Falhas do tipo CWE-287

2.452 resultados

Autenticação Insuficiente ou Ausente

Quando um usuário ou sistema afirma ser quem diz que é, a aplicação não valida (ou valida mal) essa identidade antes de conceder acesso. Isso permite que um atacante se passe por outra pessoa sem fornecer credenciais válidas, obtendo privilégios indevidos.

Exemplo

Um sistema que aceita login apenas verificando um campo de e-mail na sessão (sem senha), ou uma API que confia em um identificador de usuário enviado no header HTTP sem validar um token assinado. Um atacante simplesmente muda o valor e acessa dados de terceiros.

Como mitigar

Implemente autenticação robusta: exija senha forte + MFA quando possível, valide tokens com assinatura criptográfica, revoque sessões expiradas, e nunca confie em dados controlados pelo cliente. Teste autenticação em cada endpoint crítico.

CVE-2025-11529MEDIUMChurchCRM API Endpoint AuthMiddleware.php AuthMiddleware missing authenticationEPSS 0.5%CVE-2025-30116HIGHAn issue was discovered on the Forvia Hella HELLA Driving Recorder DR 820. Remotely Dumping of Video Footage and the Live Video Stream can oEPSS 0.5%CVE-2024-56336CRITICALA vulnerability has been identified in SINAMICS S200 (All versions with serial number beginning with SZVS8, SZVS9, SZVS0 or SZVSN and the FSEPSS 0.5%CVE-2026-64665HIGHStatamic: Account takeover via OAuth email matching without email-verification checkEPSS 0.5%CVE-2023-4242MEDIUMFULL - Customer <= 2.2.3 - Authenticated(Subscriber+) Information Disclosure via Health CheckEPSS 0.5%CVE-2024-10114HIGHSocial Login - WordPress / WooCommerce Plugin <= 2.7.7 - Authentication Bypass via WordPress.com OAuth providerEPSS 0.5%CVE-2026-73054HIGHSiYuan before v3.7.4 Authentication Bypass via WebSocketEPSS 0.5%CVE-2022-46172MEDIUMauthentik allows existing authenticated users to create arbitrary accountsEPSS 0.5%CVE-2026-82107CRITICALDataStage on Cloud Pak for Data has several vulnerabilities due to open source softwareEPSS 0.5%CVE-2026-31377HIGHApache Doris: Improper Authentication Allows Unauthorized Access to FE Meta ServiceEPSS 0.5%CVE-2024-52518MEDIUMNextcloud Server is missing password confirmation when changing external storage optionsEPSS 0.5%CVE-2026-9371MEDIUMItzCrazyKns Vane API route.ts missing authenticationEPSS 0.5%CVE-2025-47275CRITICALBrute Force Authentication Tags of CookieStore Sessions in Auth0-PHP SDKEPSS 0.5%CVE-2021-4197—An unprivileged write to the file handler flaw in the Linux kernel's control groups and namespaces subsystem was found in the way users haveEPSS 0.5%CVE-2022-36071HIGHRecovery codes abuse in SFTPGoEPSS 0.5%CVE-2026-4349MEDIUMDuende IdentityServer4 Token Renewal Endpoint authorize improper authenticationEPSS 0.5%CVE-2026-58423HIGHLFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositoriesEPSS 0.5%CVE-2026-22236CRITICALImproper Authentication Vulnerability in BLUVOYIXEPSS 0.5%CVE-2026-2249CRITICALUnauthenticated Remote Command Execution via Web Console in METIS DFSEPSS 0.5%CVE-2026-2248CRITICALUnauthenticated Remote Root Shell Access via Web Console in METIS WICEPSS 0.5%