falhas do tipo CWE-287

2.453 resultados

Autenticação Insuficiente ou Ausente

Quando um usuário ou sistema afirma ser quem diz que é, a aplicação não valida (ou valida mal) essa identidade antes de conceder acesso. Isso permite que um atacante se passe por outra pessoa sem fornecer credenciais válidas, obtendo privilégios indevidos.

Exemplo

Um sistema que aceita login apenas verificando um campo de e-mail na sessão (sem senha), ou uma API que confia em um identificador de usuário enviado no header HTTP sem validar um token assinado. Um atacante simplesmente muda o valor e acessa dados de terceiros.

Como mitigar

Implemente autenticação robusta: exija senha forte + MFA quando possível, valide tokens com assinatura criptográfica, revoque sessões expiradas, e nunca confie em dados controlados pelo cliente. Teste autenticação em cada endpoint crítico.

CVE-2021-33159HIGHImproper authentication in subsystem for Intel(R) AMT before versions 11.8.93, 11.22.93, 11.12.93, 12.0.92, 14.1.67, 15.0.42, 16.1.25 may alEPSS 0.2%CVE-2026-84091MEDIUMSUMIT Payment Gateway for WooCommerce < 4.0.0 - Unauthenticated Payment Confirmation Forgery via bit IPNEPSS 0.2%CVE-2022-42488HIGHStartup subsystem missed permission validation in param service. An malicious application installed on the device could elevate its privileges to the root user, disable security features, or cause DoS by disabling particular services.EPSS 0.2%CVE-2026-34990MEDIUMOpenPrinting CUPS: Local print admin token disclosure using temporary printersEPSS 0.2%CVE-2026-40995MEDIUMX.509 authentication bypasses Spring Security account checksEPSS 0.2%CVE-2023-28073HIGH Dell BIOS contains an improper authentication vulnerability. A locally authenticated malicious user may potentially exploit this vulnerabilEPSS 0.2%CVE-2022-45118MEDIUMTelephony in communication subsystem sends public events with personal data, but the permission is not set.EPSS 0.2%CVE-2022-30749LOWImproper access control vulnerability in Smart Things prior to 1.7.85.25 allows local attackers to add arbitrary smart devices by bypassing EPSS 0.2%CVE-2022-37931HIGHA vulnerability in NetBatch-Plus software allows unauthorized access to the applicationEPSS 0.2%CVE-2026-86781MEDIUMSSL Zen < 4.7.40 - Subscriber+ TLS Private Key DisclosureEPSS 0.2%CVE-2022-33862MEDIUMImproper access control mechanism in IPPEPSS 0.2%CVE-2026-40109LOWFlux notification-controller GCR Receiver missing email validation allows unauthorized reconciliation triggeringEPSS 0.2%CVE-2026-11717CRITICALAn authentication bypass vulnerability exists in the generic opaque token validation path (validateOpaqueToken) of googleapis/mcp-toolbox. EPSS 0.2%CVE-2024-12310HIGHBypass of Login Screen on Shared Kiosk WorkstationsEPSS 0.2%CVE-2022-45877HIGHPIN code is transmitted to the peer device in plain text during cross-device authentication, which reduces the difficulty of man-in-the-middle attacks.EPSS 0.2%CVE-2026-64745LOWThis issue was addressed with additional restrictions on the lock screen. This issue is fixed in macOS Sequoia 15.7.8, macOS Tahoe 26.6. A pEPSS 0.2%CVE-2022-43900MEDIUMIBM WebSphere Automation for IBM Cloud Pak for Watson AIOps security bypassEPSS 0.2%CVE-2023-31292MEDIUMAn issue was discovered in Sesami Cash Point & Transport Optimizer (CPTO) 6.3.8.6 (#718), allows local attackers to obtain sensitive informaEPSS 0.2%CVE-2022-26858MEDIUMDell BIOS versions contain an Improper Authentication vulnerability. A locally authenticated malicious user could potentially exploit this vEPSS 0.2%CVE-2025-41459HIGHInsecure authentication due to missing bruteforce protection and runtime manipulation in Two App Studio Journey 5.5.6 for iOSEPSS 0.2%