Falhas do tipo CWE-287

2.449 resultados

Autenticação Insuficiente ou Ausente

Quando um usuário ou sistema afirma ser quem diz que é, a aplicação não valida (ou valida mal) essa identidade antes de conceder acesso. Isso permite que um atacante se passe por outra pessoa sem fornecer credenciais válidas, obtendo privilégios indevidos.

Exemplo

Um sistema que aceita login apenas verificando um campo de e-mail na sessão (sem senha), ou uma API que confia em um identificador de usuário enviado no header HTTP sem validar um token assinado. Um atacante simplesmente muda o valor e acessa dados de terceiros.

Como mitigar

Implemente autenticação robusta: exija senha forte + MFA quando possível, valide tokens com assinatura criptográfica, revoque sessões expiradas, e nunca confie em dados controlados pelo cliente. Teste autenticação em cada endpoint crítico.

CVE-2026-90620MEDIUM0x4m4 HexStrike AI API Command Endpoint hexstrike_server.py missing authenticationEPSS 0.7%CVE-2026-8216MEDIUMIndustrial Application Software IAS Canias ERP Java RMI Session Management iasServerRemoteInterface.doAction improper authenticationEPSS 0.7%CVE-2024-50645CRITICALMallChat v1.0-SNAPSHOT has an authentication bypass vulnerability. An attacker can exploit this vulnerability to access API without any tokeEPSS 0.7%CVE-2023-46249CRITICALauthentik potential installation takeover when default admin user is deletedEPSS 0.7%CVE-2026-86214MEDIUMMstfakts College-Management-System login.php improper authenticationEPSS 0.7%CVE-2026-6129MEDIUMzhayujie chatgpt-on-wechat CowAgent Agent Mode Service missing authenticationEPSS 0.7%CVE-2026-93559MEDIUMForget-C Jellyfish AI Short Drama Studio FastAPI dependencies.py missing authenticationEPSS 0.7%CVE-2026-5320MEDIUMvanna-ai vanna Chat API Endpoint v2 missing authenticationEPSS 0.7%CVE-2026-7022MEDIUMSmythOS sre HTTP Header AgentRuntime.class.ts AgentRuntime improper authenticationEPSS 0.7%CVE-2025-46348CRITICALYesWiki Vulnerable to Unauthenticated Site Backup Creation and DownloadEPSS 0.7%CVE-2023-30845HIGHESPv2 vulnerable to JWT authentication bypass via `X-HTTP-Method-Override` headerEPSS 0.7%CVE-2026-88895HIGHCyberPanel before 3.0.5 Authentication Bypass via APIEPSS 0.7%CVE-2022-31122CRITICALWire-server vulnerable to Token Recipient Confusion resulting in account impersonation, deletion or malicious account creationEPSS 0.7%CVE-2021-26074MEDIUMBroken Authentication in Atlassian Connect Spring Boot (ACSB) from version 1.1.0 before version 2.1.3: Atlassian Connect Spring Boot is a JaEPSS 0.7%CVE-2020-1778MEDIUMBypassing user account validationEPSS 0.7%CVE-2024-28007CRITICALImproper authentication vulnerability in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WEPSS 0.7%CVE-2024-28009CRITICALImproper authentication vulnerability in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WEPSS 0.7%CVE-2026-54176MEDIUMbackpack/crud: MyAccountController allows changing the login email without a current-password checkEPSS 0.7%CVE-2023-31123CRITICALeffectindex/tripreporter vulnerable to improper password verification on POST `/api/v1/account/login`EPSS 0.6%CVE-2026-41276HIGHFlowise: AccountService resetPassword Authentication Bypass VulnerabilityEPSS 0.6%