Falhas do tipo CWE-287

2.420 resultados

Autenticação Insuficiente ou Ausente

Quando um usuário ou sistema afirma ser quem diz que é, a aplicação não valida (ou valida mal) essa identidade antes de conceder acesso. Isso permite que um atacante se passe por outra pessoa sem fornecer credenciais válidas, obtendo privilégios indevidos.

Exemplo

Um sistema que aceita login apenas verificando um campo de e-mail na sessão (sem senha), ou uma API que confia em um identificador de usuário enviado no header HTTP sem validar um token assinado. Um atacante simplesmente muda o valor e acessa dados de terceiros.

Como mitigar

Implemente autenticação robusta: exija senha forte + MFA quando possível, valide tokens com assinatura criptográfica, revoque sessões expiradas, e nunca confie em dados controlados pelo cliente. Teste autenticação em cada endpoint crítico.

CVE-2022-22523HIGHCarlo Gavazzi UWP 3.0 WebApp allows for authentication bypassEPSS 0.7%CVE-2023-1617CRITICALImproper Authentication Mechanism in B&R VC4 VisualizationEPSS 0.7%CVE-2022-38180MEDIUMIn JetBrains Ktor before 2.1.0 the wrong authentication provider could be selected in some casesEPSS 0.7%CVE-2023-4373CRITICAL Inadequate validation of permissions when employing remote tools and macros within Devolutions Remote Desktop Manager versions 2023.2.19 anEPSS 0.7%CVE-2024-1006HIGHShanxi Diankeyun Technology NODERP Cookie common.php improper authenticationEPSS 0.7%CVE-2025-63224CRITICALThe Itel DAB Encoder (IDEnc build 25aec8d) is vulnerable to Authentication Bypass due to improper JWT validation across devices. Attackers cEPSS 0.7%CVE-2026-20129CRITICALCisco Catayst SD-WAN Authentication Bypass VulnerabilityEPSS 0.7%CVE-2024-24830CRITICALOpenObserve Privilege Escalation Vulnerability in Users APIEPSS 0.7%CVE-2023-34246MEDIUMDoorkeeper Improper Authentication vulnerabilityEPSS 0.7%CVE-2017-12281—A vulnerability in the implementation of Protected Extensible Authentication Protocol (PEAP) functionality for standalone configurations of EPSS 0.7%CVE-2022-0910MEDIUMA downgrade from two-factor authentication to one-factor authentication vulnerability in the CGI program of Zyxel USG/ZyWALL series firmwareEPSS 0.7%CVE-2026-29145CRITICALApache Tomcat, Apache Tomcat Native: OCSP checks sometimes soft-fail even when soft-fail is disabledEPSS 0.7%CVE-2017-20133HIGHItech Job Portal Script admin improper authenticationEPSS 0.7%CVE-2025-32877CRITICALAn issue was discovered on COROS PACE 3 devices through 3.0808.0. It identifies itself as a device without input or output capabilities, whiEPSS 0.7%CVE-2025-24032CRITICALPAM-PKCS#11 vulnerable to authentication bypass with default value for `cert_policy` (`none`)EPSS 0.7%CVE-2024-10173MEDIUMdidi DDMQ Console Module improper authenticationEPSS 0.7%CVE-2025-4494MEDIUMJAdmin-JAVA JAdmin Admin Backend NoNeedLoginController.java toLogin improper authenticationEPSS 0.7%CVE-2017-7937—An Improper Authentication issue was discovered in Phoenix Contact GmbH mGuard firmware versions 8.3.0 to 8.4.2. An attacker may be able to EPSS 0.7%CVE-2023-33190CRITICALImproperly configured permissions in SealosEPSS 0.7%CVE-2026-16209MEDIUMGerapy Project Upload Endpoint views.py missing authenticationEPSS 0.7%