Falhas do tipo CWE-287

2.451 resultados

Autenticação Insuficiente ou Ausente

Quando um usuário ou sistema afirma ser quem diz que é, a aplicação não valida (ou valida mal) essa identidade antes de conceder acesso. Isso permite que um atacante se passe por outra pessoa sem fornecer credenciais válidas, obtendo privilégios indevidos.

Exemplo

Um sistema que aceita login apenas verificando um campo de e-mail na sessão (sem senha), ou uma API que confia em um identificador de usuário enviado no header HTTP sem validar um token assinado. Um atacante simplesmente muda o valor e acessa dados de terceiros.

Como mitigar

Implemente autenticação robusta: exija senha forte + MFA quando possível, valide tokens com assinatura criptográfica, revoque sessões expiradas, e nunca confie em dados controlados pelo cliente. Teste autenticação em cada endpoint crítico.

CVE-2025-5149MEDIUMWCMS Login getallcon getMemberByUid improper authenticationEPSS 0.6%CVE-2025-30215CRITICALNATS-Server Fails to Authorize Certain Jetstream Admin APIsEPSS 0.6%CVE-2024-45404HIGHOpenCTI's lack of Rate Limit lead to OTP brute forcingEPSS 0.6%CVE-2025-0604MEDIUMKeycloak-ldap-federation: authentication bypass due to missing ldap bind after password reset in keycloakEPSS 0.6%CVE-2020-8236—A wrong configuration in Nextcloud Server 19.0.1 incorrectly made the user feel the passwordless WebAuthn is also a two factor verification EPSS 0.6%CVE-2024-25652HIGHIn Delinea PAM Secret Server 11.4, it is possible for a user assigned "Administer Reports" permission and/or with access to Report functionaEPSS 0.6%CVE-2021-25505LOWImproper authentication in Samsung Pass prior to 3.0.02.4 allows to use app without authentication when lockscreen is unlocked.EPSS 0.6%CVE-2026-73501CRITICALkin-openapi: ValidationHandler.Load() Fail-Open Authentication Bypass via NoopAuthenticationFunc DefaultEPSS 0.6%CVE-2025-15097MEDIUMAlteryx Server status improper authenticationEPSS 0.6%CVE-2026-48039CRITICALMeta Ads MCP: Unauthenticated HTTP MCP Tool Execution Leaks Operator Meta Access TokenEPSS 0.6%CVE-2024-23813HIGHA vulnerability has been identified in Polarion ALM (All versions < V2404.0). The REST API endpoints of doorsconnector of the affected produEPSS 0.6%CVE-2026-63472CRITICALVendure: External-authentication account takeover: external login linked to a pre-existing account by email without verificationEPSS 0.6%CVE-2022-24740MEDIUMImproper Authentication in VoltoEPSS 0.6%CVE-2024-44127MEDIUMThis issue was addressed through improved state management. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18. Private BEPSS 0.6%CVE-2023-39345HIGHUnauthorized Access to Private Fields in User Registration API in strapiEPSS 0.6%CVE-2025-27414MEDIUMMinIO SFTP authentication bypass due to improperly trusted SSH keyEPSS 0.6%CVE-2026-13543MEDIUMDocumenso Google OAuth Login handle-oauth-callback-url.ts improper authenticationEPSS 0.6%CVE-2026-19974MEDIUMtreefrogframework treefrog-framework Session Cookie tsessioncookiestore.cpp strncmp improper authenticationEPSS 0.6%CVE-2026-24241MEDIUMNVIDIA Delegated Licensing Service for all appliance platforms contains a vulnerability where an attacker could exploit an improper authentiEPSS 0.6%CVE-2024-48859MEDIUMQTS, QuTS heroEPSS 0.6%