Falhas do tipo CWE-287

2.415 resultados

Autenticação Insuficiente ou Ausente

Quando um usuário ou sistema afirma ser quem diz que é, a aplicação não valida (ou valida mal) essa identidade antes de conceder acesso. Isso permite que um atacante se passe por outra pessoa sem fornecer credenciais válidas, obtendo privilégios indevidos.

Exemplo

Um sistema que aceita login apenas verificando um campo de e-mail na sessão (sem senha), ou uma API que confia em um identificador de usuário enviado no header HTTP sem validar um token assinado. Um atacante simplesmente muda o valor e acessa dados de terceiros.

Como mitigar

Implemente autenticação robusta: exija senha forte + MFA quando possível, valide tokens com assinatura criptográfica, revoque sessões expiradas, e nunca confie em dados controlados pelo cliente. Teste autenticação em cada endpoint crítico.

CVE-2026-21891CRITICALZimaOS has Authentication Bypass via System-Level UsernameEPSS 2.4%CVE-2024-37152MEDIUMUnauthenticated Access to sensitive settings in Argo CDEPSS 2.3%CVE-2020-7533—CWE-287: Improper Authentication vulnerability exists which could cause the execution of commands on the webserver without authentication whEPSS 2.3%CVE-2021-25315CRITICALsalt-api unauthenticated remote code executionEPSS 2.3%CVE-2014-0769—Festo CECX-X-(C1/M1) Controller Improper AuthenticationEPSS 2.3%CVE-2017-9625—An Improper Authentication issue was discovered in Envitech EnviDAS Ultimate Versions prior to v1.0.0.5. The web application lacks proper auEPSS 2.3%CVE-2019-18314—A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker with network accessEPSS 2.3%CVE-2017-14000—An Improper Authentication issue was discovered in Ctek SkyRouter Series 4200 and 4400, all versions prior to V6.00.11. By accessing a speciEPSS 2.3%CVE-2021-35029CRITICALAn authentication bypasss vulnerability in the web-based management interface of Zyxel USG/Zywall series firmware versions 4.35 through 4.64EPSS 2.3%CVE-2023-28125MEDIUMAn improper authentication vulnerability exists in Avalanche Premise versions 6.3.x and below that could allow an attacker to gain access toEPSS 2.3%CVE-2022-41912CRITICALcrewjam/saml go library is vulnerable to signature bypass via multiple Assertion elementsEPSS 2.2%CVE-2022-21618MEDIUMVulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JGSS). Supported versions that EPSS 2.2%CVE-2026-11387CRITICALSMS Alert <= 3.9.5 - Unauthenticated Privilege Escalation via Arbitrary Password ResetEPSS 2.2%CVE-2018-4835—A vulnerability has been identified in TeleControl Server Basic < V3.1. An attacker with network access to the TeleControl Server Basic's poEPSS 2.2%CVE-2022-31020HIGHRemote code execution in Indy's NODE_UPGRADE transactionEPSS 2.2%CVE-2022-37298CRITICALShinken Solutions Shinken Monitoring Version 2.4.3 affected is vulnerable to Incorrect Access Control. The SafeUnpickler class found in shinEPSS 2.2%CVE-2022-22576HIGHAn improper authentication vulnerability exists in curl 7.33.0 to and including 7.82.0 which might allow reuse OAUTH2-authenticated connectiEPSS 2.2%CVE-2017-7934—An Improper Authentication issue was discovered in OSIsoft PI Server 2017 PI Data Archive versions prior to 2017. PI Network Manager using oEPSS 2.1%CVE-2021-20288—An authentication flaw was found in ceph in versions before 14.2.20. When the monitor handles CEPHX_GET_AUTH_SESSION_KEY requests, it doesn'EPSS 2.1%CVE-2022-22990HIGHLimited authentication bypass vulnerability on Western Digital My Cloud devicesEPSS 2.1%