Falhas do tipo CWE-287

2.437 resultados

Autenticação Insuficiente ou Ausente

Quando um usuário ou sistema afirma ser quem diz que é, a aplicação não valida (ou valida mal) essa identidade antes de conceder acesso. Isso permite que um atacante se passe por outra pessoa sem fornecer credenciais válidas, obtendo privilégios indevidos.

Exemplo

Um sistema que aceita login apenas verificando um campo de e-mail na sessão (sem senha), ou uma API que confia em um identificador de usuário enviado no header HTTP sem validar um token assinado. Um atacante simplesmente muda o valor e acessa dados de terceiros.

Como mitigar

Implemente autenticação robusta: exija senha forte + MFA quando possível, valide tokens com assinatura criptográfica, revoque sessões expiradas, e nunca confie em dados controlados pelo cliente. Teste autenticação em cada endpoint crítico.

CVE-2025-45777CRITICALAn issue in the OTP mechanism of Chavara Family Welfare Centre Chavara Matrimony Site v2.0 allows attackers to bypass authentication via supEPSS 0.7%CVE-2022-32928MEDIUMA logic issue was addressed with improved restrictions. This issue is fixed in iOS 16, macOS Ventura 13, watchOS 9. A user in a privileged nEPSS 0.7%CVE-2023-51478CRITICALWordPress Build App Online plugin <= 1.0.19 - Unauthenticated Account Takeover vulnerabilityEPSS 0.7%CVE-2024-1148CRITICALWeak Access Control - Arbitrary file uploadEPSS 0.7%CVE-2023-51477CRITICALWordPress BuddyBoss Theme theme <= 2.4.60 - Unauth. Arbitrary WordPress Settings Change vulnerabilityEPSS 0.7%CVE-2024-1147CRITICALWeak Access Control - Arbitrary file downloadEPSS 0.7%CVE-2023-51484CRITICALWordPress Login as User or Customer plugin <= 3.8 - Unauthenticated Account Takeover vulnerabilityEPSS 0.7%CVE-2026-15542MEDIUMwill-moss Isaiah Websocket Connection Authentication main.go improper authenticationEPSS 0.7%CVE-2025-7875MEDIUMMetasoft 美特软件 MetaCRM debug.jsp improper authenticationEPSS 0.7%CVE-2026-7630MEDIUMinnocommerce InnoShop Installation Endpoint InstallServiceProvider.php boot improper authenticationEPSS 0.7%CVE-2026-5616MEDIUMJeecgBoot AI Chat JeecgBizToolsProvider.java missing authenticationEPSS 0.7%CVE-2024-25699HIGHPortal for ArcGIS has an invalid authentication vulnerabilityEPSS 0.7%CVE-2026-90601MEDIUMgetzep graphiti REST API main.py improper authenticationEPSS 0.7%CVE-2026-90524MEDIUMjaychouchannel Tourism-Management-System Update Endpoint missing authenticationEPSS 0.7%CVE-2023-3337HIGHPuneethReddyHC Online Shopping System Advanced Admin Registration reg.php improper authenticationEPSS 0.7%CVE-2026-84423MEDIUMCasdoor upload-resource API resource.go missing authenticationEPSS 0.7%CVE-2026-81202MEDIUMitsourcecode Payroll System CRUD Operation ajax.php delete missing authenticationEPSS 0.7%CVE-2026-5676MEDIUMTotolink A8000R cstecgi.cgi setLanguageCfg missing authenticationEPSS 0.7%CVE-2026-85595CRITICALTraefik before v2.11.55 and v3.0.0 through v3.7.10 Authentication Bypass via digestAuthEPSS 0.7%CVE-2024-10097HIGHLoginizer Security and Loginizer <= 1.9.2 - Authentication Bypass via WordPress.com OAuth providerEPSS 0.7%