Falhas do tipo CWE-287

2.456 resultados

Autenticação Insuficiente ou Ausente

Quando um usuário ou sistema afirma ser quem diz que é, a aplicação não valida (ou valida mal) essa identidade antes de conceder acesso. Isso permite que um atacante se passe por outra pessoa sem fornecer credenciais válidas, obtendo privilégios indevidos.

Exemplo

Um sistema que aceita login apenas verificando um campo de e-mail na sessão (sem senha), ou uma API que confia em um identificador de usuário enviado no header HTTP sem validar um token assinado. Um atacante simplesmente muda o valor e acessa dados de terceiros.

Como mitigar

Implemente autenticação robusta: exija senha forte + MFA quando possível, valide tokens com assinatura criptográfica, revoque sessões expiradas, e nunca confie em dados controlados pelo cliente. Teste autenticação em cada endpoint crítico.

CVE-2025-27403HIGHRatify Azure authentication providers can leak authentication tokens to non-Azure container registriesEPSS 0.5%CVE-2023-5328MEDIUMSATO CL4NX-J Plus Cookie improper authenticationEPSS 0.5%CVE-2025-9803CRITICALImproper Authentication in lunary-ai/lunaryEPSS 0.5%CVE-2025-13427MEDIUMAuthentication Bypass in Dialogflow CX MessengerEPSS 0.5%CVE-2024-45346HIGHGetApps application has code execution vulnerabilityEPSS 0.5%CVE-2026-73655HIGHTrigger.dev: Account Takeover via Cross-Provider OAuth Email Matching in Google LoginEPSS 0.5%CVE-2026-73771HIGHImproper Authentication Handling in AOS-CX Management Interface and APIEPSS 0.5%CVE-2025-5872MEDIUMeGauge EG3000 Energy Monitor Setting missing authenticationEPSS 0.5%CVE-2025-5876MEDIUMLucky LM-520-SC/LM-520-FSC/LM-520-FSC-SAM missing authenticationEPSS 0.5%CVE-2026-84831HIGHMandatory MFA bypass before enrollmentEPSS 0.5%CVE-2025-27416MEDIUMAsking For Scratch Username And PasswordEPSS 0.5%CVE-2023-39303MEDIUMQTS, QuTS hero, QuTScloudEPSS 0.5%CVE-2026-21854CRITICALTarkov Data Manager Authentication Bypass vulnerabilityEPSS 0.5%CVE-2026-76338HIGHImproper Authentication through REST API Distributed Search Token Requests in Splunk EnterpriseEPSS 0.5%CVE-2026-13600HIGHAutoNetTV Relay < 3.0.14 - Unauthenticated Privilege Escalation via Scheduled Sync CronEPSS 0.5%CVE-2026-12255HIGHMainWP Child < 6.1.2 - Unauthenticated Administrator Authentication Bypass via Passwordless Site RegistrationEPSS 0.5%CVE-2026-76793HIGHFirebase Authentication < 1.7.1 - Unauthenticated Account Takeover via Firebase Email ClaimEPSS 0.5%CVE-2026-73241HIGHFreeRDP: RDSTLS server authentication bypass: a credential-less Capabilities PDU is accepted at the auth step (fail-open `resultCode`)EPSS 0.5%CVE-2024-49376HIGHAutolab Has Misconfigured Reset Password PermissionsEPSS 0.5%CVE-2026-10845HIGHIBM WebSphere Application Server is affected by an authentication bypass vulnerabilityEPSS 0.5%