Falhas do tipo CWE-287

2.419 resultados

Autenticação Insuficiente ou Ausente

Quando um usuário ou sistema afirma ser quem diz que é, a aplicação não valida (ou valida mal) essa identidade antes de conceder acesso. Isso permite que um atacante se passe por outra pessoa sem fornecer credenciais válidas, obtendo privilégios indevidos.

Exemplo

Um sistema que aceita login apenas verificando um campo de e-mail na sessão (sem senha), ou uma API que confia em um identificador de usuário enviado no header HTTP sem validar um token assinado. Um atacante simplesmente muda o valor e acessa dados de terceiros.

Como mitigar

Implemente autenticação robusta: exija senha forte + MFA quando possível, valide tokens com assinatura criptográfica, revoque sessões expiradas, e nunca confie em dados controlados pelo cliente. Teste autenticação em cada endpoint crítico.

CVE-2022-36093HIGHXWiki Platform Web Templates vulnerable to Unauthorized User Registration Through the Distribution WizardEPSS 0.9%CVE-2020-5148—SonicWall SSO-agent default configuration uses NetAPI to probe the associated IP's in the network, this client probing method allows a potenEPSS 0.9%CVE-2019-5449—A missing check in the Nextcloud Server prior to version 15.0.1 causes leaking of calendar event names when adding or modifying confidentialEPSS 0.9%CVE-2020-7856HIGHA vulnerability of Helpcom could allow an unauthenticated attacker to execute arbitrary command. This vulnerability exists due to insufficieEPSS 0.9%CVE-2023-4562CRITICALInformation Disclosure, Information Tampering and Authentication Bypass Vulnerability in MELSEC-F Series main moduleEPSS 0.9%CVE-2022-38336HIGHAn access control issue in MobaXterm before v22.1 allows attackers to make connections to the server via the SSH or SFTP protocols without aEPSS 0.8%CVE-2022-3465HIGHMediabridge Medialink index.asp improper authenticationEPSS 0.8%CVE-2022-46170HIGHCodeIgniter is vulnerable to improper authentication via Session HandlersEPSS 0.8%CVE-2022-39289CRITICALDatabase log access in ZoneMinderEPSS 0.8%CVE-2026-56185MEDIUMWindows Admin Center Information Disclosure VulnerabilityEPSS 0.8%CVE-2022-35135HIGHBoodskap IoT Platform v4.4.9-02 allows attackers to escalate privileges via a crafted request sent to /api/user/upsert/<uuid>.EPSS 0.8%CVE-2021-41311HIGHAffected versions of Atlassian Jira Server and Data Center allow attackers with access to an administrator account that has had its access rEPSS 0.8%CVE-2024-1735CRITICALA vulnerability has been identified in armeria-saml versions less than 1.27.2, allowing the use of malicious SAML messages to bypass authentEPSS 0.8%CVE-2022-39255HIGHMatrix iOS SDK vulnerable ton Olm/Megolm protocol confusionEPSS 0.8%CVE-2022-39355CRITICALDiscourse Patreon vulnerable to improper validation of email during Patreon authenticationEPSS 0.8%CVE-2017-7557—dnsdist version 1.1.0 is vulnerable to a flaw in authentication mechanism for REST API potentially allowing CSRF attack.EPSS 0.8%CVE-2022-21684MEDIUMUser can bypass approval when invited to DiscourseEPSS 0.8%CVE-2026-47865CRITICALVMware Avi Load Balancer Authentication Bypass VulnerabilityEPSS 0.8%CVE-2025-43995CRITICALDell Storage Center - Dell Storage Manager, version(s) 20.1.21, contain(s) an Improper Authentication vulnerability. An unauthenticated attaEPSS 0.8%CVE-2025-44083CRITICALAn issue in D-Link DI-8100 16.07.26A1 allows a remote attacker to bypass administrator login authenticationEPSS 0.8%