Falhas do tipo CWE-287

2.453 resultados

Autenticação Insuficiente ou Ausente

Quando um usuário ou sistema afirma ser quem diz que é, a aplicação não valida (ou valida mal) essa identidade antes de conceder acesso. Isso permite que um atacante se passe por outra pessoa sem fornecer credenciais válidas, obtendo privilégios indevidos.

Exemplo

Um sistema que aceita login apenas verificando um campo de e-mail na sessão (sem senha), ou uma API que confia em um identificador de usuário enviado no header HTTP sem validar um token assinado. Um atacante simplesmente muda o valor e acessa dados de terceiros.

Como mitigar

Implemente autenticação robusta: exija senha forte + MFA quando possível, valide tokens com assinatura criptográfica, revoque sessões expiradas, e nunca confie em dados controlados pelo cliente. Teste autenticação em cada endpoint crítico.

CVE-2026-49843MEDIUMFreeSWITCH: Pre-authentication session eviction via attacker-chosen `sessid` in `mod_verto`EPSS 0.5%CVE-2025-61922CRITICALPrestaShop Checkout allows customer account takeover via emailEPSS 0.5%CVE-2022-46773MEDIUMIBM Robotic Process Automation security bypassEPSS 0.5%CVE-2026-16686HIGHVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.5%CVE-2026-7876CRITICALAuthentication bypass vulnerability found in Aspera High-Speed Transfer Server for Cloud Pak for IntegrationEPSS 0.5%CVE-2025-22375CRITICALAuthentication Bypass in CyberAudit-WebEPSS 0.5%CVE-2018-25236CRITICALHirschmann HiOS HiSecOS Authentication Bypass via HTTP ManagementEPSS 0.5%CVE-2025-56333CRITICALAn issue in Fossorial fosrl/pangolin v.1.6.2 and before allows a remote attacker to escalate privileges via the 2FA componentEPSS 0.5%CVE-2024-44202MEDIUMAn authentication issue was addressed with improved state management. This issue is fixed in Safari 18, iOS 18 and iPadOS 18. Private BrowsiEPSS 0.5%CVE-2026-62669HIGHGrav Login Plugin: 2FA Bypass via 'login.regenerate2FASecret' - Secret Rotation During Pending ChallengeEPSS 0.5%CVE-2026-56675HIGH9router: Reverse proxy locality collapse allows unauthenticated access to 9router /v1 APIsEPSS 0.5%CVE-2026-55727HIGHA flaw in the authentication mechanism for video stream requests in Genetec Security Center 5.14.0.0 prior to build 5.14.178.18 may allow anEPSS 0.5%CVE-2025-3222CRITICALSmallworld SWMFS Improper AuthenticationEPSS 0.5%CVE-2024-37367HIGHRockwell Automation FactoryTalk® View SE v12 Information Leakage Vulnerability via Authentication RestrictionEPSS 0.5%CVE-2024-37368HIGHRockwell Automation FactoryTalk® View SE v11 Information Leakage Vulnerability via Authentication RestrictionEPSS 0.5%CVE-2026-18031CRITICALTabaPay Gateway <= 1.4.0 - Unauthenticated Account Takeover via Payment CallbackEPSS 0.5%CVE-2026-16299CRITICALSingle Sign On For TNG < 2.2.0 - Unauthenticated Arbitrary Password ResetEPSS 0.5%CVE-2026-14182CRITICALCustomer Email Verification for WooCommerce < 3.2.6 - Unauthenticated Account Takeover via Type-Juggling Authentication BypassEPSS 0.5%CVE-2026-59500CRITICALPriority - CWE-287: Improper AuthenticationEPSS 0.5%CVE-2026-14919CRITICALShopMonitor.io < 1.2.0 - Unauthenticated Administrator Account Takeover via Password-Reset Email RerouteEPSS 0.5%