Falhas do tipo CWE-287

2.454 resultados

Autenticação Insuficiente ou Ausente

Quando um usuário ou sistema afirma ser quem diz que é, a aplicação não valida (ou valida mal) essa identidade antes de conceder acesso. Isso permite que um atacante se passe por outra pessoa sem fornecer credenciais válidas, obtendo privilégios indevidos.

Exemplo

Um sistema que aceita login apenas verificando um campo de e-mail na sessão (sem senha), ou uma API que confia em um identificador de usuário enviado no header HTTP sem validar um token assinado. Um atacante simplesmente muda o valor e acessa dados de terceiros.

Como mitigar

Implemente autenticação robusta: exija senha forte + MFA quando possível, valide tokens com assinatura criptográfica, revoque sessões expiradas, e nunca confie em dados controlados pelo cliente. Teste autenticação em cada endpoint crítico.

CVE-2024-22441CRITICALHPE Cray Parallel Application Launch Service (PALS) is subject to an authentication bypass.EPSS 0.5%CVE-2022-46316CRITICALA thread security vulnerability exists in the authentication process. Successful exploitation of this vulnerability may affect data integritEPSS 0.5%CVE-2026-55761HIGHPortainer: Unauthenticated Restore Endpoint Allows Admin Takeover on Uninitialised Portainer InstancesEPSS 0.5%CVE-2026-21881CRITICALKanboard is Vulnerable to Reverse Proxy Authentication BypassEPSS 0.5%CVE-2025-5247MEDIUMGowabby HFish url.go LoadUrl improper authenticationEPSS 0.5%CVE-2022-23501MEDIUMTYPO3 vulnerable to Improper Authentication in Frontend LoginEPSS 0.5%CVE-2022-39238MEDIUMImproper Authentication in Arvados when using PAM as identity providerEPSS 0.5%CVE-2025-66698HIGHAn issue in Semantic machines v5.4.8 allows attackers to bypass authentication via sending a crafted HTTP request to various API endpoints.EPSS 0.5%CVE-2025-2344MEDIUMIROAD Dash Cam X5/Dash Cam X6 API Endpoint missing authenticationEPSS 0.5%CVE-2026-94606HIGHauthentik: MFA Bypass via State Confusion / Parameter Injection in AuthenticatorEmailStageEPSS 0.5%CVE-2026-24038HIGHHorilla HR has 2FA Bypass through its OTP Handling LogicEPSS 0.5%CVE-2026-46715MEDIUMFlask-Security-Too OAuth reauthentication freshness bypass via cross- user OAuth identity acceptanceEPSS 0.5%CVE-2025-57434HIGHCreacast Creabox Manager contains a critical authentication flaw that allows an attacker to bypass login validation. The system grants accesEPSS 0.5%CVE-2022-47209HIGHA support user exists on the device and appears to be a backdoor for Technical Support staff. The default password for this account is “suppEPSS 0.5%CVE-2023-28963MEDIUMJunos OS: User-controlled input vulnerability in J-WebEPSS 0.5%CVE-2025-52553MEDIUMauthentik has Insufficient Session verification for Remote Access Control endpoint accessEPSS 0.5%CVE-2025-49146HIGHpgjdbc Client Allows Fallback to Insecure Authentication Despite channelBinding=require ConfigurationEPSS 0.5%CVE-2026-7844MEDIUMchatchat-space Langchain-Chatchat Compatible File Service openai_routes.py delete_file missing authenticationEPSS 0.5%CVE-2024-25106CRITICALOpenObserve Unauthorized Access Vulnerability in Users APIEPSS 0.5%CVE-2025-15224LOWlibssh key passphrase bypass without agent setEPSS 0.5%