Falhas do tipo CWE-287

2.420 resultados

Autenticação Insuficiente ou Ausente

Quando um usuário ou sistema afirma ser quem diz que é, a aplicação não valida (ou valida mal) essa identidade antes de conceder acesso. Isso permite que um atacante se passe por outra pessoa sem fornecer credenciais válidas, obtendo privilégios indevidos.

Exemplo

Um sistema que aceita login apenas verificando um campo de e-mail na sessão (sem senha), ou uma API que confia em um identificador de usuário enviado no header HTTP sem validar um token assinado. Um atacante simplesmente muda o valor e acessa dados de terceiros.

Como mitigar

Implemente autenticação robusta: exija senha forte + MFA quando possível, valide tokens com assinatura criptográfica, revoque sessões expiradas, e nunca confie em dados controlados pelo cliente. Teste autenticação em cada endpoint crítico.

CVE-2025-7955CRITICALRingCentral Communications 1.5 - 1.6.8 - Missing Server‑Side Verification to Authentication Bypass via ringcentral_admin_login_2fa_verify FunctionEPSS 0.7%CVE-2024-4303HIGH ArmorX Android APP - MFA BypassEPSS 0.7%CVE-2026-62825CRITICALAzure Key Vault Elevation of Privilege VulnerabilityEPSS 0.7%CVE-2023-22278MEDIUMm-FILTER prior to Ver.5.70R01 (Ver.5 Series) and m-FILTER prior to Ver.4.87R04 (Ver.4 Series) allows a remote unauthenticated attacker to byEPSS 0.7%CVE-2022-36133CRITICALThe WebConfig functionality of Epson TM-C3500 and TM-C7500 devices with firmware version WAM31500 allows authentication bypass.EPSS 0.7%CVE-2025-54376HIGHHoverfly's WebSocket endpoint `/api/v2/ws/logs` reachable without authentication even when --auth is enabled.EPSS 0.7%CVE-2022-39246HIGHmatrix-android-sdk2 vulnerable to impersonation via forwarded Megolm sessionsEPSS 0.7%CVE-2026-25893CRITICALFUXA Unauthenticated Remote Code Execution via Admin JWT MintingEPSS 0.7%CVE-2020-18305HIGHExtreme Networks EXOS before v.22.7 and before v.30.2 was discovered to contain an issue in its Web GUI which fails to restrict URL access, EPSS 0.7%CVE-2023-51484CRITICALWordPress Login as User or Customer plugin <= 3.8 - Unauthenticated Account Takeover vulnerabilityEPSS 0.7%CVE-2025-15455MEDIUMbg5sbk MiniCMS File Recovery Request page.php delete_page improper authenticationEPSS 0.7%CVE-2025-0070CRITICALImproper Authentication in SAP NetWeaver ABAP Server and ABAP PlatformEPSS 0.7%CVE-2023-0105MEDIUMA flaw was found in Keycloak. This flaw allows impersonation and lockout due to the email trust not being handled correctly in Keycloak. An EPSS 0.7%CVE-2025-26685MEDIUMMicrosoft Defender for Identity Spoofing VulnerabilityEPSS 0.7%CVE-2021-32646MEDIUMEscalation of permissions in roomerEPSS 0.7%CVE-2026-8508MEDIUMAn improper authentication vulnerability in the "social_login.cgi" CGI program in Zyxel WAX650S firmware versions through 7.10(ABRM.4)C0 couEPSS 0.7%CVE-2023-41956HIGHWordPress Simple Membership plugin <= 4.3.4 - Authenticated Account Takeover vulnerabilityEPSS 0.7%CVE-2023-7079MEDIUMArbitrary remote file read in Wrangler dev serverEPSS 0.7%CVE-2024-2112MEDIUMForm Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder <= 1.15.22 - Sensitive Information ExposureEPSS 0.7%CVE-2025-45777CRITICALAn issue in the OTP mechanism of Chavara Family Welfare Centre Chavara Matrimony Site v2.0 allows attackers to bypass authentication via supEPSS 0.7%