Falhas do tipo CWE-287

2.419 resultados

Autenticação Insuficiente ou Ausente

Quando um usuário ou sistema afirma ser quem diz que é, a aplicação não valida (ou valida mal) essa identidade antes de conceder acesso. Isso permite que um atacante se passe por outra pessoa sem fornecer credenciais válidas, obtendo privilégios indevidos.

Exemplo

Um sistema que aceita login apenas verificando um campo de e-mail na sessão (sem senha), ou uma API que confia em um identificador de usuário enviado no header HTTP sem validar um token assinado. Um atacante simplesmente muda o valor e acessa dados de terceiros.

Como mitigar

Implemente autenticação robusta: exija senha forte + MFA quando possível, valide tokens com assinatura criptográfica, revoque sessões expiradas, e nunca confie em dados controlados pelo cliente. Teste autenticação em cada endpoint crítico.

CVE-2022-39251HIGHMatrix Javascript SDK vulnerable to Olm/Megolm protocol confusionEPSS 1.0%CVE-2021-43834CRITICALIncorrect Authentication in elabftwEPSS 1.0%CVE-2024-0988MEDIUMSichuan Yougou Technology KuERP common.php checklogin improper authenticationEPSS 1.0%CVE-2021-38686HIGHImproper Authentication Vulnerability in VioStorEPSS 1.0%CVE-2026-58399HIGH@acastellon/auth has an authentication bypass via spoofable headers in validateToken()EPSS 1.0%CVE-2024-10511MEDIUMCWE-287: Improper Authentication vulnerability exists that could cause Denial of access to the web interface when someone on the local netwoEPSS 1.0%CVE-2022-39387CRITICALXWiki OIDC Authenticator vulnerable to OpenID login bypass due to improper authentication EPSS 1.0%CVE-2023-1460MEDIUMSourceCodester Online Pizza Ordering System Password Change improper authenticationEPSS 1.0%CVE-2025-58060HIGHcups has Authentication bypass with AuthType NegotiateEPSS 1.0%CVE-2017-6617—A vulnerability in the session identification management functionality of the web-based GUI of Cisco Integrated Management Controller (IMC) EPSS 1.0%CVE-2024-12510MEDIUMLDAP Authentication Sever Pass-back attackEPSS 1.0%CVE-2013-10004MEDIUMTelecommunication Software SAMwin Contact Center Suite Password SAMwinLIBVB.dll passwordScramble improper authenticationEPSS 1.0%CVE-2022-30238HIGHA CWE-287: Improper Authentication vulnerability exists that could allow an attacker to take over the admin account when an attacker hijacksEPSS 1.0%CVE-2021-34578CRITICALWAGO: Authentication Vulnerability in Web-Based ManagementEPSS 1.0%CVE-2017-20237CRITICALHirschmann Industrial HiVision Authentication Bypass Remote Code ExecutionEPSS 1.0%CVE-2023-25264HIGHAn issue was discovered in Docmosis Tornado prior to version 2.9.5. An unauthenticated attacker can bypass the authentication check filter cEPSS 1.0%CVE-2022-1084HIGHSourceCodester One Church Management System Session userregister.php improper authenticationEPSS 1.0%CVE-2026-23600CRITICALA remote authentication bypass vulnerability  exists in HPE AutoPass License Server (APLS).EPSS 1.0%CVE-2024-5044MEDIUMEmlog Pro Cookie improper authenticationEPSS 1.0%CVE-2022-34155HIGHWordPress OAuth Single Sign On – SSO (OAuth Client) Plugin <= 6.23.3 is vulnerable to Broken AuthenticationEPSS 1.0%