Falhas do tipo CWE-287

2.456 resultados

Autenticação Insuficiente ou Ausente

Quando um usuário ou sistema afirma ser quem diz que é, a aplicação não valida (ou valida mal) essa identidade antes de conceder acesso. Isso permite que um atacante se passe por outra pessoa sem fornecer credenciais válidas, obtendo privilégios indevidos.

Exemplo

Um sistema que aceita login apenas verificando um campo de e-mail na sessão (sem senha), ou uma API que confia em um identificador de usuário enviado no header HTTP sem validar um token assinado. Um atacante simplesmente muda o valor e acessa dados de terceiros.

Como mitigar

Implemente autenticação robusta: exija senha forte + MFA quando possível, valide tokens com assinatura criptográfica, revoque sessões expiradas, e nunca confie em dados controlados pelo cliente. Teste autenticação em cada endpoint crítico.

CVE-2026-49186HIGHLack of MQTT Broker Topic Access Control ListsEPSS 0.5%CVE-2025-62376CRITICALpwn.college DOJO vulnerable to improper authentication in workspace endpoint allowing unauthorized Windows VM accessEPSS 0.5%CVE-2023-38691MEDIUMmatrix-appservice-bridge doesn't verify the sub parameter of an openId token exhange, allowing unauthorized access to provisioning APIsEPSS 0.5%CVE-2024-9927HIGHWooCommerce Order Proposal <= 2.0.5 - Authenticated (Shop Manager+) Privilege Escalation via Order ProposalEPSS 0.5%CVE-2026-10845HIGHIBM WebSphere Application Server is affected by an authentication bypass vulnerabilityEPSS 0.5%CVE-2025-14097HIGHRemote Code Execution Vulnerability in Radiometer ProductsEPSS 0.5%CVE-2026-73085MEDIUMAudiobookshelf: Refresh Token Accepted on Resource EndpointsEPSS 0.5%CVE-2026-55377HIGHLogto: Account Center MFA management step-up bypass via WebAuthn registration verificationEPSS 0.5%CVE-2020-7295LOWWeb Gateway (MWG) - Privilege Escalation vulnerabilityEPSS 0.5%CVE-2024-47078HIGHMeshtastic firmware Authentication/Authorization Bypass via MQTTEPSS 0.5%CVE-2026-73337HIGHJoomla! Core - [20260807] - MFA Authentication Bypass in Joomla 4.0.0-5.4.7 and 6.0.0-6.1.2EPSS 0.5%CVE-2026-46488CRITICALmotionEye: Authentication possible via password hashEPSS 0.5%CVE-2026-83327CRITICALVulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Personalization). Supported versions thatEPSS 0.5%CVE-2025-62349HIGHSalt Master authentication protocol downgrade may enable minion impersonationEPSS 0.5%CVE-2026-48114CRITICALMetacat has an unauthenticated SQL injection vulnerabilityEPSS 0.5%CVE-2026-21582HIGHThis High severity BASM (Broken Authentication & Session Management) vulnerability known as CVE-2026-21582 was introduced in version 7.2.1 oEPSS 0.5%CVE-2023-23761HIGHImproper authentication vulnerability in GitHub Enterprise Server leading to modification of secret gistsEPSS 0.5%CVE-2021-25910HIGHZIV AUTOMATION 4CCT vulnerable to improper authenticationEPSS 0.5%CVE-2026-44847HIGHMaxKB: Webhook Trigger Authentication BypassEPSS 0.5%CVE-2025-5870MEDIUMTRENDnet TV-IP121W Web Interface setup.cgi improper authenticationEPSS 0.5%