Falhas do tipo CWE-287

2.446 resultados

Autenticação Insuficiente ou Ausente

Quando um usuário ou sistema afirma ser quem diz que é, a aplicação não valida (ou valida mal) essa identidade antes de conceder acesso. Isso permite que um atacante se passe por outra pessoa sem fornecer credenciais válidas, obtendo privilégios indevidos.

Exemplo

Um sistema que aceita login apenas verificando um campo de e-mail na sessão (sem senha), ou uma API que confia em um identificador de usuário enviado no header HTTP sem validar um token assinado. Um atacante simplesmente muda o valor e acessa dados de terceiros.

Como mitigar

Implemente autenticação robusta: exija senha forte + MFA quando possível, valide tokens com assinatura criptográfica, revoque sessões expiradas, e nunca confie em dados controlados pelo cliente. Teste autenticação em cada endpoint crítico.

CVE-2025-66022CRITICALFACTION Unauthenticated Custom Extension Upload leads to RCEEPSS 0.7%CVE-2026-8737MEDIUMSanluan PublicCMS Trade Address Query TradeAddressListDirective.java execute missing authenticationEPSS 0.7%CVE-2026-8244MEDIUMIndustrial Application Software IAS Canias ERP Login RMI improper authenticationEPSS 0.7%CVE-2026-94151MEDIUMOmega Solution HRM OS Role Permission API permission missing authenticationEPSS 0.7%CVE-2026-8214MEDIUMIndustrial Application Software IAS Canias ERP RMI doAction improper authenticationEPSS 0.7%CVE-2026-8031MEDIUMPicoTronica e-Clinic Healthcare System ECHS API Endpoint patient-records missing authenticationEPSS 0.7%CVE-2025-7897MEDIUMharry0703 MoneyPrinterTurbo API Endpoint base.py verify_token missing authenticationEPSS 0.7%CVE-2023-25597MEDIUMA vulnerability in the web conferencing component of Mitel MiCollab through 9.6.2.9 could allow an unauthenticated attacker to download a shEPSS 0.7%CVE-2022-36296MEDIUMWordPress ActiveDEMAND plugin <= 0.2.27 - Broken Authentication vulnerabilityEPSS 0.7%CVE-2023-44752CRITICALAn issue in Student Study Center Desk Management System v1.0 allows attackers to bypass authentication via a crafted GET request to /php-sscEPSS 0.7%CVE-2026-86117CRITICALCoolify through 4.3.17 OAuth Account Takeover via Unverified Email MatchingEPSS 0.7%CVE-2025-60424HIGHA lack of rate limiting in the OTP verification component of Nagios Fusion v2024R1.2 and v2024R2 allows attackers to bypass authentication vEPSS 0.7%CVE-2026-8994HIGHLogin with NEAR <= 0.3.3 - Authentication Bypass via 'account' ParameterEPSS 0.7%CVE-2022-2664HIGHPrivate Cloud Management Platform POST Request global_config_query improper authenticationEPSS 0.7%CVE-2026-19342MEDIUMcode-projects Task Management System Login index.php improper authenticationEPSS 0.7%CVE-2026-28408CRITICALWeGIA lacks authentication verification in adicionar_tipo_docs_atendido.phpEPSS 0.7%CVE-2022-47408CRITICALAn issue was discovered in the fp_newsletter (aka Newsletter subscriber management) extension before 1.1.1, 1.2.0, 2.x before 2.1.2, 2.2.1 tEPSS 0.7%CVE-2026-69854CRITICALSpring Cloud Azure Elevation of Privilege VulnerabilityEPSS 0.7%CVE-2026-50559HIGHAuthentication/Authorization Bypass via Advanced Path Normalization VulnerabilitiesEPSS 0.7%CVE-2026-47159MEDIUMVaultwarden: Authentication Flow Information Disclosure in SSO Discovery Allows Organization Enumeration and Pre-Validation Token ExposureEPSS 0.7%