Falhas do tipo CWE-287

2.419 resultados

Autenticação Insuficiente ou Ausente

Quando um usuário ou sistema afirma ser quem diz que é, a aplicação não valida (ou valida mal) essa identidade antes de conceder acesso. Isso permite que um atacante se passe por outra pessoa sem fornecer credenciais válidas, obtendo privilégios indevidos.

Exemplo

Um sistema que aceita login apenas verificando um campo de e-mail na sessão (sem senha), ou uma API que confia em um identificador de usuário enviado no header HTTP sem validar um token assinado. Um atacante simplesmente muda o valor e acessa dados de terceiros.

Como mitigar

Implemente autenticação robusta: exija senha forte + MFA quando possível, valide tokens com assinatura criptográfica, revoque sessões expiradas, e nunca confie em dados controlados pelo cliente. Teste autenticação em cada endpoint crítico.

CVE-2023-28862CRITICALAn issue was discovered in LemonLDAP::NG before 2.16.1. Weak session ID generation in the AuthBasic handler and incorrect failure handling dEPSS 1.0%CVE-2022-47633HIGHAn image signature validation bypass vulnerability in Kyverno 1.8.3 and 1.8.4 allows a malicious image registry (or a man-in-the-middle attaEPSS 1.0%CVE-2021-4230LOWAirfield Online MySQL Backup improper authenticationEPSS 1.0%CVE-2022-4002HIGHA command injection vulnerability could allow an authenticated user to execute operating system commands as root via a specially crafted APIEPSS 1.0%CVE-2021-28174MEDIUMMitake Smart Stock Selection System - Broken AuthenticationEPSS 1.0%CVE-2014-125060HIGHholdennb CollabCal calenderServer.cpp handleGet improper authenticationEPSS 1.0%CVE-2021-26077CRITICALBroken Authentication in Atlassian Connect Spring Boot (ACSB) in version 1.1.0 before 2.1.3 and from version 2.1.4 before 2.1.5: Atlassian CEPSS 1.0%CVE-2026-76187CRITICALApache Airflow Keycloak provider: Any realm client's credentials mint an Airflow session JWTEPSS 0.9%CVE-2022-36106MEDIUMMissing check for expiration time of password reset token in TYPO3EPSS 0.9%CVE-2020-26236HIGHVerification Code Hijacking in ScratchVerifierEPSS 0.9%CVE-2022-22730CRITICALImproper authentication in the Intel(R) Edge Insights for Industrial software before version 2.6.1 may allow an unauthenticated user to poteEPSS 0.9%CVE-2025-5495MEDIUMNetgear WNR614 URL improper authenticationEPSS 0.9%CVE-2021-32951MEDIUMAdvantech WebAccess/NMS Improper AuthenticationEPSS 0.9%CVE-2023-22303CRITICALTP-Link SG105PE firmware prior to 'TL-SG105PE(UN) 1.0_1.0.0 Build 20221208' contains an authentication bypass vulnerability. Under the certaEPSS 0.9%CVE-2023-31127CRITICALDMTF-2023-0001: SPDM mutual authentication bypassEPSS 0.9%CVE-2023-6344MEDIUMTyler Technologies Court Case Management Plus use of Aquaforest TIFF Server te003.aspx and te004.aspx allows authentication bypassEPSS 0.9%CVE-2023-6343MEDIUMTyler Technologies Court Case Management Plus use of Aquaforest TIFF Server tssp.aspx allows authentication bypassEPSS 0.9%CVE-2018-7340HIGHMultiple SAML libraries may allow authentication bypass via incorrect XML canonicalization and DOM traversalEPSS 0.9%CVE-2021-28495HIGHIn Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, user authenticatEPSS 0.9%CVE-2026-78168CRITICALEFM ipTIME T24000M Session Validation httpcon_check_session_url improper authenticationEPSS 0.9%