Falhas do tipo CWE-287

2.419 resultados

Autenticação Insuficiente ou Ausente

Quando um usuário ou sistema afirma ser quem diz que é, a aplicação não valida (ou valida mal) essa identidade antes de conceder acesso. Isso permite que um atacante se passe por outra pessoa sem fornecer credenciais válidas, obtendo privilégios indevidos.

Exemplo

Um sistema que aceita login apenas verificando um campo de e-mail na sessão (sem senha), ou uma API que confia em um identificador de usuário enviado no header HTTP sem validar um token assinado. Um atacante simplesmente muda o valor e acessa dados de terceiros.

Como mitigar

Implemente autenticação robusta: exija senha forte + MFA quando possível, valide tokens com assinatura criptográfica, revoque sessões expiradas, e nunca confie em dados controlados pelo cliente. Teste autenticação em cada endpoint crítico.

CVE-2022-24738HIGHAccount compromise in EvmosEPSS 1.1%CVE-2015-10083MEDIUMharrystech Dynosaur-Rails application_controller.rb basic_auth improper authenticationEPSS 1.1%CVE-2019-18320—A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker with network accessEPSS 1.1%CVE-2022-40602CRITICALA flaw in the Zyxel LTE3301-M209 firmware verisons prior to V1.00(ABLG.6)C0 could allow a remote attacker to access the device using an imprEPSS 1.1%CVE-2020-15269HIGHExpired token reuse in SpreeEPSS 1.1%CVE-2022-39249HIGHMatrix Javascript SDK vulnerable to impersonation via forwarded Megolm sessionsEPSS 1.1%CVE-2024-20738CRITICALAdobe FrameMaker Publishing Server Authentication Bypass Vulnerability | CVE-2023-44324 bypassEPSS 1.1%CVE-2023-2283—A vulnerability was found in libssh, where the authentication check of the connecting client can be bypassed in the`pki_verify_data_signaturEPSS 1.1%CVE-2018-0116—A vulnerability in the RADIUS authentication module of Cisco Policy Suite could allow an unauthenticated, remote attacker to be authorized aEPSS 1.1%CVE-2021-33539HIGHWEIDMUELLER: WLAN devices affected by authentication bypass vulnerabilityEPSS 1.1%CVE-2022-25027HIGHThe Forgotten Password functionality of Rocket TRUfusion Portal v7.9.2.1 allows remote attackers to bypass authentication and access restricEPSS 1.1%CVE-2023-39349HIGHSentry vulnerable to privilege escalation via ApiTokensEndpointEPSS 1.1%CVE-2025-4268MEDIUMTOTOLINK A720R cstecgi.cgi missing authenticationEPSS 1.1%CVE-2025-64513CRITICALMilvus Proxy has Critical Authentication Bypass VulnerabilityEPSS 1.1%CVE-2020-8148—UniFi Cloud Key firmware < 1.1.6 contains a vulnerability that enables an attacker being able to change a device hostname by sending a malicEPSS 1.1%CVE-2019-14910CRITICALA vulnerability was found in keycloak 7.x, when keycloak is configured with LDAP user federation and StartTLS is used instead of SSL/TLS froEPSS 1.1%CVE-2022-44244MEDIUMAn authentication bypass in Lin-CMS v0.2.1 allows attackers to escalate privileges to Super Administrator.EPSS 1.1%CVE-2026-23906CRITICALApache Druid: Authentication Bypass via LDAP Anonymous BindEPSS 1.1%CVE-2022-36092HIGHXWiki Platform Old Core vulnerable to Authentication Bypass Using the Login ActionEPSS 1.1%CVE-2022-43620HIGHThis vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-1935 1.03 routers. AutEPSS 1.1%