Falhas do tipo CWE-287

2.449 resultados

Autenticação Insuficiente ou Ausente

Quando um usuário ou sistema afirma ser quem diz que é, a aplicação não valida (ou valida mal) essa identidade antes de conceder acesso. Isso permite que um atacante se passe por outra pessoa sem fornecer credenciais válidas, obtendo privilégios indevidos.

Exemplo

Um sistema que aceita login apenas verificando um campo de e-mail na sessão (sem senha), ou uma API que confia em um identificador de usuário enviado no header HTTP sem validar um token assinado. Um atacante simplesmente muda o valor e acessa dados de terceiros.

Como mitigar

Implemente autenticação robusta: exija senha forte + MFA quando possível, valide tokens com assinatura criptográfica, revoque sessões expiradas, e nunca confie em dados controlados pelo cliente. Teste autenticação em cada endpoint crítico.

CVE-2023-51405HIGHWordPress BookingPress plugin <= 1.0.74 - Booking Price Manipulation vulnerabilityEPSS 0.7%CVE-2023-51482CRITICALWordPress Eazy Plugin Manager plugin <= 4.1.2 - Auth. Arbitrary Options Update lead to RCE vulnerabilityEPSS 0.7%CVE-2026-0953CRITICALTutor LMS Pro <= 3.9.5 - Authentication Bypass via Social LoginEPSS 0.7%CVE-2026-74894CRITICALopenssl_encrypt before 1.4.0 Authentication Bypass via Bearer TokenEPSS 0.7%CVE-2026-90620MEDIUM0x4m4 HexStrike AI API Command Endpoint hexstrike_server.py missing authenticationEPSS 0.7%CVE-2026-5000MEDIUMPromtEngineer localGPT API Endpoint server.py LocalGPTHandler missing authenticationEPSS 0.7%CVE-2026-6577MEDIUMliangliangyy DjangoBlog logtracks Endpoint views.py missing authenticationEPSS 0.7%CVE-2026-90504MEDIUMvvbbnn00 WARP-Clash-API authorized missing authenticationEPSS 0.7%CVE-2026-5632MEDIUMassafelovic gpt-researcher HTTP REST API Endpoint missing authenticationEPSS 0.7%CVE-2026-4562MEDIUMMacCMS Timming API Endpoint Timming.php weak authenticationEPSS 0.7%CVE-2026-15491MEDIUMRafyMrX TOKO-ONLINE-ROTI missing authenticationEPSS 0.7%CVE-2026-5320MEDIUMvanna-ai vanna Chat API Endpoint v2 missing authenticationEPSS 0.7%CVE-2026-7679MEDIUMYunaiV yudao-cloud OAuth2TokenServiceImpl.java getAccessToken improper authenticationEPSS 0.7%CVE-2026-95271MEDIUMdgtlmoon changedetection.io Authentication Hook flask_app.py check_authentication improper authenticationEPSS 0.7%CVE-2026-7710MEDIUMYunaiV yudao-cloud Ruoyi-Vue-Pro JwtAuthenticationTokenFilter.java doFilterInternal improper authenticationEPSS 0.7%CVE-2026-6569MEDIUMkodcloud KodExplorer fileGet Endpoint share.class.php improper authenticationEPSS 0.7%CVE-2026-7022MEDIUMSmythOS sre HTTP Header AgentRuntime.class.ts AgentRuntime improper authenticationEPSS 0.7%CVE-2026-82919MEDIUMcu silicon edit Endpoint views.py create_app missing authenticationEPSS 0.7%CVE-2026-18810MEDIUMH3C NX15 networkSetup missing authenticationEPSS 0.7%CVE-2026-6582MEDIUMTransformerOptimus SuperAGI Vector Database Management Endpoint vector_dbs.py get_vector_db_details missing authenticationEPSS 0.7%