Falhas do tipo CWE-287

2.449 resultados

Autenticação Insuficiente ou Ausente

Quando um usuário ou sistema afirma ser quem diz que é, a aplicação não valida (ou valida mal) essa identidade antes de conceder acesso. Isso permite que um atacante se passe por outra pessoa sem fornecer credenciais válidas, obtendo privilégios indevidos.

Exemplo

Um sistema que aceita login apenas verificando um campo de e-mail na sessão (sem senha), ou uma API que confia em um identificador de usuário enviado no header HTTP sem validar um token assinado. Um atacante simplesmente muda o valor e acessa dados de terceiros.

Como mitigar

Implemente autenticação robusta: exija senha forte + MFA quando possível, valide tokens com assinatura criptográfica, revoque sessões expiradas, e nunca confie em dados controlados pelo cliente. Teste autenticação em cada endpoint crítico.

CVE-2026-30967HIGHParse Server OAuth2 authentication adapter account takeover via identity spoofingEPSS 0.6%CVE-2026-19125HIGHEthPress <= 2.3.5 - Unauthenticated Authentication BypassEPSS 0.6%CVE-2026-30949HIGHParse Server is missing audience validation in Keycloak authentication adapterEPSS 0.6%CVE-2025-1475CRITICALWPCOM Member <= 1.7.5 - Authentication Bypass via 'user_phone'EPSS 0.6%CVE-2026-3224CRITICALAuthentication bypass in the Microsoft Entra ID (Azure AD) authentication mode in Devolutions Server 2025.3.15.0 and earlier allows an unautEPSS 0.6%CVE-2026-16198MEDIUMSipeed PicoClaw First Run Setup access_control.go authentication bypassEPSS 0.6%CVE-2022-46875MEDIUMThe executable file warning was not presented when downloading .atloc and .ftploc files, which can run commands on a user's computer. <br>*NEPSS 0.6%CVE-2026-48812HIGHFreeScout Allows Unauthenticated Access to Legacy Attachment FilesEPSS 0.6%CVE-2025-52856CRITICALVioStorEPSS 0.6%CVE-2022-43690MEDIUMConcrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 did not use strict comparison for the legacy_salt so that limitedEPSS 0.6%CVE-2024-47806HIGHJenkins OpenId Connect Authentication Plugin 4.354.v321ce67a_1de8 and earlier does not check the `aud` (Audience) claim of an ID Token, alloEPSS 0.6%CVE-2024-47807HIGHJenkins OpenId Connect Authentication Plugin 4.354.v321ce67a_1de8 and earlier does not check the `iss` (Issuer) claim of an ID Token, allowiEPSS 0.6%CVE-2018-0163—A vulnerability in the 802.1x multiple-authentication (multi-auth) feature of Cisco IOS Software could allow an unauthenticated, adjacent atEPSS 0.6%CVE-2024-9946HIGHSocial Share, Social Login and Social Comments Plugin – Super Socializer <= 7.13.68 - Authentication Bypass via Disqus OAuth providerEPSS 0.6%CVE-2026-85701MEDIUMramon-victor freegpt-webui Authentication Check __init__.py ChatCompletion.create missing authenticationEPSS 0.6%CVE-2026-44472HIGHSaleor: Account pre-hijacking vulnerability due to unverified anonymous order mergeEPSS 0.6%CVE-2026-29145CRITICALApache Tomcat, Apache Tomcat Native: OCSP checks sometimes soft-fail even when soft-fail is disabledEPSS 0.6%CVE-2026-29792CRITICALFeathersjs has an OAuth Callback Account TakeoverEPSS 0.6%CVE-2020-8350HIGHAn authentication bypass vulnerability was reported in Lenovo ThinkPad Stack Wireless Router firmware version 1.1.3.4 that could allow escalEPSS 0.6%CVE-2026-10243MEDIUMcode-projects Smart Parking System Admin Endpoint missing authenticationEPSS 0.6%