Falhas do tipo CWE-287

2.450 resultados

Autenticação Insuficiente ou Ausente

Quando um usuário ou sistema afirma ser quem diz que é, a aplicação não valida (ou valida mal) essa identidade antes de conceder acesso. Isso permite que um atacante se passe por outra pessoa sem fornecer credenciais válidas, obtendo privilégios indevidos.

Exemplo

Um sistema que aceita login apenas verificando um campo de e-mail na sessão (sem senha), ou uma API que confia em um identificador de usuário enviado no header HTTP sem validar um token assinado. Um atacante simplesmente muda o valor e acessa dados de terceiros.

Como mitigar

Implemente autenticação robusta: exija senha forte + MFA quando possível, valide tokens com assinatura criptográfica, revoque sessões expiradas, e nunca confie em dados controlados pelo cliente. Teste autenticação em cada endpoint crítico.

CVE-2022-4041MEDIUMPrivilege Escalation Vulnerability in Hitachi Storage Plug-in for VMware vCenterEPSS 0.6%CVE-2020-22657CRITICALIn Ruckus R310 10.5.1.0.199, Ruckus R500 10.5.1.0.199, Ruckus R600 10.5.1.0.199, Ruckus T300 10.5.1.0.199, Ruckus T301n 10.5.1.0.199, RuckusEPSS 0.6%CVE-2026-88007CRITICALTraefik HTTP/3 Backend NTLM Connection ReuseEPSS 0.6%CVE-2026-31387MEDIUMApache OFBiz: Cookie Manipulation Allows Authenticated JWT Forgery and Account ImpersonationEPSS 0.6%CVE-2022-29237MEDIUMLimited Authentication Bypass for Media Files in OpencastEPSS 0.6%CVE-2024-24771HIGHOpen Forms potential multi-factor authentication bypassEPSS 0.6%CVE-2026-16857HIGHVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.6%CVE-2026-87016HIGHOpen WebUI: Sign-in as another user via wildcard characters in the OAuth subject claim on SQLiteEPSS 0.6%CVE-2026-53761HIGHFrappe CRM: Authentication Bypass via Logged Invitation Keys in crm/apiEPSS 0.6%CVE-2025-22228HIGHCVE-2025-22228: Spring Security BCryptPasswordEncoder does not enforce maximum password lengthEPSS 0.6%CVE-2024-0002CRITICALA condition exists in FlashArray Purity whereby an attacker can employ a privileged account allowing remote access to the array.EPSS 0.6%CVE-2026-41145HIGHMinIO has an Unauthenticated Object Write via Query-String Credential Signature Bypass in Unsigned-Trailer UploadsEPSS 0.6%CVE-2025-60772CRITICALImproper authentication in the web-based management interface of NETLINK HG322G V1.0.00-231017, allows a remote unauthenticated attacker to EPSS 0.6%CVE-2026-68569HIGHApache Tomcat: Principal lookup can fail open in some casesEPSS 0.6%CVE-2024-2450HIGHMattermost versions 8.1.x before 8.1.10, 9.2.x before 9.2.6, 9.3.x before 9.3.2, and 9.4.x before 9.4.3 fail to correctly verify account ownEPSS 0.6%CVE-2026-10697HIGHMFA Bypass in MOVEit TransferEPSS 0.6%CVE-2026-25804HIGHAntrea has invalid enforcement order for network policy rules caused by integer overflowEPSS 0.6%CVE-2024-37893MEDIUMMFA bypass in oauth flow in Firefly IIIEPSS 0.6%CVE-2019-1758MEDIUMCisco IOS Software Catalyst 6500 Series 802.1x Authentication Bypass VulnerabilityEPSS 0.6%CVE-2025-5149MEDIUMWCMS Login getallcon getMemberByUid improper authenticationEPSS 0.6%