Falhas do tipo CWE-287

2.456 resultados

Autenticação Insuficiente ou Ausente

Quando um usuário ou sistema afirma ser quem diz que é, a aplicação não valida (ou valida mal) essa identidade antes de conceder acesso. Isso permite que um atacante se passe por outra pessoa sem fornecer credenciais válidas, obtendo privilégios indevidos.

Exemplo

Um sistema que aceita login apenas verificando um campo de e-mail na sessão (sem senha), ou uma API que confia em um identificador de usuário enviado no header HTTP sem validar um token assinado. Um atacante simplesmente muda o valor e acessa dados de terceiros.

Como mitigar

Implemente autenticação robusta: exija senha forte + MFA quando possível, valide tokens com assinatura criptográfica, revoque sessões expiradas, e nunca confie em dados controlados pelo cliente. Teste autenticação em cada endpoint crítico.

CVE-2026-14205CRITICALWP Events Manager < 2.2.5 - Subscriber+ Payment Bypass via 'qty' ParameterEPSS 0.5%CVE-2026-83261CRITICALVulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Core). The supported version that is afEPSS 0.5%CVE-2026-83269CRITICALVulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versions that are affecteEPSS 0.5%CVE-2026-83355CRITICALVulnerability in the Oracle Enterprise Manager for Fusion Middleware product of Oracle Enterprise Manager (component: Metrics). Supported vEPSS 0.5%CVE-2026-70757CRITICALVulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected areEPSS 0.5%CVE-2026-70756CRITICALVulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected areEPSS 0.5%CVE-2026-83020CRITICALVulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). SupporEPSS 0.5%CVE-2026-82994CRITICALVulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). SupporEPSS 0.5%CVE-2026-83021CRITICALVulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). Supported versions that are affEPSS 0.5%CVE-2026-15611CRITICALUnverified email-based SSO account linkingEPSS 0.5%CVE-2026-34121HIGHAuthentication Bypass in DS Configuration Service via HTTP Request Parsing Differential of TP-Link Tapo C520WSEPSS 0.5%CVE-2026-5076CRITICALARMember Premium <= 7.3.1 - Insecure Password Reset Mechanism to Unauthenticated Privilege EscalationEPSS 0.5%CVE-2026-52893CRITICALWekan: OIDC Account Takeover via Unconditional Email-Based Account Merge in onCreateUser hookEPSS 0.5%CVE-2025-43936HIGHDell ObjectScale, versions prior to ObjectScale 4.4.0.0, contains an Improper Authentication vulnerability. An unauthenticated attacker withEPSS 0.5%CVE-2025-15586CRITICALOGP-Website installs prior git commit 52f865a4fba763594453068acf8fa9e3fc38d663 are affected by a type juggling flaw which if exploited can rEPSS 0.5%CVE-2024-21654MEDIUMrubygems.org MFA Bypass through password reset function could allow account takeover EPSS 0.5%CVE-2026-22752CRITICALSpring Security Authorization Server Dynamic Client Registration endpoints perform insufficient validation of client metadataEPSS 0.5%CVE-2026-55075HIGHCoder vulnerable to OIDC account takeover via email-based user matching and email_verified bypassEPSS 0.5%CVE-2026-34531MEDIUMFlask-HTTPAuth invokes token verification callback when missing or empty token was given by clientEPSS 0.5%CVE-2024-4129HIGHAuthentication bypass in Snow License ManagerEPSS 0.5%