Falhas do tipo CWE-287

2.420 resultados

Autenticação Insuficiente ou Ausente

Quando um usuário ou sistema afirma ser quem diz que é, a aplicação não valida (ou valida mal) essa identidade antes de conceder acesso. Isso permite que um atacante se passe por outra pessoa sem fornecer credenciais válidas, obtendo privilégios indevidos.

Exemplo

Um sistema que aceita login apenas verificando um campo de e-mail na sessão (sem senha), ou uma API que confia em um identificador de usuário enviado no header HTTP sem validar um token assinado. Um atacante simplesmente muda o valor e acessa dados de terceiros.

Como mitigar

Implemente autenticação robusta: exija senha forte + MFA quando possível, valide tokens com assinatura criptográfica, revoque sessões expiradas, e nunca confie em dados controlados pelo cliente. Teste autenticação em cada endpoint crítico.

CVE-2025-7574CRITICALLB-LINK BL-WR9000 Web Interface lighttpd.cgi restore improper authenticationEPSS 0.8%CVE-2024-10963HIGHPam: improper hostname interpretation in pam_access leads to access control bypassEPSS 0.8%CVE-2022-31131MEDIUMOwnership check missing when updating or deleting mail attachments in Nextcloud mailEPSS 0.8%CVE-2022-22289MEDIUMImproper access control vulnerability in S Assistant prior to version 7.5 allows attacker to remotely get senstive information.EPSS 0.8%CVE-2024-25313HIGHCode-projects Simple School Managment System 1.0 allows Authentication Bypass via the username and password parameters at School/teacher_logEPSS 0.8%CVE-2022-21692MEDIUMImproper Access Control in OnionshareEPSS 0.8%CVE-2024-1817HIGHDemososo DM Enterprise Website Building System Cookie indexDM_load.php dmlogin improper authenticationEPSS 0.8%CVE-2022-39267HIGHBrokercap Bifrost vulnerable to authentication bypass for admin and monitor user groupsEPSS 0.8%CVE-2021-3424—A flaw was found in keycloak as shipped in Red Hat Single Sign-On 7.4 where IDN homograph attacks are possible. A malicious user can registeEPSS 0.8%CVE-2025-3268MEDIUMqinguoyi TinyWebServer http_conn.cpp improper authenticationEPSS 0.8%CVE-2025-5512MEDIUMquequnlong shiyi-blog Administrator Backend verifyPassword improper authenticationEPSS 0.8%CVE-2022-23505MEDIUMPassport-wsfed-saml2 vulnerable to Authentication Bypass for WSFed authenticationEPSS 0.8%CVE-2024-7012CRITICALPuppet-foreman: an authentication bypass vulnerability exists in foremanEPSS 0.8%CVE-2025-14567MEDIUMhaxxorsid Stock-Management-System employees missing authenticationEPSS 0.8%CVE-2023-5329MEDIUMField Logic DataCube4 Web API improper authenticationEPSS 0.8%CVE-2026-32174HIGHAzure Bot Service Elevation of Privilege VulnerabilityEPSS 0.8%CVE-2019-15620—Improper access control in Nextcloud Talk 6.0.3 leaks the existance and the name of private conversations when linked them to another sharedEPSS 0.8%CVE-2024-13111MEDIUMBeijing Yunfan Internet Technology Yunfan Learning Examination System JWT Token SysUserControl improper authenticationEPSS 0.8%CVE-2018-17928—The product CMS-770 (Software Versions 1.7.1 and prior)is vulnerable that an attacker can read sensitive configuration files by bypassing thEPSS 0.8%CVE-2024-7401HIGHClient Enrollment Process BypassEPSS 0.8%