Falhas do tipo CWE-287

2.419 resultados

Autenticação Insuficiente ou Ausente

Quando um usuário ou sistema afirma ser quem diz que é, a aplicação não valida (ou valida mal) essa identidade antes de conceder acesso. Isso permite que um atacante se passe por outra pessoa sem fornecer credenciais válidas, obtendo privilégios indevidos.

Exemplo

Um sistema que aceita login apenas verificando um campo de e-mail na sessão (sem senha), ou uma API que confia em um identificador de usuário enviado no header HTTP sem validar um token assinado. Um atacante simplesmente muda o valor e acessa dados de terceiros.

Como mitigar

Implemente autenticação robusta: exija senha forte + MFA quando possível, valide tokens com assinatura criptográfica, revoque sessões expiradas, e nunca confie em dados controlados pelo cliente. Teste autenticação em cada endpoint crítico.

CVE-2022-23555CRITICALauthentik vulnerable to Improper Authentication via invitation URL token reuseEPSS 0.9%CVE-2025-14746MEDIUMNingyuanda TC155 RTSP Live Video Stream Endpoint improper authenticationEPSS 0.9%CVE-2025-27641CRITICALVasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.951 Application 20.0.2368 allows Unauthenticated APIs for Single-SigEPSS 0.9%CVE-2023-21721MEDIUMMicrosoft OneNote Elevation of Privilege VulnerabilityEPSS 0.9%CVE-2023-22334MEDIUMUse of password hash instead of password for authentication vulnerability in CONPROSYS HMI System (CHS) Ver.3.4.5 and earlier allows a remotEPSS 0.9%CVE-2020-11101CRITICALSierra Wireless AirLink Mobility Manager (AMM) before 2.17 mishandles sessions and thus an unauthenticated attacker can obtain a login sessiEPSS 0.9%CVE-2021-28494CRITICALIn Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, authentication iEPSS 0.9%CVE-2025-34186CRITICALIlevia EVE X1/X5 Server 4.7.18.0.eden Authentication BypassEPSS 0.9%CVE-2023-28609CRITICALapi/auth.go in Ansible Semaphore before 2.8.89 mishandles authentication.EPSS 0.9%CVE-2026-59822HIGHLiteLLM: MCP Authentication Bypass via OAuth2 Passthrough FallbackEPSS 0.9%KEVCVE-2020-15222HIGHReplay of private_key_jwt possible in ORY FositeEPSS 0.9%CVE-2022-31083HIGHAuthentication bypass in Parse Server Apple Game Center auth adapter EPSS 0.9%CVE-2023-35137HIGHAn improper authentication vulnerability in the authentication module of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmwEPSS 0.9%CVE-2025-48370LOWauth-js Vulnerable to Insecure Path Routing from Malformed User InputEPSS 0.9%CVE-2023-49340CRITICALAn issue was discovered in Newland Nquire 1000 Interactive Kiosk version NQ1000-II_G_V1.00.011, allows remote attackers to escalate privilegEPSS 0.9%CVE-2011-2054MEDIUMCisco ASA Secondary Authentication Bypass VulnerabilityEPSS 0.9%CVE-2025-6916HIGHTOTOLINK T6 formLoginAuth.htm Form_Login missing authenticationEPSS 0.9%CVE-2024-25128CRITICALFlask-AppBuilder incorrect authentication when using auth type OpenID EPSS 0.9%CVE-2022-21695MEDIUMImproper Access Control in OnionshareEPSS 0.9%CVE-2023-31634CRITICALIn TeslaMate before 1.27.2, there is unauthorized access to port 4000 for remote viewing and operation of user data. After accessing the IP EPSS 0.9%