Falhas do tipo CWE-287

2.446 resultados

Autenticação Insuficiente ou Ausente

Quando um usuário ou sistema afirma ser quem diz que é, a aplicação não valida (ou valida mal) essa identidade antes de conceder acesso. Isso permite que um atacante se passe por outra pessoa sem fornecer credenciais válidas, obtendo privilégios indevidos.

Exemplo

Um sistema que aceita login apenas verificando um campo de e-mail na sessão (sem senha), ou uma API que confia em um identificador de usuário enviado no header HTTP sem validar um token assinado. Um atacante simplesmente muda o valor e acessa dados de terceiros.

Como mitigar

Implemente autenticação robusta: exija senha forte + MFA quando possível, valide tokens com assinatura criptográfica, revoque sessões expiradas, e nunca confie em dados controlados pelo cliente. Teste autenticação em cada endpoint crítico.

CVE-2026-86292MEDIUMSourceCodester Simple Traffic Offense System User Creation saveuser.php missing authenticationEPSS 0.7%CVE-2026-86306MEDIUMlight0011 cms Cookie Helper UserModel.class.php improper authenticationEPSS 0.7%CVE-2026-92401MEDIUMChangeWeDer crm improper authenticationEPSS 0.7%CVE-2026-6126MEDIUMzhayujie chatgpt-on-wechat CowAgent Administrative HTTP Endpoint missing authenticationEPSS 0.7%CVE-2022-24901HIGHAuthentication bypass and denial of service (DoS) vulnerabilities in Apple Game Center auth adapter EPSS 0.7%CVE-2026-61435HIGHPraisonAI before 4.6.78 Authentication Bypass via Host Header SpoofingEPSS 0.7%CVE-2022-48364MEDIUMThe undo_mark_statuses_as_sensitive method in app/services/approve_appeal_service.rb in Mastodon 3.5.x before 3.5.3 does not use the server'EPSS 0.7%CVE-2026-50561CRITICALYuxi has a JWT Authentication Bypass Leading to Cross-Instance Administrator Token ReuseEPSS 0.7%CVE-2023-43793HIGHMisskey allows users to bypass authentication of Bull dashboardEPSS 0.7%CVE-2026-37270CRITICALTrueview Security camera T18161- AF v4.9.60.0 contains an authentication bypass vulnerability caused by improper password validation and theEPSS 0.7%CVE-2024-22206CRITICAL@clerk/nextjs auth() and getAuth() methods vulnerable to insecure direct object reference (IDOR)EPSS 0.7%CVE-2023-22497MEDIUMNetdata is vulnerable to improper authenticationEPSS 0.7%CVE-2025-14703MEDIUMShiguangwu sgwbox N3 POST Message fsnotify improper authenticationEPSS 0.7%CVE-2026-40165HIGHauthentik: SAML NameID XML Comment Injection Enables Authentication Bypass via Identifier TruncationEPSS 0.7%CVE-2026-4187MEDIUMTiandy Easy7 Integrated Management Platform Device Identifier UpdateLocalDevInfo.jsp missing authenticationEPSS 0.7%CVE-2026-18610MEDIUMNewType WebEIP EIP_Com_FileList.aspx improper authenticationEPSS 0.7%CVE-2024-47080HIGHmatrix-js-sdk keys sent via `sendSharedHistoryKeys` vulnerable to interception by malicious homeserverEPSS 0.7%CVE-2019-13423—Search Guard Kibana Plugin versions before 5.6.8-7 and before 6.x.y-12 had an issue that an authenticated Kibana user could impersonate as kEPSS 0.7%CVE-2024-11494HIGH**UNSUPPORTED WHEN ASSIGNED** The improper authentication vulnerability in the Zyxel P-6101C ADSL modem firmware version P-6101CSA6AP_201403EPSS 0.7%CVE-2025-60534CRITICALBlue Access Cobalt v02.000.195 suffers from an authentication bypass vulnerability, which allows an attacker to selectively proxy requests iEPSS 0.7%