Falhas do tipo CWE-287

2.454 resultados

Autenticação Insuficiente ou Ausente

Quando um usuário ou sistema afirma ser quem diz que é, a aplicação não valida (ou valida mal) essa identidade antes de conceder acesso. Isso permite que um atacante se passe por outra pessoa sem fornecer credenciais válidas, obtendo privilégios indevidos.

Exemplo

Um sistema que aceita login apenas verificando um campo de e-mail na sessão (sem senha), ou uma API que confia em um identificador de usuário enviado no header HTTP sem validar um token assinado. Um atacante simplesmente muda o valor e acessa dados de terceiros.

Como mitigar

Implemente autenticação robusta: exija senha forte + MFA quando possível, valide tokens com assinatura criptográfica, revoque sessões expiradas, e nunca confie em dados controlados pelo cliente. Teste autenticação em cada endpoint crítico.

CVE-2022-41737HIGHIBM Spectrum Scale security bypassEPSS 0.1%CVE-2026-10548MEDIUMNousResearch hermes-agent Credential Pool Synchronization credential_pool.py _sync_anthropic_entry_from_credentials_file improper authenticationEPSS 0.1%CVE-2026-20752MEDIUMImproper authentication for some Intel(R) PROSet/Wireless WiFi Software within Ring 0: Kernel may allow an information disclosure. System soEPSS 0.1%CVE-2022-39899MEDIUMImproper authentication vulnerability in Samsung WindowManagerService prior to SMR Dec-2022 Release 1 allows attacker to send the input evenEPSS 0.1%CVE-2022-48305MEDIUMThere is an identity authentication bypass vulnerability in Huawei Children Smart Watch (Simba-AL00) 1.1.1.274. Successful exploitation of tEPSS 0.1%CVE-2025-64432MEDIUMKubeVirt Affected by an Authentication Bypass in Kubernetes Aggregation LayerEPSS 0.1%CVE-2019-6198HIGHA vulnerability was reported in Lenovo PC Manager prior to version 2.8.90.11211 that could allow a local attacker to escalate privileges.EPSS 0.1%CVE-2019-6197HIGHA vulnerability was reported in Lenovo PC Manager prior to version 2.8.90.11211 that could allow a local attacker to escalate privileges.EPSS 0.1%CVE-2025-68712MEDIUMSpSoft AppLock (com.sp.protector.free) 7.9.40 for Android allows a local attacker with physical access to bypass fingerprint or PIN authentiEPSS 0.1%CVE-2026-97846MEDIUMKeycloak-services: keycloak-services: standard token exchange v2 bypasses mtls holder-of-key bindingEPSS 0.1%CVE-2025-6723MEDIUMUntrusted user data can lead to privilege escalationEPSS 0.1%CVE-2025-71057HIGHImproper session management in D-Link Wireless N 300 ADSL2+ Modem Router DSL-124 ME_1.00 allows attackers to execute a session hijacking attEPSS 0.1%CVE-2023-21471MEDIUMImproper access control vulnerability in SemClipboard prior to SMR Apr-2023 Release 1 allows attackers to read arbitrary files with system pEPSS 0.1%CVE-2026-20891MEDIUMImproper authentication for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 2: Device Drivers may allow an escalation ofEPSS 0.1%CVE-2026-13208MEDIUMKubevirt: virt-handler-rhel9: kubevirt: virt-handler notify server trusts vmi identity from unauthenticated grpc request bodyEPSS 0.1%CVE-2026-47166MEDIUMImageMagick: Heap Buffer Over-Read in distributed pixel cache serverEPSS 0.1%CVE-2022-41590MEDIUMSome smartphones have authentication-related (including session management) vulnerabilities as the setup wizard is bypassed. Successful explEPSS 0.1%CVE-2023-24852HIGHImproper Authentication in CoreEPSS 0.1%CVE-2020-9250LOWThere is an insufficient authentication vulnerability in some Huawei smart phone. An unauthenticated, local attacker can crafts software pacEPSS 0.1%CVE-2025-6044MEDIUMAn Improper Access Control vulnerability in the Stylus Tools component of Google ChromeOS version 16238.64.0 on the garaged stylus devices aEPSS 0.1%