Falhas do tipo CWE-287

2.456 resultados

Autenticação Insuficiente ou Ausente

Quando um usuário ou sistema afirma ser quem diz que é, a aplicação não valida (ou valida mal) essa identidade antes de conceder acesso. Isso permite que um atacante se passe por outra pessoa sem fornecer credenciais válidas, obtendo privilégios indevidos.

Exemplo

Um sistema que aceita login apenas verificando um campo de e-mail na sessão (sem senha), ou uma API que confia em um identificador de usuário enviado no header HTTP sem validar um token assinado. Um atacante simplesmente muda o valor e acessa dados de terceiros.

Como mitigar

Implemente autenticação robusta: exija senha forte + MFA quando possível, valide tokens com assinatura criptográfica, revoque sessões expiradas, e nunca confie em dados controlados pelo cliente. Teste autenticação em cada endpoint crítico.

CVE-2026-56850MEDIUMA flaw in Node.js HTTPS Agent connection reuse can cause PFX object-array key collisions, allowing mutual TLS (mTLS) client identities to beEPSS 0.1%CVE-2024-29757HIGHthere is a possible permission bypass due to Debug certs being allowlisted. This could lead to local escalation of privilege with no additioEPSS 0.1%CVE-2023-21466MEDIUMPendingIntent hijacking vulnerability in CertificatePolicy in framework prior to SMR Apr-2023 Release 1 allows local attackers to access conEPSS 0.1%CVE-2026-94419LOWClient session cache reference poisoning allows resumption with wrong serverEPSS 0.1%CVE-2025-20730MEDIUMIn preloader, there is a possible escalation of privilege due to an insecure default value. This could lead to local escalation of privilegeEPSS 0.1%CVE-2026-100876MEDIUMmathurvishal CloudClassroom-PHP-Project loginlinkstudent.php missing authenticationEPSS —CVE-2026-100903MEDIUMООО НПО Ритм GEOritm REST API obj-groups missing authenticationEPSS —CVE-2026-52749MEDIUMImproper Authentication in Kaon AR2140XEPSS —CVE-2026-101004MEDIUMnotionnext-org NotionNext Authentication Guard cache.js cleanCache missing authenticationEPSS —CVE-2026-100871HIGHSylius before 1.12.25, 1.13.17, 1.14.20, 2.1.16, and 2.2.9 JWT Audience Confusion Allows Admin API AuthenticationEPSS —CVE-2026-101042HIGHParse Server 9.0.0 Authentication Bypass via Unverified Provider IdentityEPSS —CVE-2026-101073MEDIUMNetcore NR289-GE CGI Dispatcher boa improper authenticationEPSS —CVE-2026-101050HIGHHeym before 0.0.53 Authentication Bypass via Telegram WebhookEPSS —CVE-2026-101077CRITICALNetcore NR289-GE boa_temp process_request missing authenticationEPSS —CVE-2026-101049HIGHHeym before 0.0.53 Slack Webhook Signature Verification BypassEPSS —CVE-2026-100886CRITICALSeetong T8108/T8108P/T8116/T8232 Debug Service improper authenticationEPSS —