Falhas do tipo CWE-287

2.420 resultados

Autenticação Insuficiente ou Ausente

Quando um usuário ou sistema afirma ser quem diz que é, a aplicação não valida (ou valida mal) essa identidade antes de conceder acesso. Isso permite que um atacante se passe por outra pessoa sem fornecer credenciais válidas, obtendo privilégios indevidos.

Exemplo

Um sistema que aceita login apenas verificando um campo de e-mail na sessão (sem senha), ou uma API que confia em um identificador de usuário enviado no header HTTP sem validar um token assinado. Um atacante simplesmente muda o valor e acessa dados de terceiros.

Como mitigar

Implemente autenticação robusta: exija senha forte + MFA quando possível, valide tokens com assinatura criptográfica, revoque sessões expiradas, e nunca confie em dados controlados pelo cliente. Teste autenticação em cada endpoint crítico.

CVE-2024-11186CRITICALOn affected versions of the CloudVision Portal, improper access controls could enable a malicious authenticated user to take broader actions on managed EOS devices than intended. This advisory impacts the Arista CloudVision Portal products when run on-premEPSS 0.8%CVE-2020-20402HIGHWestbrookadmin portfolioCMS v1.05 allows attackers to bypass password validation and access sensitive information via session fixation.EPSS 0.7%CVE-2025-46548MEDIUMApache Pekko Management, Apache Pekko Management, Apache Pekko Management, Akka Management, Akka Management, Akka Management: management API basic authentication is not effectiveEPSS 0.7%CVE-2022-35726MEDIUMWordPress Video Gallery plugin <= 1.3.4.5 - Broken Authentication vulnerabilityEPSS 0.7%CVE-2023-37283HIGHAuthentication Bypass via HTML Form & Identifier First AdapterEPSS 0.7%CVE-2024-22394CRITICALAn improper authentication vulnerability has been identified in SonicWall SonicOS SSL-VPN feature, which in specific conditions could allow EPSS 0.7%CVE-2026-82694CRITICALTenda AC1206 Web UI ate R7WebsSecurityHandler missing authenticationEPSS 0.7%CVE-2023-6787MEDIUMKeycloak: session hijacking via re-authenticationEPSS 0.7%CVE-2021-38679MEDIUMImproper Authentication in Kazoo ServerEPSS 0.7%CVE-2025-63216CRITICALThe Itel DAB Gateway (IDGat build c041640a) is vulnerable to Authentication Bypass due to improper JWT validation across devices. Attackers EPSS 0.7%CVE-2024-28012CRITICALImproper authentication vulnerability in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WEPSS 0.7%CVE-2026-82695CRITICALTenda AC18 Telnet telnet missing authenticationEPSS 0.7%CVE-2018-16496—In Versa Director, the un-authentication request found.EPSS 0.7%CVE-2024-33110CRITICALD-Link DIR-845L router v1.01KRb03 and before is vulnerable to Permission Bypass via the getcfg.php component.EPSS 0.7%CVE-2022-43549CRITICALImproper authentication in Veeam Backup for Google Cloud v1.0 and v3.0 allows attackers to bypass authentication mechanisms.EPSS 0.7%CVE-2022-2533MEDIUMAn issue has been discovered in GitLab affecting all versions starting from 12.10 before 15.1.6, all versions starting from 15.2 before 15.2EPSS 0.7%CVE-2026-23813CRITICALAuthentication Bypass in Web Interface allows Unauthenticated Admin Password ResetEPSS 0.7%CVE-2023-21841HIGHVulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected areEPSS 0.7%CVE-2024-12264CRITICALPayU CommercePro Plugin <= 3.8.3 - Unauthenticated Privilege EscalationEPSS 0.7%CVE-2026-32136CRITICALAdGuard Home: HTTP/2 Cleartext (h2c) Upgrade Authentication BypassEPSS 0.7%