Falhas do tipo CWE-287

2.456 resultados

Autenticação Insuficiente ou Ausente

Quando um usuário ou sistema afirma ser quem diz que é, a aplicação não valida (ou valida mal) essa identidade antes de conceder acesso. Isso permite que um atacante se passe por outra pessoa sem fornecer credenciais válidas, obtendo privilégios indevidos.

Exemplo

Um sistema que aceita login apenas verificando um campo de e-mail na sessão (sem senha), ou uma API que confia em um identificador de usuário enviado no header HTTP sem validar um token assinado. Um atacante simplesmente muda o valor e acessa dados de terceiros.

Como mitigar

Implemente autenticação robusta: exija senha forte + MFA quando possível, valide tokens com assinatura criptográfica, revoque sessões expiradas, e nunca confie em dados controlados pelo cliente. Teste autenticação em cada endpoint crítico.

CVE-2024-13804CRITICALUnauthenticated RCE in HPE Insight Cluster Management UtilityEPSS 0.5%CVE-2025-2388MEDIUMKeytop 路内停车收费系统 API getParks improper authenticationEPSS 0.5%CVE-2026-41571CRITICALNote Mark: OIDC-registered users authenticated by submitting password "null"EPSS 0.5%CVE-2025-3062MEDIUMDrupal Admin LTE theme - Critical - Unsupported - SA-CONTRIB-2025-010EPSS 0.5%CVE-2025-3061MEDIUMMaterial Admin - Critical - Unsupported - SA-CONTRIB-2025-006EPSS 0.5%CVE-2026-72922HIGHAutoGPT: Webhook provider path confusion bypasses generic webhook secret verificationEPSS 0.5%CVE-2023-21027HIGHIn multiple functions of PasspointXmlUtils.java, there is a possible authentication misconfiguration due to a logic error in the code. This EPSS 0.5%CVE-2026-92914HIGHAVideo LoginControl PGP Second Factor Authentication BypassEPSS 0.5%CVE-2025-61665HIGHWeGIA: Broken Access Control in `get_relatorios_socios.php` EndpointEPSS 0.5%CVE-2024-1609HIGHOPPO Store APP has a WebView component privilege escalation vulnerability.EPSS 0.5%CVE-2026-48528CRITICALMetacat has an unauthenticated SQL injection vulnerabilityEPSS 0.5%CVE-2026-86723HIGHAVideo LoginControl PGP Authentication Bypass via verifyChallengeEPSS 0.5%CVE-2023-42662CRITICALJFrog Artifactory Improper SSO Mechanism may lead to Exposure of Access TokensEPSS 0.5%CVE-2026-86722HIGHAVideo Authentication Bypass via SQL Cache InvalidationEPSS 0.5%CVE-2022-24885LOWImproper Authentication in Nextcloud Android FilesEPSS 0.5%CVE-2026-32305HIGHTraefik mTLS bypass via fragmented ClientHello SNI extraction failureEPSS 0.5%CVE-2024-25618MEDIUMExternal OpenID Connect Account Takeover by E-Mail Change in mastodonEPSS 0.5%CVE-2026-50191HIGH4gaBoards: Pre-Account Takeover via SSO Email LinkageEPSS 0.5%CVE-2025-5871MEDIUMPapendorf SOL Connect Center Web Interface missing authenticationEPSS 0.5%CVE-2025-27403HIGHRatify Azure authentication providers can leak authentication tokens to non-Azure container registriesEPSS 0.5%