Falhas do tipo CWE-287

2.452 resultados

Autenticação Insuficiente ou Ausente

Quando um usuário ou sistema afirma ser quem diz que é, a aplicação não valida (ou valida mal) essa identidade antes de conceder acesso. Isso permite que um atacante se passe por outra pessoa sem fornecer credenciais válidas, obtendo privilégios indevidos.

Exemplo

Um sistema que aceita login apenas verificando um campo de e-mail na sessão (sem senha), ou uma API que confia em um identificador de usuário enviado no header HTTP sem validar um token assinado. Um atacante simplesmente muda o valor e acessa dados de terceiros.

Como mitigar

Implemente autenticação robusta: exija senha forte + MFA quando possível, valide tokens com assinatura criptográfica, revoque sessões expiradas, e nunca confie em dados controlados pelo cliente. Teste autenticação em cada endpoint crítico.

CVE-2023-48865MEDIUMAn issue discovered in Reportico Till 8.1.0 allows attackers to obtain sensitive information via execute_mode parameter of the URL.EPSS 0.6%CVE-2026-24898CRITICALOpenEMR has an Unauthenticated MedEx Token DisclosureEPSS 0.6%CVE-2022-37774MEDIUMThere is a broken access control vulnerability in the Maarch RM 2.8.3 solution. When accessing some specific document (pdf, email) from an aEPSS 0.6%CVE-2026-4592MEDIUMkalcaddle kodbox Password Login index.class.php tfaVerify improper authenticationEPSS 0.6%CVE-2026-14627MEDIUMNousResearch hermes-agent Discord Platform Integration discord.py DiscordAdapter._is_allowed_user improper authenticationEPSS 0.6%CVE-2026-45156HIGHNextcloud: Authentication Bypass in ID4me handling via Missing JWT Signature Verification in User OIDCEPSS 0.6%CVE-2026-47426HIGHOpenAM OAuth Client Impersonation via JWKS Resolver CacheEPSS 0.6%CVE-2025-30361CRITICALWeGIA Vulnerable to Broken Authentication - Old Password ValidationEPSS 0.6%CVE-2026-90474HIGHMCPHub before 1.0.32 OAuth 2.0 Authentication BypassEPSS 0.6%CVE-2026-89136HIGHClient accepts unsolicited RawPublicKey server certificate typeEPSS 0.6%CVE-2026-77567HIGHFilament: App-based MFA can be bypassed when recovery codes are enabledEPSS 0.6%CVE-2025-5985MEDIUMcode-projects School Fees Payment System improper authenticationEPSS 0.6%CVE-2026-16261HIGHHuge IT Login <= 1.0.4 - Unauthenticated Account TakeoverEPSS 0.6%CVE-2022-44610MEDIUMImproper authentication in the Intel(R) DCM software before version 5.1 may allow an authenticated user to potentially enable escalation of EPSS 0.6%CVE-2022-3674HIGHSourceCodester Sanitization Management System missing authenticationEPSS 0.5%CVE-2024-36402MEDIUMUnauthenticated writes to the media repository allow planting of problematic content in Matrix Media RepoEPSS 0.5%CVE-2024-43240CRITICALWordPress Indeed Ultimate Membership Pro plugin <= 12.7 - Unauthenticated Privilege Escalation vulnerabilityEPSS 0.5%CVE-2025-63210CRITICALThe Newtec Celox UHD (models: CELOXA504, CELOXA820) running firmware version celox-21.6.13 is vulnerable to an authentication bypass. An attEPSS 0.5%CVE-2020-16222—Philips Patient Monitoring Devices Improper AuthenticationEPSS 0.5%CVE-2023-36724MEDIUMWindows Power Management Service Information Disclosure VulnerabilityEPSS 0.5%