Falhas do tipo CWE-287

2.446 resultados

Autenticação Insuficiente ou Ausente

Quando um usuário ou sistema afirma ser quem diz que é, a aplicação não valida (ou valida mal) essa identidade antes de conceder acesso. Isso permite que um atacante se passe por outra pessoa sem fornecer credenciais válidas, obtendo privilégios indevidos.

Exemplo

Um sistema que aceita login apenas verificando um campo de e-mail na sessão (sem senha), ou uma API que confia em um identificador de usuário enviado no header HTTP sem validar um token assinado. Um atacante simplesmente muda o valor e acessa dados de terceiros.

Como mitigar

Implemente autenticação robusta: exija senha forte + MFA quando possível, valide tokens com assinatura criptográfica, revoque sessões expiradas, e nunca confie em dados controlados pelo cliente. Teste autenticação em cada endpoint crítico.

CVE-2026-47159MEDIUMVaultwarden: Authentication Flow Information Disclosure in SSO Discovery Allows Organization Enumeration and Pre-Validation Token ExposureEPSS 0.7%CVE-2026-55678MEDIUMArc: Unauthenticated cluster node admission when `cluster.shared_secret` is unsetEPSS 0.7%CVE-2023-32347HIGH Teltonika’s Remote Management System versions prior to 4.10.0 use device serial numbers and MAC addresses to identify devices from the userEPSS 0.7%CVE-2025-6528MEDIUM70mai M300 RTSP Live Video Stream Endpoint 12 improper authenticationEPSS 0.7%CVE-2026-55445CRITICALQinglong: Incomplete fix for CVE-2026-3965: Improper AuthenticationEPSS 0.7%CVE-2026-5270CRITICALAuthentication Bypass in Navigator and Blue Planet ProductsEPSS 0.7%CVE-2022-39254HIGHWhen matrix-nio receives forwarded room keys, the receiver doesn't check if it requested the key from the forwarderEPSS 0.7%CVE-2026-61740CRITICALLightRAG: Authentication bypass: hardcoded DEFAULT_TOKEN_SECRET and public /auth-status defeat LIGHTRAG_API_KEY protectionEPSS 0.7%CVE-2020-7293CRITICALWeb Gateway (MWG) - Privilege Escalation vulnerabilityEPSS 0.7%CVE-2022-23554MEDIUMAuthentication bypass in AlpineEPSS 0.7%CVE-2023-35940HIGHGLPI vulnerable to unauthenticated access to Dashboard dataEPSS 0.7%CVE-2026-65375HIGHThe issue was addressed with improved authentication. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.6. An EPSS 0.7%CVE-2026-6635MEDIUMrowboatlabs rowboat tools_webhook app.py tool_call improper authenticationEPSS 0.7%CVE-2026-85702MEDIUMramon-victor freegpt-webui Backend Conversation API backend.py _conversation missing authenticationEPSS 0.7%CVE-2026-41076HIGHRT: LDAP authentication bypass via empty passwordEPSS 0.7%CVE-2026-28215CRITICALhoppscotch Vulnerable to Unauthenticated Onboarding Config TakeoverEPSS 0.7%CVE-2023-51472CRITICALWordPress Checkout Mestres WP plugin <= 7.1.9.7 - Unauthenticated Account Takeover vulnerabilityEPSS 0.7%CVE-2024-41196CRITICALAn issue in Ocuco Innovation - REPORTSERVER.EXE v2.10.24.13 allows attackers to bypass authentication and escalate privileges to AdministratEPSS 0.7%CVE-2022-42951HIGHAn issue was discovered in Couchbase Server 6.5.x and 6.6.x before 6.6.6, 7.x before 7.0.5, and 7.1.x before 7.1.2. During the start-up of aEPSS 0.7%CVE-2025-37184CRITICALUnauthenticated Bypass Allows Multi-Factor Authentication CircumventionEPSS 0.7%