Falhas do tipo CWE-287

2.420 resultados

Autenticação Insuficiente ou Ausente

Quando um usuário ou sistema afirma ser quem diz que é, a aplicação não valida (ou valida mal) essa identidade antes de conceder acesso. Isso permite que um atacante se passe por outra pessoa sem fornecer credenciais válidas, obtendo privilégios indevidos.

Exemplo

Um sistema que aceita login apenas verificando um campo de e-mail na sessão (sem senha), ou uma API que confia em um identificador de usuário enviado no header HTTP sem validar um token assinado. Um atacante simplesmente muda o valor e acessa dados de terceiros.

Como mitigar

Implemente autenticação robusta: exija senha forte + MFA quando possível, valide tokens com assinatura criptográfica, revoque sessões expiradas, e nunca confie em dados controlados pelo cliente. Teste autenticação em cada endpoint crítico.

CVE-2023-3638CRITICALGeoVision GV-ADR2701 Improper AuthenticationEPSS 0.7%CVE-2023-46942HIGHLack of authentication in NPM's package @evershop/evershop before version 1.0.0-rc.8, allows remote attackers to obtain sensitive informatioEPSS 0.7%CVE-2023-51982CRITICALCrateDB 5.5.1 is contains an authentication bypass vulnerability in the Admin UI component. After configuring password authentication and_ LEPSS 0.7%CVE-2024-45148HIGHAdobe Commerce | Improper Authentication (CWE-287)EPSS 0.7%CVE-2026-94493CRITICALGigatech PDV5701 WebSocket Service index.html missing authenticationEPSS 0.7%CVE-2026-5229CRITICALReceive Notifications After Form Submitting – Form Notify for Any Forms <= 1.1.10 - Unauthenticated Authentication Bypass via LINE OAuth CallbackEPSS 0.7%CVE-2026-62827HIGHMicrosoft SharePoint Server Elevation of Privilege VulnerabilityEPSS 0.7%CVE-2021-40507CRITICALAn issue was discovered in the ALU unit of the OR1200 (aka OpenRISC 1200) processor 2011-09-10 through 2015-11-11. The overflow flag is not EPSS 0.7%CVE-2021-40506CRITICALAn issue was discovered in the ALU unit of the OR1200 (aka OpenRISC 1200) processor 2011-09-10 through 2015-11-11. The overflow flag is not EPSS 0.7%CVE-2020-5425HIGHUser Impersonation possible in Tanzu SSOEPSS 0.7%CVE-2023-30945CRITICALCVE-2023-30945 EPSS 0.7%CVE-2026-19977CRITICALEFM ipTIME A3004T Session Validation httpcon_check_session_url improper authenticationEPSS 0.7%CVE-2026-86293MEDIUMSourceCodester Simple Traffic Offense System Deletion Endpoint delete-user.php missing authenticationEPSS 0.7%CVE-2026-46840CRITICALVulnerability in Oracle REST Data Services (component: Backend-as-a-Service). Supported versions that are affected are 24.2.0-26.1.0. EasilEPSS 0.7%CVE-2023-44252HIGH** UNSUPPORTED WHEN ASSIGNED **An improper authentication vulnerability [CWE-287] in Fortinet FortiWAN version 5.2.0 through 5.2.1 and versiEPSS 0.7%CVE-2022-23654HIGHImproper write access check in Requarks/wikiEPSS 0.7%CVE-2026-48929HIGHRocket.Chat in versions <8.5.1, <8.4.4, <8.3.6, <8.2.6, <8.1.6, <8.0.7, <7.13.9, and <7.10.13 is vulnerable to unauthenticated file deletionEPSS 0.7%CVE-2023-45801HIGHImproper Authentication vulnerability in Nadatel DVR allows Information Elicitation.This issue affects DVR: from 3.0.0 before 9.9.0. EPSS 0.7%CVE-2026-16083MEDIUMSipeed PicoClaw LINE Webhook line.go webhook.ParseRequest authentication replayEPSS 0.7%CVE-2024-28735HIGHUnit4 Financials by Coda versions prior to 2023Q4 suffer from an incorrect access control authorization bypass vulnerability which allows anEPSS 0.7%