Falhas do tipo CWE-287

2.449 resultados

Autenticação Insuficiente ou Ausente

Quando um usuário ou sistema afirma ser quem diz que é, a aplicação não valida (ou valida mal) essa identidade antes de conceder acesso. Isso permite que um atacante se passe por outra pessoa sem fornecer credenciais válidas, obtendo privilégios indevidos.

Exemplo

Um sistema que aceita login apenas verificando um campo de e-mail na sessão (sem senha), ou uma API que confia em um identificador de usuário enviado no header HTTP sem validar um token assinado. Um atacante simplesmente muda o valor e acessa dados de terceiros.

Como mitigar

Implemente autenticação robusta: exija senha forte + MFA quando possível, valide tokens com assinatura criptográfica, revoque sessões expiradas, e nunca confie em dados controlados pelo cliente. Teste autenticação em cada endpoint crítico.

CVE-2026-52830CRITICALfast-mcp-telegram: Bearer token path traversal bypasses reserved Telegram session protectionEPSS 0.6%CVE-2026-40964HIGHAuthentication Bypass in cf-auth-proxy in Cloud Foundry Foundation all installations allows an unauthenticated remote attacker to gain read EPSS 0.6%CVE-2026-35903CRITICALMERCURY MIPC252W IP camera 1.0.5 Build 230306 Rel.79931n contains an improper authentication vulnerability in the RTSP service. After succesEPSS 0.6%CVE-2026-97879MEDIUMzhistaredu StarTraining api-docs Endpoint SecurityConfig.java missing authenticationEPSS 0.6%CVE-2023-43805HIGHNexkey allows users to bypass authentication of Bull dashboardEPSS 0.6%CVE-2026-75878CRITICALIBM Sterling File Gateway is Vulnerable to Authentication BypassEPSS 0.6%CVE-2025-47889CRITICALIn Jenkins WSO2 Oauth Plugin 1.0 and earlier, authentication claims are accepted without validation by the "WSO2 Oauth" security realm, alloEPSS 0.6%CVE-2022-1349—WPQA < 5.2 - Subscriber+ Arbitrary Profile Picture Deletion via IDOREPSS 0.6%CVE-2026-75325CRITICALDWSurvey v6.14.0 is is vulnerable to authentication bypass via the '/api/dwsurvey/none/' and '/api/dwsurvey/up/**' parameters.EPSS 0.6%CVE-2024-53990CRITICALAsyncHttpClient (AHC) library's `CookieStore` replaces explicitly defined `Cookie`sEPSS 0.6%CVE-2022-31164HIGHTovy before v0.7.51 vulnerable to users logging in as and impersonating other usersEPSS 0.6%CVE-2026-37271CRITICALFire-Boltt Smartwatch FB BGS001 Firmware: MOY-JS14-2.0.4 is vulnerable to Improper Authentication, The device accepts GATT Write Request comEPSS 0.6%CVE-2026-6274CRITICALAuthentication Bypass in DTS Electronics' Redline WR3200EPSS 0.6%CVE-2026-57148CRITICALpraisonai-platform 0.1.4 still boots on the hardcoded JWT secret dev-secret-change-me (default-open production guard)EPSS 0.6%CVE-2026-90961CRITICALMISP LdapAuth and LinOTPAuth Authentication Bypass via Empty or Non-String CredentialsEPSS 0.6%CVE-2026-33175HIGHOAuthenticator: Authentication Bypass in Auth0OAuthenticator via Unverified Email ClaimsEPSS 0.6%CVE-2026-66014HIGHPotential authentication bypass leading to privilege escalation in ArtifactoryEPSS 0.6%CVE-2024-3701CRITICALImproper Authentication in com.transsion.kolun.aiserviceEPSS 0.6%CVE-2023-46717MEDIUMAn improper authentication vulnerability [CWE-287] in FortiOS versions 7.4.1 and below, versions 7.2.6 and below, and versions 7.0.12 and beEPSS 0.6%CVE-2026-80218HIGHSign-in token minted for one resource accepted by another in AshAuthenticationEPSS 0.6%