Falhas do tipo CWE-287

2.453 resultados

Autenticação Insuficiente ou Ausente

Quando um usuário ou sistema afirma ser quem diz que é, a aplicação não valida (ou valida mal) essa identidade antes de conceder acesso. Isso permite que um atacante se passe por outra pessoa sem fornecer credenciais válidas, obtendo privilégios indevidos.

Exemplo

Um sistema que aceita login apenas verificando um campo de e-mail na sessão (sem senha), ou uma API que confia em um identificador de usuário enviado no header HTTP sem validar um token assinado. Um atacante simplesmente muda o valor e acessa dados de terceiros.

Como mitigar

Implemente autenticação robusta: exija senha forte + MFA quando possível, valide tokens com assinatura criptográfica, revoque sessões expiradas, e nunca confie em dados controlados pelo cliente. Teste autenticação em cada endpoint crítico.

CVE-2024-34399CRITICAL**UNSUPPORTED WHEN ASSIGNED** An issue was discovered in BMC Remedy Mid Tier 7.6.04. An unauthenticated remote attacker is able to access anEPSS 0.5%CVE-2025-64055CRITICALAn issue was discovered in Fanvil x210 V2 2.12.20 allowing unauthenticated attackers on the local network to access administrative functionsEPSS 0.5%CVE-2026-61436HIGHPraisonAI before 4.6.78 Missing Webhook Signature VerificationEPSS 0.5%CVE-2026-54547HIGHMeta Ads MCP: X-Pipeboard-Token Header Auth Bypass Reuses Operator Meta TokenEPSS 0.5%CVE-2025-49591HIGHCryptPad 2FA Bypass VulnerabilityEPSS 0.5%CVE-2026-50338HIGHAzure Spring Apps Elevation of Privilege VulnerabilityEPSS 0.5%CVE-2026-56237CRITICALCapgo - Unauthenticated API Key Generation via Client-Side Parameter ManipulationEPSS 0.5%CVE-2024-10620MEDIUMknightliao Disconf Configuration Center list improper authenticationEPSS 0.5%CVE-2023-1980MEDIUMTwo factor authentication bypass on login in Devolutions Remote Desktop Manager 2022.3.35 and earlier allow user to cancel the two factorEPSS 0.5%CVE-2026-15372HIGHWP 2FA < 4.1.0 - Two-Factor Authentication Bypass via Passkeys ProviderEPSS 0.5%CVE-2024-38523HIGHHush Line OTP issueEPSS 0.5%CVE-2021-32738MEDIUMUtils.readChallengeTx does not verify the server account signatureEPSS 0.5%CVE-2024-11917HIGHJobSearch WP Job Board <= 2.9.2 - Authentication Bypass via Social LoginsEPSS 0.5%CVE-2024-36444HIGHcgi-bin/fdmcgiwebv2.cgi on Swissphone DiCal-RED 4009 devices allows an unauthenticated attacker to gain access to device logs.EPSS 0.5%CVE-2026-14557CRITICALSoftMarket <= 1.0.0 - Unauthenticated Account Takeover via Email Verification BypassEPSS 0.5%CVE-2024-11293HIGHRegistration Forms – User Registration Forms, Invitation-Based Registrations, Front-end User Profile, Login Form & Content Restriction Social Sites Login <= 1.7.9 - Authentication Bypass via WordPress.com OAuth providerEPSS 0.5%CVE-2025-15581MEDIUMOrthanc versions before 1.12.10 are affected by an authorisation logic flaw in the application's HTTP Basic Authentication implementation. EPSS 0.5%CVE-2024-41929HIGHImproper authentication vulnerability in multiple digital video recorders provided by TAKENAKA ENGINEERING CO., LTD. allows a remote authentEPSS 0.5%CVE-2022-39231LOWParse Server subject to Improper Authentication allowing Auth adapter app ID validation to be circumventedEPSS 0.5%CVE-2025-23116CRITICALAn Authentication Bypass vulnerability on UniFi Protect Application with Auto-Adopt Bridge Devices enabled could allow a malicious actor witEPSS 0.5%