Falhas do tipo CWE-287

2.453 resultados

Autenticação Insuficiente ou Ausente

Quando um usuário ou sistema afirma ser quem diz que é, a aplicação não valida (ou valida mal) essa identidade antes de conceder acesso. Isso permite que um atacante se passe por outra pessoa sem fornecer credenciais válidas, obtendo privilégios indevidos.

Exemplo

Um sistema que aceita login apenas verificando um campo de e-mail na sessão (sem senha), ou uma API que confia em um identificador de usuário enviado no header HTTP sem validar um token assinado. Um atacante simplesmente muda o valor e acessa dados de terceiros.

Como mitigar

Implemente autenticação robusta: exija senha forte + MFA quando possível, valide tokens com assinatura criptográfica, revoque sessões expiradas, e nunca confie em dados controlados pelo cliente. Teste autenticação em cada endpoint crítico.

CVE-2026-61687HIGHhatchet - Unauthenticated OAuth state CSRF / login-CSRF via empty-state collision in ValidateOAuthStateEPSS 0.2%CVE-2025-41459HIGHInsecure authentication due to missing bruteforce protection and runtime manipulation in Two App Studio Journey 5.5.6 for iOSEPSS 0.2%CVE-2025-22236HIGHCVE-2025-22236 salt advisoryEPSS 0.2%CVE-2026-33248MEDIUMNATS has mTLS verify_and_map authentication bypass via incorrect Subject DN matchingEPSS 0.2%CVE-2025-64517MEDIUMsudo-rs doesn't record authenticating user properly in timestampEPSS 0.2%CVE-2019-6854—A CWE-287: Improper Authentication vulnerability exists in a folder within EcoStruxure Geo SCADA Expert (ClearSCADA) -with initial releases EPSS 0.2%CVE-2026-47272HIGHpam_usb: OTP pad authentication bypass via missing system pad check and uninitialized RNG bufferEPSS 0.2%CVE-2025-65431MEDIUMAn issue was discovered in allauth-django before 65.13.0. Both Okta and NetIQ were using preferred_username as the identifier for third-partEPSS 0.2%CVE-2025-32875MEDIUMAn issue was discovered in the COROS application through 3.8.12 for Android. Bluetooth pairing and bonding is neither initiated nor enforcedEPSS 0.2%CVE-2024-9133MEDIUMA user with administrator privileges is able to retrieve authentication tokensEPSS 0.2%CVE-2024-4601MEDIUMImproper Authentication vulnerability in Socomec Net VisionEPSS 0.2%CVE-2026-57178HIGHsocial-auth-core: VK App backend accepts unsigned callback data when auth_key is missingEPSS 0.2%CVE-2021-3784MEDIUMGaruda Linux Improper AuthorizationEPSS 0.2%CVE-2026-96456MEDIUMReachy Mini Bluetooth PIN authentication can be bypassed by racing an authenticated deviceEPSS 0.2%CVE-2025-26475MEDIUMDell Secure Connect Gateway (SCG) 5.0 Appliance - SRS, version(s) 5.26, Enables Live-Restore setting which enhances security by keeping contEPSS 0.2%CVE-2021-25430—Improper access control vulnerability in Bluetooth application prior to SMR July-2021 Release 1 allows untrusted application to access the BEPSS 0.2%CVE-2022-37345HIGHImproper authentication in BIOS firmware[A1] for some Intel(R) NUC Kits before version RY0386 may allow an authenticated user to potentiallyEPSS 0.2%CVE-2026-39969MEDIUMTypeBot: WhatsApp Webhook Endpoint Missing Signature VerificationEPSS 0.2%CVE-2022-36370HIGHImproper authentication in BIOS firmware for some Intel(R) NUC Boards and Intel(R) NUC Kits before version MYi30060 may allow a privileged uEPSS 0.2%CVE-2025-20083HIGHImproper authentication in the firmware for the Intel(R) Slim Bootloader may allow a privileged user to potentially enable escalation of priEPSS 0.2%