Falhas do tipo CWE-287

2.452 resultados

Autenticação Insuficiente ou Ausente

Quando um usuário ou sistema afirma ser quem diz que é, a aplicação não valida (ou valida mal) essa identidade antes de conceder acesso. Isso permite que um atacante se passe por outra pessoa sem fornecer credenciais válidas, obtendo privilégios indevidos.

Exemplo

Um sistema que aceita login apenas verificando um campo de e-mail na sessão (sem senha), ou uma API que confia em um identificador de usuário enviado no header HTTP sem validar um token assinado. Um atacante simplesmente muda o valor e acessa dados de terceiros.

Como mitigar

Implemente autenticação robusta: exija senha forte + MFA quando possível, valide tokens com assinatura criptográfica, revoque sessões expiradas, e nunca confie em dados controlados pelo cliente. Teste autenticação em cada endpoint crítico.

CVE-2026-60367CRITICALVulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). SupporEPSS 0.5%CVE-2023-44039CRITICALIn VeridiumID before 3.5.0, the WebAuthn API allows an internal unauthenticated attacker (who can pass enrollment verifications and is allowEPSS 0.5%CVE-2025-9965CRITICALUDP Service Weak AuthenticationEPSS 0.5%CVE-2025-9100MEDIUMzhenfeng13 My-Blog Frontend Blog Article Comment comment authentication replayEPSS 0.5%CVE-2023-37268MEDIUMUser login confusion with SSO in warpgateEPSS 0.5%CVE-2025-11661MEDIUMProjectsAndPrograms School Management System missing authenticationEPSS 0.5%CVE-2024-21543MEDIUMVersions of the package djoser before 2.3.0 are vulnerable to Authentication Bypass when the authenticate() function fails. This is because EPSS 0.5%CVE-2026-2065MEDIUMFlycatcher Toys smART Pixelator Bluetooth Low Energy missing authenticationEPSS 0.5%CVE-2023-23857CRITICALImproper Access Control in SAP NetWeaver AS for JavaEPSS 0.5%CVE-2022-26508MEDIUMImproper authentication in the Intel(R) SDP Tool before version 3.0.0 may allow an unauthenticated user to potentially enable information diEPSS 0.5%CVE-2023-47222CRITICALMedia Streaming add-onEPSS 0.5%CVE-2024-45823CRITICALFactoryTalk® Batch View™ Authentication Bypass Vulnerability via shared secretsEPSS 0.5%CVE-2024-23647MEDIUMPKCE downgrade attack in AuthentikEPSS 0.5%CVE-2024-41199HIGHAn issue in Ocuco Innovation - JOBMANAGER.EXE v2.10.24.16 allows attackers to bypass authentication and escalate privileges to AdministratorEPSS 0.5%CVE-2026-50623MEDIUMApache CXF: Authentication Bypass in OAuth2 TokenIntrospectionServiceEPSS 0.5%CVE-2026-18786HIGHCheckView < 2.3.2 - Administrator Account Creation via REST API Authentication BypassEPSS 0.5%CVE-2026-2991HIGHKiviCare – Clinic & Patient Management System (EHR) <= 4.1.2 - Unauthenticated Authentication Bypass via Social Login TokenEPSS 0.5%CVE-2024-41798CRITICALA vulnerability has been identified in SENTRON 7KM PAC3200 (All versions). Affected devices only provide a 4-digit PIN to protect from adminEPSS 0.5%CVE-2026-50365HIGHRemote Access Management service/API (RPC server) Elevation of Privilege VulnerabilityEPSS 0.5%CVE-2026-56080MEDIUMCap-go - Authentication Logic Flaw in Enforce Password PolicyEPSS 0.5%