Falhas do tipo CWE-287

2.451 resultados

Autenticação Insuficiente ou Ausente

Quando um usuário ou sistema afirma ser quem diz que é, a aplicação não valida (ou valida mal) essa identidade antes de conceder acesso. Isso permite que um atacante se passe por outra pessoa sem fornecer credenciais válidas, obtendo privilégios indevidos.

Exemplo

Um sistema que aceita login apenas verificando um campo de e-mail na sessão (sem senha), ou uma API que confia em um identificador de usuário enviado no header HTTP sem validar um token assinado. Um atacante simplesmente muda o valor e acessa dados de terceiros.

Como mitigar

Implemente autenticação robusta: exija senha forte + MFA quando possível, valide tokens com assinatura criptográfica, revoque sessões expiradas, e nunca confie em dados controlados pelo cliente. Teste autenticação em cada endpoint crítico.

CVE-2026-15341CRITICALUser Session Synchronizer <= 1.4.0 - Unauthenticated Authentication Bypass to Account Takeover via 'ussync-key', 'ussync-token', and 'ussync-ref' ParametersEPSS 0.6%CVE-2026-7113MEDIUMNousResearch hermes-agent Webhooks Endpoint webhook.py missing authenticationEPSS 0.6%CVE-2024-45369CRITICALmySCADA myPRO Improper AuthenticationEPSS 0.6%CVE-2022-46411HIGHAn issue was discovered in Veritas NetBackup Flex Scale through 3.0 and Access Appliance through 8.0.100. A default password is persisted afEPSS 0.6%CVE-2026-49448CRITICALauthentik: SourceStage bypass via empty POSTEPSS 0.6%CVE-2026-2174MEDIUMcode-projects Contact Management System CRUD Endpoint improper authenticationEPSS 0.6%CVE-2026-54600HIGHWallos: Unauthenticated database replacement via import endpoint on fresh installEPSS 0.6%CVE-2022-40616MEDIUMIBM Maximo Asset Management 7.6.1.1, 7.6.1.2, and 7.6.1.3 could allow a user to bypass authentication and obtain sensitive information or peEPSS 0.6%CVE-2025-11852MEDIUMApeman ID71 ONVIF Service device_service missing authenticationEPSS 0.6%CVE-2026-77194MEDIUMSimple Membership <= 4.8.1 - Unauthenticated Authentication Bypass to Administrator Account Takeover via Multisite Identity BindingEPSS 0.6%CVE-2023-42818MEDIUMSSH public key login without private key challenge if mfa is enabled in jumpserverEPSS 0.6%CVE-2025-15457MEDIUMbg5sbk MiniCMS Trash File Restore post.php improper authenticationEPSS 0.6%CVE-2025-15458MEDIUMbg5sbk MiniCMS Article post-edit.php improper authenticationEPSS 0.6%CVE-2026-65633HIGHPurpose-limited JWT accepted as full bearer authentication in AshAuthenticationEPSS 0.6%CVE-2024-47218CRITICALAn issue was discovered in vesoft NebulaGraph through 3.8.0. It allows bypassing authentication.EPSS 0.6%CVE-2024-37019CRITICALNorthern.tech Mender Enterprise before 3.6.4 and 3.7.x before 3.7.4 has Weak Authentication.EPSS 0.6%CVE-2026-15348MEDIUMPremium Packages <= 7.0.4 - Authentication Bypass to Non-Admin via 'wpdmppdl' ParameterEPSS 0.6%CVE-2022-30124MEDIUMAn improper authentication vulnerability exists in Rocket.Chat Mobile App <4.14.1.22788 that allowed an attacker with physical access to a mEPSS 0.6%CVE-2026-78885MEDIUMliketrek TREK OIDC Service oidcService.ts findOrCreateUser improper authenticationEPSS 0.6%CVE-2026-7112MEDIUMNousResearch hermes-agent API_SERVER_KEY api_server.py _check_auth improper authenticationEPSS 0.6%