Falhas do tipo CWE-287

2.453 resultados

Autenticação Insuficiente ou Ausente

Quando um usuário ou sistema afirma ser quem diz que é, a aplicação não valida (ou valida mal) essa identidade antes de conceder acesso. Isso permite que um atacante se passe por outra pessoa sem fornecer credenciais válidas, obtendo privilégios indevidos.

Exemplo

Um sistema que aceita login apenas verificando um campo de e-mail na sessão (sem senha), ou uma API que confia em um identificador de usuário enviado no header HTTP sem validar um token assinado. Um atacante simplesmente muda o valor e acessa dados de terceiros.

Como mitigar

Implemente autenticação robusta: exija senha forte + MFA quando possível, valide tokens com assinatura criptográfica, revoque sessões expiradas, e nunca confie em dados controlados pelo cliente. Teste autenticação em cada endpoint crítico.

CVE-2026-12492CRITICALHappy Coders OTP Login for WooCommerce < 2.8 - Unauthenticated Account Takeover via hcotp_auto_login_userEPSS 0.5%CVE-2026-100746MEDIUMcoollabsio Coolify GitHub App Setup redirect missing authenticationEPSS 0.5%CVE-2026-86707CRITICALPrivate Feed Key <= 0.1 - Unauthenticated Authentication Bypass via 'feedkey' ParameterEPSS 0.5%CVE-2024-37367HIGHRockwell Automation FactoryTalk® View SE v12 Information Leakage Vulnerability via Authentication RestrictionEPSS 0.5%CVE-2026-14182CRITICALCustomer Email Verification for WooCommerce < 3.2.6 - Unauthenticated Account Takeover via Type-Juggling Authentication BypassEPSS 0.5%CVE-2026-86710CRITICALLogin with QR <= 1.0.0 - Unauthenticated Authentication Bypass via 'autologin_code' ParameterEPSS 0.5%CVE-2024-37368HIGHRockwell Automation FactoryTalk® View SE v11 Information Leakage Vulnerability via Authentication RestrictionEPSS 0.5%CVE-2026-16299CRITICALSingle Sign On For TNG < 2.2.0 - Unauthenticated Arbitrary Password ResetEPSS 0.5%CVE-2026-7664CRITICALUnauthenticated Flow Execution via Webhook Endpoint in Langflow OSSEPSS 0.5%CVE-2025-12374CRITICALEmail Verification, Email OTP, Block Spam Email, Passwordless login, Hide Login, Magic Login – User Verification <= 2.0.44 - Authentication Bypass to Account TakeoverEPSS 0.5%CVE-2023-22663MEDIUMImproper authentication for some Intel Unison software may allow an authenticated user to potentially enable escalation of privilege via netEPSS 0.5%CVE-2026-95676HIGHAuthPoint Gateway Improper Authentication in LDAP Sync Allows First-Factor Authentication BypassEPSS 0.5%CVE-2023-46172MEDIUMIBM DS8900F security bypassEPSS 0.5%CVE-2026-10288MEDIUMcode-projects Hotel and Tourism Reservation System Admin Login login.php password_verify improper authenticationEPSS 0.5%CVE-2026-33117CRITICALAzure SDK for Java Security Feature Bypass VulnerabilityEPSS 0.5%CVE-2026-17197HIGHIBM i is Affected By Multiple Vulnerabilities in Host ServersEPSS 0.5%CVE-2022-34331MEDIUMIBM Power FW security bypassEPSS 0.5%CVE-2026-86721HIGHAVideo through c3edcc274c Authorization Bypass via Session CookieEPSS 0.5%CVE-2024-35184MEDIUMpaperless-ngx's remote user auth via header works even when disabling it for APIEPSS 0.5%CVE-2024-22441CRITICALHPE Cray Parallel Application Launch Service (PALS) is subject to an authentication bypass.EPSS 0.5%