Falhas do tipo CWE-287

2.417 resultados

Autenticação Insuficiente ou Ausente

Quando um usuário ou sistema afirma ser quem diz que é, a aplicação não valida (ou valida mal) essa identidade antes de conceder acesso. Isso permite que um atacante se passe por outra pessoa sem fornecer credenciais válidas, obtendo privilégios indevidos.

Exemplo

Um sistema que aceita login apenas verificando um campo de e-mail na sessão (sem senha), ou uma API que confia em um identificador de usuário enviado no header HTTP sem validar um token assinado. Um atacante simplesmente muda o valor e acessa dados de terceiros.

Como mitigar

Implemente autenticação robusta: exija senha forte + MFA quando possível, valide tokens com assinatura criptográfica, revoque sessões expiradas, e nunca confie em dados controlados pelo cliente. Teste autenticação em cada endpoint crítico.

CVE-2021-31349CRITICALSession Smart Router: Authentication Bypass VulnerabilityEPSS 1.7%CVE-2023-2706HIGHOTP Login Woocommerce & Gravity Forms <= 2.2 - Authentication Bypass to Privilege EscalationEPSS 1.7%CVE-2020-25165—BD Alaris PC Unit, Model 8015, Versions 9.33.1 and earlier and BD Alaris Systems Manager, Versions 4.33 and earlier The affected products arEPSS 1.7%CVE-2021-21378HIGHJWT authentication bypass with unknown issuer tokenEPSS 1.7%CVE-2021-43445CRITICALONLYOFFICE all versions as of 2021-11-08 is affected by Incorrect Access Control. An attacker can authenticate with the web socket service oEPSS 1.7%CVE-2020-8253—Improper authentication in Citrix XenMobile Server 10.12 before RP2, Citrix XenMobile Server 10.11 before RP4, Citrix XenMobile Server 10.10EPSS 1.7%CVE-2022-35925MEDIUMMissing rate limit in Authentication in bookwyrmEPSS 1.7%CVE-2020-25719—A flaw was found in the way Samba, as an Active Directory Domain Controller, implemented Kerberos name-based authentication. The Samba AD DCEPSS 1.7%CVE-2021-36368LOWAn issue was discovered in OpenSSH before 8.9. If a client is using public-key authentication with agent forwarding but without -oLogLevel=vEPSS 1.7%CVE-2019-20464HIGHAn issue was discovered on Sannce Smart HD Wifi Security Camera EAN 2 950004 595317 devices. By default, a mobile application is used to strEPSS 1.7%CVE-2022-23635HIGHUnauthenticated control plane denial of service attack in IstioEPSS 1.7%CVE-2019-14856MEDIUMansible before versions 2.8.6, 2.7.14, 2.6.20 is vulnerable to a NoneEPSS 1.7%CVE-2021-21335MEDIUMBasic Authentication can be bypassed using a malformed usernameEPSS 1.7%CVE-2018-5387—Wizkunde SAMLBase may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be aEPSS 1.7%CVE-2018-3761—Nextcloud Server before 12.0.8 and 13.0.3 suffer from improper authentication on the OAuth2 token endpoint. Missing checks potentially allowEPSS 1.7%CVE-2025-26326HIGHA vulnerability was identified in the NVDA Remote (version 2.6.4) and Tele NVDA Remote (version 2025.3.3) remote connection add-ons, which aEPSS 1.6%CVE-2020-15136MEDIUMImproper authentication in etcdEPSS 1.6%CVE-2019-15585—Improper authentication exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE) in the GitEPSS 1.6%CVE-2026-12571CRITICALAuthentication Bypass Leading to Account TakeoverEPSS 1.6%CVE-2022-22935LOWAn issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. A minion authentication denial of service can cause a MEPSS 1.6%