Falhas do tipo CWE-287

2.453 resultados

Autenticação Insuficiente ou Ausente

Quando um usuário ou sistema afirma ser quem diz que é, a aplicação não valida (ou valida mal) essa identidade antes de conceder acesso. Isso permite que um atacante se passe por outra pessoa sem fornecer credenciais válidas, obtendo privilégios indevidos.

Exemplo

Um sistema que aceita login apenas verificando um campo de e-mail na sessão (sem senha), ou uma API que confia em um identificador de usuário enviado no header HTTP sem validar um token assinado. Um atacante simplesmente muda o valor e acessa dados de terceiros.

Como mitigar

Implemente autenticação robusta: exija senha forte + MFA quando possível, valide tokens com assinatura criptográfica, revoque sessões expiradas, e nunca confie em dados controlados pelo cliente. Teste autenticação em cada endpoint crítico.

CVE-2026-83061CRITICALVulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Supported versions that arEPSS 0.5%CVE-2026-83042CRITICALVulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are afEPSS 0.5%CVE-2026-83099CRITICALVulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). Supported versions that aEPSS 0.5%CVE-2026-83339CRITICALVulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versionsEPSS 0.5%CVE-2026-73947CRITICALVulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that EPSS 0.5%CVE-2026-83066CRITICALVulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Supported versions that arEPSS 0.5%CVE-2026-46890CRITICALVulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Marketing). Supported versions that are affected are EPSS 0.5%CVE-2026-1740MEDIUMEFM ipTIME A8004T Hidden Hiddenloginsetup timepro.cgi httpcon_check_session_url improper authenticationEPSS 0.5%CVE-2025-67158HIGHAn authentication bypass in the /cgi-bin/jvsweb.cgi endpoint of Revotech I6032W-FHW v1.0.0014 - 20210517 allows attackers to access sensitivEPSS 0.5%CVE-2026-19607MEDIUMKeycloak-services: keycloak-services: broker-originated username collision causes account lockoutEPSS 0.5%CVE-2026-93532MEDIUMgedelumbung HospitalManagement Password Change password.php simpan improper authenticationEPSS 0.5%CVE-2026-78863MEDIUMliketrek TREK Pre-2FA mfa_token authService.ts loginUser improper authenticationEPSS 0.5%CVE-2026-18216MEDIUMBackup Migration < 2.1.7 - Admin+ Privilege Escalation via Post-Restore Auto-LoginEPSS 0.5%CVE-2026-5557MEDIUMbadlogic pi-mono pi-mom Slack Bot slack.ts authentication bypassEPSS 0.5%CVE-2026-16076MEDIUMAstrBotDevs AstrBot API open_api.py OpenApiRoute.chat_send authentication spoofingEPSS 0.5%CVE-2025-14002HIGHWPCOM Member <= 1.7.16 - Authentication Bypass via Weak OTPEPSS 0.5%CVE-2024-55954HIGHOpenObserve Improper Authorization Allows Admin User to Remove Root UserEPSS 0.5%CVE-2024-45750HIGHAn issue in TheGreenBow Windows Standard VPN Client 6.87.108 (and older), Windows Enterprise VPN Client 6.87.109 (and older), Windows EnterpEPSS 0.5%CVE-2019-3825MEDIUMA vulnerability was discovered in gdm before 3.31.4. When timed login is enabled in configuration, an attacker could bypass the lock screen EPSS 0.5%CVE-2026-57216MEDIUMRabbitMQ: AMQP 1.0, AMQP 0-9-1, Stream Protocol loopback enforcement can lead to remote guest sessions due to listener-address loopback checksEPSS 0.5%