Falhas do tipo CWE-287

2.451 resultados

Autenticação Insuficiente ou Ausente

Quando um usuário ou sistema afirma ser quem diz que é, a aplicação não valida (ou valida mal) essa identidade antes de conceder acesso. Isso permite que um atacante se passe por outra pessoa sem fornecer credenciais válidas, obtendo privilégios indevidos.

Exemplo

Um sistema que aceita login apenas verificando um campo de e-mail na sessão (sem senha), ou uma API que confia em um identificador de usuário enviado no header HTTP sem validar um token assinado. Um atacante simplesmente muda o valor e acessa dados de terceiros.

Como mitigar

Implemente autenticação robusta: exija senha forte + MFA quando possível, valide tokens com assinatura criptográfica, revoque sessões expiradas, e nunca confie em dados controlados pelo cliente. Teste autenticação em cada endpoint crítico.

CVE-2026-48087CRITICALOpenReception: WebAuthn passkey injection allows account takeoverEPSS 0.6%CVE-2026-59954HIGHApollo ConfigService access key authentication bypass via appId parsing and non-canonical matchingEPSS 0.6%CVE-2022-0985—Insufficient capability checks could allow users with the moodle/site:uploadusers capability to delete users, without having the necessary mEPSS 0.6%CVE-2025-68717CRITICALKAYSUS KS-WR3600 routers with firmware 1.0.5.9.1 allow authentication bypass during session validation. If any user is logged in, endpoints EPSS 0.6%CVE-2024-7050HIGHImproper Authentication vulnerability in OpenText OpenText Directory Services may allow Multi-factor Authentication Bypass in particular sceEPSS 0.6%CVE-2026-4831MEDIUMkalcaddle kodbox Password-protected Share auth.class.php can improper authenticationEPSS 0.6%CVE-2026-4664MEDIUMCustomer Reviews for WooCommerce <= 5.103.0 - Unauthenticated Authentication Bypass to Arbitrary Review Submission via 'key' ParameterEPSS 0.6%CVE-2022-27839LOWImproper authentication vulnerability in SecretMode in Samsung Internet prior to version 16.2.1 allows attackers to access bookmark tab withEPSS 0.6%CVE-2025-49851HIGHImproper Authentication in ControlID iDSecure On-premisesEPSS 0.6%CVE-2026-70482HIGHOpen WebUI: Account takeover via OAuth token exchange accepting tokens issued to any clientEPSS 0.6%CVE-2024-27253CRITICALIBM Engineering Requirements Management DOORS Next is impacted by vulnerability in Reviews delete requestEPSS 0.6%CVE-2024-47070CRITICALauthentik vulnerable to password authentication bypass via X-Forwarded-For HTTP headerEPSS 0.6%CVE-2026-46389CRITICALUDS Identity Config has a client authentication bypass in `ClientIdAndKubernetesSecretAuthenticator`EPSS 0.6%CVE-2026-12597HIGHLoginPress Pro <= 6.2.3 - Unauthenticated Authentication Bypass via Unverified OAuth Email via GitHub OAuth CallbackEPSS 0.6%CVE-2024-41198CRITICALAn issue in Ocuco Innovation - REPORTS.EXE v2.10.24.13 allows attackers to bypass authentication and escalate privileges to Administrator viEPSS 0.6%CVE-2024-41197CRITICALAn issue in Ocuco Innovation - INVCLIENT.EXE v2.10.24.5 allows attackers to bypass authentication and escalate privileges to Administrator vEPSS 0.6%CVE-2024-41195CRITICALAn issue in Ocuco Innovation - INNOVASERVICEINTF.EXE v2.10.24.17 allows attackers to bypass authentication and escalate privileges to AdminiEPSS 0.6%CVE-2025-7114MEDIUMSimStudioAI sim Session route.ts POST missing authenticationEPSS 0.6%CVE-2023-6155MEDIUMQuiz Maker < 6.4.9.5 - Unauthenticated Email Address DisclosureEPSS 0.6%CVE-2022-38982CRITICALThe fingerprint module has service logic errors.Successful exploitation of this vulnerability will cause the phone lock to be cracked.EPSS 0.6%