Falhas do tipo CWE-287

2.451 resultados

Autenticação Insuficiente ou Ausente

Quando um usuário ou sistema afirma ser quem diz que é, a aplicação não valida (ou valida mal) essa identidade antes de conceder acesso. Isso permite que um atacante se passe por outra pessoa sem fornecer credenciais válidas, obtendo privilégios indevidos.

Exemplo

Um sistema que aceita login apenas verificando um campo de e-mail na sessão (sem senha), ou uma API que confia em um identificador de usuário enviado no header HTTP sem validar um token assinado. Um atacante simplesmente muda o valor e acessa dados de terceiros.

Como mitigar

Implemente autenticação robusta: exija senha forte + MFA quando possível, valide tokens com assinatura criptográfica, revoque sessões expiradas, e nunca confie em dados controlados pelo cliente. Teste autenticação em cada endpoint crítico.

CVE-2026-89093MEDIUMBetter Messages <= 2.15.33 - Unauthenticated Information Exposure Spoofing via 'X-Real-IP' Header via /guests/registerEPSS 0.6%CVE-2026-44476MEDIUMDoorkeeper OpenID Connect: Dynamic Client Registration feature creates public clients with client_secretEPSS 0.6%CVE-2025-11287MEDIUMsamanhappy MCPHub sseService.ts handleSseConnectionfunction improper authenticationEPSS 0.6%CVE-2023-28962MEDIUMJunos OS: Unauthenticated access vulnerability in J-WebEPSS 0.6%CVE-2023-3127HIGHImproper Authentication in iSTAREPSS 0.6%CVE-2024-10327HIGHA vulnerability in Okta Verify for iOS versions 9.25.1 (beta) and 9.27.0 (including beta) allows push notification responses through the iOSEPSS 0.6%CVE-2025-52395CRITICALAn issue in Roadcute API v.1 allows a remote attacker to execute arbitrary code via the application exposing a password reset API endpoint tEPSS 0.6%CVE-2026-18922CRITICAL389-ds-base: 389-ds-base: sasl plain authentication allows privilege escalation to directory manager via stale identity in cyrus sasl auxiliary propertyEPSS 0.6%CVE-2021-25368LOWHijacking vulnerability in Samsung Cloud prior to version 4.7.0.3 allows attackers to intercept when the provider is executed.EPSS 0.6%CVE-2023-51471HIGHWordPress Checkout Mestres WP plugin <= 7.1.9.7 - Unauthenticated Arbitrary Options Update vulnerabilityEPSS 0.6%CVE-2024-12919CRITICALPaid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction <= 2.13.7 - Authentication Bypass via pms_payment_idEPSS 0.6%CVE-2023-48703HIGHSAML authentication bypass vulnerability in RobotsAndPencils/go-samlEPSS 0.6%CVE-2026-33432HIGHRoxy-WI has Pre-Authentication LDAP Injection that Leads to Authentication BypassEPSS 0.6%CVE-2026-12595HIGHLoginPress Pro <= 6.2.3 - Unauthenticated Authentication Bypass via Unverified OAuth Email via Discord OAuth CallbackEPSS 0.6%CVE-2026-12598HIGHLoginPress Pro <= 6.2.3 - Unauthenticated Authentication Bypass via Unverified OAuth Email in Spotify OAuth CallbackEPSS 0.6%CVE-2025-6533MEDIUMxxyopen/201206030 novel-plus CATCHA LoginController.java ajaxLogin authentication replayEPSS 0.6%CVE-2025-49812HIGHApache HTTP Server: mod_ssl TLS upgrade attackEPSS 0.6%CVE-2026-20317CRITICALCisco Secure Workload Software Security Hardening Release August 2026 - Improper Authentication VulnerabilitiesEPSS 0.6%CVE-2026-72533HIGHPortainer Portainer CE - Authentication BypassEPSS 0.6%CVE-2026-33409HIGHParse Server: Auth provider validation bypass on login via partial authDataEPSS 0.6%