Falhas do tipo CWE-287

2.420 resultados

Autenticação Insuficiente ou Ausente

Quando um usuário ou sistema afirma ser quem diz que é, a aplicação não valida (ou valida mal) essa identidade antes de conceder acesso. Isso permite que um atacante se passe por outra pessoa sem fornecer credenciais válidas, obtendo privilégios indevidos.

Exemplo

Um sistema que aceita login apenas verificando um campo de e-mail na sessão (sem senha), ou uma API que confia em um identificador de usuário enviado no header HTTP sem validar um token assinado. Um atacante simplesmente muda o valor e acessa dados de terceiros.

Como mitigar

Implemente autenticação robusta: exija senha forte + MFA quando possível, valide tokens com assinatura criptográfica, revoque sessões expiradas, e nunca confie em dados controlados pelo cliente. Teste autenticação em cada endpoint crítico.

CVE-2023-25597MEDIUMA vulnerability in the web conferencing component of Mitel MiCollab through 9.6.2.9 could allow an unauthenticated attacker to download a shEPSS 0.7%CVE-2022-36296MEDIUMWordPress ActiveDEMAND plugin <= 0.2.27 - Broken Authentication vulnerabilityEPSS 0.7%CVE-2023-44752CRITICALAn issue in Student Study Center Desk Management System v1.0 allows attackers to bypass authentication via a crafted GET request to /php-sscEPSS 0.7%CVE-2026-4664MEDIUMCustomer Reviews for WooCommerce <= 5.103.0 - Unauthenticated Authentication Bypass to Arbitrary Review Submission via 'key' ParameterEPSS 0.7%CVE-2025-60424HIGHA lack of rate limiting in the OTP verification component of Nagios Fusion v2024R1.2 and v2024R2 allows attackers to bypass authentication vEPSS 0.7%CVE-2022-2664HIGHPrivate Cloud Management Platform POST Request global_config_query improper authenticationEPSS 0.7%CVE-2026-50559HIGHAuthentication/Authorization Bypass via Advanced Path Normalization VulnerabilitiesEPSS 0.7%CVE-2022-39009CRITICALThe WLAN module has a vulnerability in permission verification. Successful exploitation of this vulnerability may cause third-party apps to EPSS 0.7%CVE-2026-47159MEDIUMVaultwarden: Authentication Flow Information Disclosure in SSO Discovery Allows Organization Enumeration and Pre-Validation Token ExposureEPSS 0.7%CVE-2023-32347HIGH Teltonika’s Remote Management System versions prior to 4.10.0 use device serial numbers and MAC addresses to identify devices from the userEPSS 0.7%CVE-2026-56162CRITICALAzure SQL Database Elevation of Privilege VulnerabilityEPSS 0.7%CVE-2026-5270CRITICALAuthentication Bypass in Navigator and Blue Planet ProductsEPSS 0.7%CVE-2026-55445CRITICALQinglong: Incomplete fix for CVE-2026-3965: Improper AuthenticationEPSS 0.7%CVE-2026-61740CRITICALLightRAG: Authentication bypass: hardcoded DEFAULT_TOKEN_SECRET and public /auth-status defeat LIGHTRAG_API_KEY protectionEPSS 0.7%CVE-2025-4019MEDIUM20120630 Novel-Plus GeneratorController.java genCode missing authenticationEPSS 0.7%CVE-2026-8305MEDIUMOpenClaw bluebubbles Webhook monitor.ts handleBlueBubblesWebhookRequest improper authenticationEPSS 0.7%CVE-2026-86810MEDIUMOpen-Web-Analytics Controller Controller.php checkCapabilityAndAuthenticateUser improper authenticationEPSS 0.7%CVE-2020-7293CRITICALWeb Gateway (MWG) - Privilege Escalation vulnerabilityEPSS 0.7%CVE-2023-35940HIGHGLPI vulnerable to unauthenticated access to Dashboard dataEPSS 0.7%CVE-2022-23554MEDIUMAuthentication bypass in AlpineEPSS 0.7%