Falhas do tipo CWE-287

2.419 resultados

Autenticação Insuficiente ou Ausente

Quando um usuário ou sistema afirma ser quem diz que é, a aplicação não valida (ou valida mal) essa identidade antes de conceder acesso. Isso permite que um atacante se passe por outra pessoa sem fornecer credenciais válidas, obtendo privilégios indevidos.

Exemplo

Um sistema que aceita login apenas verificando um campo de e-mail na sessão (sem senha), ou uma API que confia em um identificador de usuário enviado no header HTTP sem validar um token assinado. Um atacante simplesmente muda o valor e acessa dados de terceiros.

Como mitigar

Implemente autenticação robusta: exija senha forte + MFA quando possível, valide tokens com assinatura criptográfica, revoque sessões expiradas, e nunca confie em dados controlados pelo cliente. Teste autenticação em cada endpoint crítico.

CVE-2019-14880MEDIUMA vulnerability was found in Moodle versions 3.7 before 3.7.3, 3.6 before 3.6.7, 3.5 before 3.5.9 and earlier. OAuth 2 providers who do not EPSS 1.1%CVE-2023-52161HIGHThe Access Point functionality in eapol_auth_key_handle in eapol.c in iNet wireless daemon (IWD) before 2.14 allows attackers to gain unauthEPSS 1.1%CVE-2025-37093CRITICALAn authentication bypass vulnerability exists in HPE StoreOnce Software.EPSS 1.1%CVE-2022-38119CRITICALPOWERCOM CO., LTD. UPSMON PRO - Broken AuthenticationEPSS 1.1%CVE-2022-20733MEDIUMCisco Identity Services Engine Authentication Bypass VulnerabilityEPSS 1.1%CVE-2023-2024CRITICALImproper Authentication for OpenBlue Enterprise Manager Data CollectorEPSS 1.1%CVE-2018-0435—Cisco Umbrella API Unauthorized Access VulnerabilityEPSS 1.1%CVE-2023-29032HIGHApache OpenMeetings: allows bypass authenticationEPSS 1.1%CVE-2022-2765MEDIUMSourceCodester Company Website CMS settings improper authenticationEPSS 1.1%CVE-2021-41126HIGHDeleted Admin Can Sign In to Admin InterfaceEPSS 1.1%CVE-2020-16098CRITICALIt is possible to enumerate access card credentials via an unauthenticated network connection to the server in versions of Command Centre v8EPSS 1.1%CVE-2021-3827—A flaw was found in keycloak, where the default ECP binding flow allows other authentication flows to be bypassed. By exploiting this behaviEPSS 1.1%CVE-2026-53913CRITICALApache Camel Keycloak: KeycloakSecurityPolicy verifies the bearer access token only inside its role and permission checks, so in the default configuration the token is never verified and any non-null bearer value is acceptedEPSS 1.1%CVE-2025-11942MEDIUM70mai X200 Pairing missing authenticationEPSS 1.1%CVE-2024-23629CRITICALMotorola MR2600 Authentication Bypass VulnerabilityEPSS 1.1%CVE-2022-42458CRITICALAuthentication bypass using an alternate path or channel vulnerability in bingo!CMS version1.7.4.1 and earlier allows a remote unauthenticatEPSS 1.1%CVE-2019-18312—A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 ServEPSS 1.1%CVE-2019-14909CRITICALA vulnerability was found in Keycloak 7.x where the user federation LDAP bind type is none (LDAP anonymous bind), any password, invalid or vEPSS 1.1%CVE-2025-7862MEDIUMTOTOLINK T6 Telnet Service cstecgi.cgi setTelnetCfg missing authenticationEPSS 1.1%CVE-2017-12712—The authentication algorithm in Abbott Laboratories pacemakers manufactured prior to Aug 28, 2017, which involves an authentication key and EPSS 1.1%