Falhas do tipo CWE-287

2.450 resultados

Autenticação Insuficiente ou Ausente

Quando um usuário ou sistema afirma ser quem diz que é, a aplicação não valida (ou valida mal) essa identidade antes de conceder acesso. Isso permite que um atacante se passe por outra pessoa sem fornecer credenciais válidas, obtendo privilégios indevidos.

Exemplo

Um sistema que aceita login apenas verificando um campo de e-mail na sessão (sem senha), ou uma API que confia em um identificador de usuário enviado no header HTTP sem validar um token assinado. Um atacante simplesmente muda o valor e acessa dados de terceiros.

Como mitigar

Implemente autenticação robusta: exija senha forte + MFA quando possível, valide tokens com assinatura criptográfica, revoque sessões expiradas, e nunca confie em dados controlados pelo cliente. Teste autenticação em cada endpoint crítico.

CVE-2024-11209MEDIUMApereo CAS 2FA login improper authenticationEPSS 0.6%CVE-2023-25913HIGHAuthentication Bypass in Danfoss AK-SM800AEPSS 0.6%CVE-2022-4441HIGHPrivilege Escalation Vulnerability in Hitachi Storage Plug-in for VMware vCenterEPSS 0.6%CVE-2026-92578CRITICALWWBN AVideo through 29.0 Authentication Bypass via Stored Password HashEPSS 0.6%CVE-2026-16867HIGHIBM i is Affected By Multiple Vulnerabilities in NetServerEPSS 0.6%CVE-2023-30967CRITICALGotham Orbital Simulator path traversalEPSS 0.6%CVE-2022-39252HIGHWhen matrix-rust-sdk recieves forwarded room keys, the reciever doesn't check if it requested the key from the forwarderEPSS 0.6%CVE-2023-44397HIGHCloudExplorer Lite permission bypass vulnerabilityEPSS 0.6%CVE-2026-29093HIGHWWBN AVideo: Unauthenticated PHP session store exposed to host network via published memcached portEPSS 0.6%CVE-2024-7763CRITICALWhatsUp Gold getReport Missing Authentication Authentication Bypass VulnerabilityEPSS 0.6%CVE-2026-5795HIGHIn Eclipse Jetty, the class JASPIAuthenticator initiates the authentication checks, which set two ThreadLocal variable. Upon returning froEPSS 0.6%CVE-2026-82466CRITICALRodauth before 2.46.0 Authentication Bypass via webauthn_loginEPSS 0.6%CVE-2022-29893HIGHImproper authentication in firmware for Intel(R) AMT before versions 11.8.93, 11.22.93, 11.12.93, 12.0.92, 14.1.67, 15.0.42, 16.1.25 may allEPSS 0.6%CVE-2023-4816MEDIUMA vulnerability exists in the Equipment Tag Out authentication, when configured with Single Sign-On (SSO) with password validation in T214. EPSS 0.6%CVE-2026-54089CRITICALFile Browser: Authentication Bypass via Proxy Auth Header ForgeryEPSS 0.6%CVE-2025-54888HIGH@fedify/fedify: Improper Authentication and Incorrect AuthorizationEPSS 0.6%CVE-2026-47865CRITICALVMware Avi Load Balancer Authentication Bypass VulnerabilityEPSS 0.6%CVE-2026-51584CRITICALAn issue in usememos v0.27.1 allows a remote attacker to achieve account takeover via the ssoCredentials branch of the SignIn handler in serEPSS 0.6%CVE-2026-55076HIGHCoder's OIDC email_verified type coercion bypass enables account takeover via unverified email linkingEPSS 0.6%CVE-2026-66908HIGHApache Camel: Camel-platform-http-main: when JWT authentication was configured with a keystore but no issuer or audience, the iss and aud claims were never validated, so any unexpired token signed by a trusted key was acceptedEPSS 0.6%