Falhas do tipo CWE-287

2.451 resultados

Autenticação Insuficiente ou Ausente

Quando um usuário ou sistema afirma ser quem diz que é, a aplicação não valida (ou valida mal) essa identidade antes de conceder acesso. Isso permite que um atacante se passe por outra pessoa sem fornecer credenciais válidas, obtendo privilégios indevidos.

Exemplo

Um sistema que aceita login apenas verificando um campo de e-mail na sessão (sem senha), ou uma API que confia em um identificador de usuário enviado no header HTTP sem validar um token assinado. Um atacante simplesmente muda o valor e acessa dados de terceiros.

Como mitigar

Implemente autenticação robusta: exija senha forte + MFA quando possível, valide tokens com assinatura criptográfica, revoque sessões expiradas, e nunca confie em dados controlados pelo cliente. Teste autenticação em cada endpoint crítico.

CVE-2024-12287CRITICALBiagiotti Membership <= 1.0.2 - Authentication Bypass via biagiotti_membership_check_facebook_userEPSS 0.6%CVE-2026-16015MEDIUMpoco-ai poco-claw executor_manager API tasks.py create_task missing authenticationEPSS 0.6%CVE-2026-42560CRITICALauth: Patreon provider assigns the same local user ID to every authenticated Patreon account, enabling cross‑user impersonationEPSS 0.6%CVE-2026-75774MEDIUMkarakeep-app karakeep OAuth Sign-In auth.ts improper authenticationEPSS 0.6%CVE-2023-37226CRITICALLoftware Spectrum before 4.6 HF14 has Missing Authentication for a Critical Function.EPSS 0.6%CVE-2024-56329HIGHAccount Takeover Vulnerability in Social Account Linking in joelbutcher/socialstreamEPSS 0.6%CVE-2018-8862—In ATI Systems Emergency Mass Notification Systems (HPSS16, HPSS32, MHPSS, and ALERT4000) devices, an improper authentication vulnerability EPSS 0.6%CVE-2026-41070CRITICALopenvpn-auth-oauth2 returns FUNC_SUCCESS on client-deny, allowing unauthenticated VPN accessEPSS 0.6%CVE-2026-93960MEDIUMPixelfed OAuth Scope ApiV1Controller.php instancePeers missing authenticationEPSS 0.6%CVE-2026-27197CRITICALSentry: Improper Authentication on SAML SSO process allows user identity linkingEPSS 0.6%CVE-2024-45106HIGHApache Ozone: Improper authentication when generating S3 secretsEPSS 0.6%CVE-2025-27138HIGHDataEase has an improper authentication vulnerabilityEPSS 0.6%CVE-2026-52827HIGHKimai: Two-factor authentication bypass on the Kimai APIEPSS 0.6%CVE-2026-0589MEDIUMcode-projects Online Product Reservation System Administration Backend improper authenticationEPSS 0.6%CVE-2026-59955HIGHApollo ConfigService access key authentication bypass via raw config file appId parsingEPSS 0.6%CVE-2026-48087CRITICALOpenReception: WebAuthn passkey injection allows account takeoverEPSS 0.6%CVE-2026-82906MEDIUMsdcb chats Signed File Download Endpoint FileController.cs DownloadPublic missing authenticationEPSS 0.6%CVE-2023-48312CRITICALAuthentication bypass using an empty token in capsule-proxyEPSS 0.6%CVE-2026-33716CRITICALAVideo Allows Unauthenticated Live Stream Control via Token Verification URL Override in control.json.phpEPSS 0.6%CVE-2026-59954HIGHApollo ConfigService access key authentication bypass via appId parsing and non-canonical matchingEPSS 0.6%