Falhas do tipo CWE-287

2.450 resultados

Autenticação Insuficiente ou Ausente

Quando um usuário ou sistema afirma ser quem diz que é, a aplicação não valida (ou valida mal) essa identidade antes de conceder acesso. Isso permite que um atacante se passe por outra pessoa sem fornecer credenciais válidas, obtendo privilégios indevidos.

Exemplo

Um sistema que aceita login apenas verificando um campo de e-mail na sessão (sem senha), ou uma API que confia em um identificador de usuário enviado no header HTTP sem validar um token assinado. Um atacante simplesmente muda o valor e acessa dados de terceiros.

Como mitigar

Implemente autenticação robusta: exija senha forte + MFA quando possível, valide tokens com assinatura criptográfica, revoque sessões expiradas, e nunca confie em dados controlados pelo cliente. Teste autenticação em cada endpoint crítico.

CVE-2025-55171HIGHWeGIA Anonymous Attacker can Delete Arbitrary Image file at endpoint `/html/personalizacao_remover.php`EPSS 0.6%CVE-2026-41428CRITICALBudibase: Authentication Bypass via Unanchored Regex in Public Endpoint Matcher — Unauthenticated Access to Protected EndpointsEPSS 0.6%CVE-2026-19749MEDIUMTenda CH7 RTSP/ONVIF missing authenticationEPSS 0.6%CVE-2026-97878MEDIUMzhistaredu StarTraining Druid Console index.html anonymous missing authenticationEPSS 0.6%CVE-2026-77001CRITICALSocial Login & Sharing buttons with Analytics By SoClever <= 1.2.0 - Unauthenticated Authentication BypassEPSS 0.6%CVE-2026-53483CRITICALDell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1EPSS 0.6%CVE-2026-17101HIGHIBM i is Affected By Multiple Vulnerabilities in Navigator for iEPSS 0.6%CVE-2026-86709CRITICALThe Pressengine <= 1.0 - Unauthenticated Authentication BypassEPSS 0.6%CVE-2026-75800CRITICALFrontegg SAML SSO <= 1.0.1 - Unauthenticated Account Takeover via Unverified SAMLResponseEPSS 0.6%CVE-2024-22442CRITICALThe vulnerability could be remotely exploited to bypass authentication.EPSS 0.6%CVE-2023-1065MEDIUMThis vulnerability in the Snyk Kubernetes Monitor can result in irrelevant data being posted to a Snyk Organization, which could in turn obfEPSS 0.6%CVE-2024-6576HIGHMOVEit Transfer Privilege Escalation VulnerabilityEPSS 0.6%CVE-2024-2873CRITICALUser authentication bypass in wolfSSH serverEPSS 0.6%CVE-2026-46579HIGHOpenshift/router: openshift/router: mtls client certificate spoofing via unstripped x-ssl-client headers on http frontendEPSS 0.6%CVE-2025-27672CRITICALVasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows OAUTH Security Bypass OVE-20230524-EPSS 0.6%CVE-2024-11322HIGHCyberPower PowerPanel Business Unauthenticated Restart DoSEPSS 0.6%CVE-2022-46400MEDIUMThe Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) allows attackers to bypass passkey enEPSS 0.6%CVE-2024-51996HIGHSymphony has an Authentication Bypass via RememberMeEPSS 0.6%CVE-2023-1477HIGHImproper Authentication vulnerability in HYPR Keycloak Authenticator Extension allows Authentication Abuse.This issue affects HYPR Keycloak EPSS 0.6%CVE-2026-55652CRITICALWekan: Header-login IP allowlist bypass via X-Forwarded-For spoofing in Wekan allows unauthenticated full account takeover (incl. admin)EPSS 0.6%