Falhas do tipo CWE-287

2.453 resultados

Autenticação Insuficiente ou Ausente

Quando um usuário ou sistema afirma ser quem diz que é, a aplicação não valida (ou valida mal) essa identidade antes de conceder acesso. Isso permite que um atacante se passe por outra pessoa sem fornecer credenciais válidas, obtendo privilégios indevidos.

Exemplo

Um sistema que aceita login apenas verificando um campo de e-mail na sessão (sem senha), ou uma API que confia em um identificador de usuário enviado no header HTTP sem validar um token assinado. Um atacante simplesmente muda o valor e acessa dados de terceiros.

Como mitigar

Implemente autenticação robusta: exija senha forte + MFA quando possível, valide tokens com assinatura criptográfica, revoque sessões expiradas, e nunca confie em dados controlados pelo cliente. Teste autenticação em cada endpoint crítico.

CVE-2026-2248CRITICALUnauthenticated Remote Root Shell Access via Web Console in METIS WICEPSS 0.5%CVE-2025-32879HIGHAn issue was discovered on COROS PACE 3 devices through 3.0808.0. It starts advertising if no device is connected via Bluetooth. This allowsEPSS 0.5%CVE-2024-9947HIGHProfilePress - Pro <= 4.11.1 - Authentication Bypass via WordPress.com OAuth providerEPSS 0.5%CVE-2026-56793HIGHDell OpenManage Server Administrator, versions prior to 11.1.0.2, contains an Improper Authentication vulnerability. An unauthenticated attaEPSS 0.5%CVE-2022-23540MEDIUMjsonwebtoken vulnerable to signature validation bypass due to insecure default algorithm in jwt.verify()EPSS 0.5%CVE-2026-9373MEDIUMJeecgBoot OpenAPI Endpoint call improper authenticationEPSS 0.5%CVE-2026-14291HIGHSecurity Ninja (Premium) < 5.290 - Two-Factor Authentication Bypass via secnin_skip_2faEPSS 0.5%CVE-2025-6979HIGHCaptive Portal can allow authentication bypassEPSS 0.5%CVE-2025-6172CRITICALPermission vulnerability in the mobile application (com.afmobi.boomplayer) may lead to the risk of unauthorized operation.EPSS 0.5%CVE-2024-57432HIGHmacrozheng mall-tiny 1.0.1 suffers from Insecure Permissions. The application's JWT signing keys are hardcoded and do not change. User inforEPSS 0.5%CVE-2025-8838MEDIUMWinterChenS my-site Backend admin preHandle improper authenticationEPSS 0.5%CVE-2026-36727CRITICALAn insecure authentication vulnerability in the /api/social-sign-in endpoint of bookcars v8.3 allows attackers to bypass authentication via EPSS 0.5%CVE-2026-44196CRITICALPingvin Share X: TOTP Authentication Bypass via Password-only LoginEPSS 0.5%CVE-2025-8348MEDIUMKehua Charging Pile Cloud Platform home improper authenticationEPSS 0.5%CVE-2026-32815MEDIUMSiYuan: Cross-Origin WebSocket Hijacking via Authentication Bypass — Unauthenticated Information DisclosureEPSS 0.5%CVE-2025-56752CRITICALA vulnerability in the Ruijie RG-ES series switch firmware ESW_1.0(1)B1P39 enables remote attackers to fully bypass authentication mechanismEPSS 0.5%CVE-2020-5224MEDIUMSession key exposure through session list in Django User SessionsEPSS 0.5%CVE-2024-11671MEDIUMImproper authentication in SQL data source MFA validation in Devolutions Remote Desktop Manager 2024.3.17 and earlier on Windows allows an aEPSS 0.5%CVE-2026-49872MEDIUMApache APISIX: Improper authentication in cas-auth pluginEPSS 0.5%CVE-2025-9994CRITICALAmp’ed RF BT-AP 111 Bluetooth access point's HTTP admin interface does not require authenticationEPSS 0.5%