Falhas do tipo CWE-287

2.442 resultados

Autenticação Insuficiente ou Ausente

Quando um usuário ou sistema afirma ser quem diz que é, a aplicação não valida (ou valida mal) essa identidade antes de conceder acesso. Isso permite que um atacante se passe por outra pessoa sem fornecer credenciais válidas, obtendo privilégios indevidos.

Exemplo

Um sistema que aceita login apenas verificando um campo de e-mail na sessão (sem senha), ou uma API que confia em um identificador de usuário enviado no header HTTP sem validar um token assinado. Um atacante simplesmente muda o valor e acessa dados de terceiros.

Como mitigar

Implemente autenticação robusta: exija senha forte + MFA quando possível, valide tokens com assinatura criptográfica, revoque sessões expiradas, e nunca confie em dados controlados pelo cliente. Teste autenticação em cada endpoint crítico.

CVE-2022-39801HIGHSAP GRC Access control Emergency Access Management allows an authenticated attacker to access a Firefighter session even after it is closed EPSS 0.7%CVE-2024-10097HIGHLoginizer Security and Loginizer <= 1.9.2 - Authentication Bypass via WordPress.com OAuth providerEPSS 0.7%CVE-2015-5298—The Google Login Plugin (versions 1.0 and 1.1) allows malicious anonymous users to authenticate successfully against Jenkins instances that EPSS 0.7%CVE-2026-86669MEDIUMaircheng-org iWebShop-5 systemseller.php login improper authenticationEPSS 0.7%CVE-2024-27767CRITICALUnitronics Unistream Unilogic – Versions prior to 1.35.227 CWE-287: Improper AuthenticationEPSS 0.7%CVE-2026-14622MEDIUMjairiidriss restaurant-website-php-mysql AJAX Endpoint ajax_files missing authenticationEPSS 0.7%CVE-2023-51442HIGHAuthentication bypass vulnerability in navidrome's subsonic endpointEPSS 0.7%CVE-2026-8621HIGHCrabbox < v0.12.0 Authentication Bypass via Header SpoofingEPSS 0.7%CVE-2026-62896CRITICALMicrosoft Teams Elevation of Privilege VulnerabilityEPSS 0.7%CVE-2022-2757CRITICAL Due to the lack of adequately implemented access-control rules, all versions Kingspan TMS300 CS are vulnerable to an attacker viewing andEPSS 0.7%CVE-2026-30863CRITICALParse Server: JWT audience validation bypass in Google, Apple, and Facebook authentication adaptersEPSS 0.7%CVE-2023-23460CRITICALPriority Web – Authentication bypass EPSS 0.7%CVE-2026-8321MEDIUMinkeep agents runAuth Middleware runAuth.ts createDevContext authentication bypassEPSS 0.7%CVE-2026-86306MEDIUMlight0011 cms Cookie Helper UserModel.class.php improper authenticationEPSS 0.7%CVE-2026-87922MEDIUMRizwan17 inventory-management-system AJAX Backend process.php DBOperation.addCategory missing authenticationEPSS 0.7%CVE-2026-15557MEDIUMwaooAI waoowaoo Internal Task Header api-auth.ts requireProjectAuthLight improper authenticationEPSS 0.7%CVE-2026-6126MEDIUMzhayujie chatgpt-on-wechat CowAgent Administrative HTTP Endpoint missing authenticationEPSS 0.7%CVE-2026-47156CRITICALMantisBT: SOAP API Authentication Bypass with Privilege Escalation to AdministratorEPSS 0.7%CVE-2026-16210MEDIUMnewpanjing simpleui AjaxAdmin AJAX Endpoint admin.py self.get_action missing authenticationEPSS 0.7%CVE-2026-82758MEDIUMash_authentication_oauth2_server treats an empty resolved secret as valid, opening the gated Dynamic Client Registration endpointEPSS 0.7%