Falhas do tipo CWE-287

2.417 resultados

Autenticação Insuficiente ou Ausente

Quando um usuário ou sistema afirma ser quem diz que é, a aplicação não valida (ou valida mal) essa identidade antes de conceder acesso. Isso permite que um atacante se passe por outra pessoa sem fornecer credenciais válidas, obtendo privilégios indevidos.

Exemplo

Um sistema que aceita login apenas verificando um campo de e-mail na sessão (sem senha), ou uma API que confia em um identificador de usuário enviado no header HTTP sem validar um token assinado. Um atacante simplesmente muda o valor e acessa dados de terceiros.

Como mitigar

Implemente autenticação robusta: exija senha forte + MFA quando possível, valide tokens com assinatura criptográfica, revoque sessões expiradas, e nunca confie em dados controlados pelo cliente. Teste autenticação em cada endpoint crítico.

CVE-2026-86426CRITICALLibreNMS before 26.8.0 Authentication Bypass via API Token Type ConfusionEPSS 2.1%CVE-2024-57046HIGHA vulnerability in the Netgear DGN2200 router with firmware version v1.0.0.46 and earlier permits unauthorized individuals to bypass the autEPSS 2.1%CVE-2017-9939—A vulnerability was discovered in Siemens SiPass integrated (All versions before V2.70) that could allow an attacker with network access to EPSS 2.1%CVE-2022-29165CRITICALArgo CD will blindly trust JWT claims if anonymous access is enabledEPSS 2.1%CVE-2017-12196MEDIUMundertow before versions 1.4.18.SP1, 2.0.2.Final, 1.4.24.Final was found vulnerable when using Digest authentication, the server does not enEPSS 2.0%CVE-2018-0382MEDIUMCisco Wireless LAN Controller Software Session Hijacking VulnerabilityEPSS 2.0%CVE-2017-12316—A vulnerability in the Guest Portal login page of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to peEPSS 2.0%CVE-2019-18284—A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). The AdminService is available wEPSS 2.0%CVE-2022-36436CRITICALOSU Open Source Lab VNCAuthProxy through 1.1.1 is affected by an vncap/vnc/protocol.py VNCServerAuthenticator authentication-bypass vulnerabEPSS 2.0%CVE-2017-7930—An Improper Authentication issue was discovered in OSIsoft PI Server 2017 PI Data Archive versions prior to 2017. PI Data Archive has protocEPSS 2.0%CVE-2026-27960CRITICALOpenCTI privilege escalation and unauthenticated access via default admin accountEPSS 2.0%CVE-2024-48445CRITICALAn issue in compop.ca ONLINE MALL v.3.5.3 allows a remote attacker to execute arbitrary code via the rid, tid, et, and ts parameters.EPSS 2.0%CVE-2020-27780—A flaw was found in Linux-Pam in versions prior to 1.5.1 in the way it handle empty passwords for non-existing users. When the user doesn't EPSS 2.0%CVE-2022-1049—A flaw was found in the Pacemaker configuration tool (pcs). The pcs daemon was allowing expired accounts, and accounts with expired passwordEPSS 2.0%CVE-2017-12225—A vulnerability in the web functionality of the Cisco Prime LAN Management Solution could allow an authenticated, remote attacker to hijack EPSS 2.0%CVE-2021-38161—Not validating origin TLS certificateEPSS 1.9%CVE-2026-53595CRITICALFreeScout vulnerable to anonymous account takeover via /user-setup empty invite_hash on MySQLEPSS 1.9%CVE-2024-23465HIGHSolarWinds Access Rights Manager (ARM) ChangeHumster Exposed Dangerous Method Authentication Bypass VulnerabilityEPSS 1.9%CVE-2026-0558HIGHUnauthenticated File Upload in parisneo/lollmsEPSS 1.9%CVE-2026-49869CRITICALKestra: Unauthenticated Remote Code Execution via Authentication Bypass in `AuthenticationFilter`EPSS 1.9%KEV