Falhas do tipo CWE-287

2.420 resultados

Autenticação Insuficiente ou Ausente

Quando um usuário ou sistema afirma ser quem diz que é, a aplicação não valida (ou valida mal) essa identidade antes de conceder acesso. Isso permite que um atacante se passe por outra pessoa sem fornecer credenciais válidas, obtendo privilégios indevidos.

Exemplo

Um sistema que aceita login apenas verificando um campo de e-mail na sessão (sem senha), ou uma API que confia em um identificador de usuário enviado no header HTTP sem validar um token assinado. Um atacante simplesmente muda o valor e acessa dados de terceiros.

Como mitigar

Implemente autenticação robusta: exija senha forte + MFA quando possível, valide tokens com assinatura criptográfica, revoque sessões expiradas, e nunca confie em dados controlados pelo cliente. Teste autenticação em cada endpoint crítico.

CVE-2022-32928MEDIUMA logic issue was addressed with improved restrictions. This issue is fixed in iOS 16, macOS Ventura 13, watchOS 9. A user in a privileged nEPSS 0.7%CVE-2023-51477CRITICALWordPress BuddyBoss Theme theme <= 2.4.60 - Unauth. Arbitrary WordPress Settings Change vulnerabilityEPSS 0.7%CVE-2024-1147CRITICALWeak Access Control - Arbitrary file downloadEPSS 0.7%CVE-2023-51478CRITICALWordPress Build App Online plugin <= 1.0.19 - Unauthenticated Account Takeover vulnerabilityEPSS 0.7%CVE-2024-1148CRITICALWeak Access Control - Arbitrary file uploadEPSS 0.7%CVE-2026-3053MEDIUMDataLinkDC dinky OpenAPI Endpoint AppConfig.java addInterceptors missing authenticationEPSS 0.7%CVE-2026-15542MEDIUMwill-moss Isaiah Websocket Connection Authentication main.go improper authenticationEPSS 0.7%CVE-2025-7875MEDIUMMetasoft 美特软件 MetaCRM debug.jsp improper authenticationEPSS 0.7%CVE-2026-90524MEDIUMjaychouchannel Tourism-Management-System Update Endpoint missing authenticationEPSS 0.7%CVE-2023-3337HIGHPuneethReddyHC Online Shopping System Advanced Admin Registration reg.php improper authenticationEPSS 0.7%CVE-2024-25699HIGHPortal for ArcGIS has an invalid authentication vulnerabilityEPSS 0.7%CVE-2022-39801HIGHSAP GRC Access control Emergency Access Management allows an authenticated attacker to access a Firefighter session even after it is closed EPSS 0.7%CVE-2024-10097HIGHLoginizer Security and Loginizer <= 1.9.2 - Authentication Bypass via WordPress.com OAuth providerEPSS 0.7%CVE-2025-52572CRITICALHikka vulnerable to RCE through dangling web interfaceEPSS 0.7%CVE-2020-36832CRITICALIndeed Membership Pro 7.3 - 8.6 - Authentication BypassEPSS 0.7%CVE-2015-5298—The Google Login Plugin (versions 1.0 and 1.1) allows malicious anonymous users to authenticate successfully against Jenkins instances that EPSS 0.7%CVE-2023-51442HIGHAuthentication bypass vulnerability in navidrome's subsonic endpointEPSS 0.7%CVE-2024-27767CRITICALUnitronics Unistream Unilogic – Versions prior to 1.35.227 CWE-287: Improper AuthenticationEPSS 0.7%CVE-2026-14622MEDIUMjairiidriss restaurant-website-php-mysql AJAX Endpoint ajax_files missing authenticationEPSS 0.7%CVE-2022-39264HIGHnheko vulnerable to secret poisoning using MITM on secret requests by the homeserverEPSS 0.7%