Falhas do tipo CWE-287

2.456 resultados

Autenticação Insuficiente ou Ausente

Quando um usuário ou sistema afirma ser quem diz que é, a aplicação não valida (ou valida mal) essa identidade antes de conceder acesso. Isso permite que um atacante se passe por outra pessoa sem fornecer credenciais válidas, obtendo privilégios indevidos.

Exemplo

Um sistema que aceita login apenas verificando um campo de e-mail na sessão (sem senha), ou uma API que confia em um identificador de usuário enviado no header HTTP sem validar um token assinado. Um atacante simplesmente muda o valor e acessa dados de terceiros.

Como mitigar

Implemente autenticação robusta: exija senha forte + MFA quando possível, valide tokens com assinatura criptográfica, revoque sessões expiradas, e nunca confie em dados controlados pelo cliente. Teste autenticação em cada endpoint crítico.

CVE-2026-27939HIGHStatamic allows Authenticated Control Panel users to escalate privileges via elevated session bypassEPSS 0.5%CVE-2026-44847HIGHMaxKB: Webhook Trigger Authentication BypassEPSS 0.5%CVE-2026-40138CRITICALCritical Pre-Authentication Vulnerability in BeyondTrust Remote Support and Privileged Remote AccessEPSS 0.5%CVE-2024-41800MEDIUMCraft CMS Allows TOTP Token To Stay Valid After UseEPSS 0.5%CVE-2025-0637CRITICALInadequate access control in Beta10EPSS 0.5%CVE-2026-84114MEDIUMCleo Harmony SAML Authentication LocalUserUtil.getNativeUserByAssertions improper authenticationEPSS 0.5%CVE-2023-35901LOWIBM Robotic Process Automation security bypassEPSS 0.5%CVE-2024-11087HIGHminiOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) Pro Addon <= 200.3.9 - Authentication BypassEPSS 0.5%CVE-2026-47718MEDIUMFUXA provides guest and invalid-token access to protected read APIs in secure modeEPSS 0.5%CVE-2025-53845MEDIUMAn improper authentication vulnerability [CWE-287] in Fortinet FortiAnalyzer version 7.6.0 through 7.6.3 and before 7.4.6 allows an unauthenEPSS 0.5%CVE-2024-38810MEDIUMMissing Authorization When Using @AuthorizeReturnObjectEPSS 0.5%CVE-2025-27621HIGHUpTrain has a Constant Default API KeyEPSS 0.5%CVE-2025-59280LOWWindows SMB Client Tampering VulnerabilityEPSS 0.5%CVE-2023-26150MEDIUMVersions of the package asyncua before 0.9.96 are vulnerable to Improper Authentication such that it is possible to access Address Space witEPSS 0.5%CVE-2026-16905MEDIUMIBM Db2 Mirror for i is affected by multiple vulnerabilitiesEPSS 0.5%CVE-2026-73777HIGHAuthorization Bypass Vulnerabilities Leading to Privilege Escalation in AOS-CX API EndpointEPSS 0.5%CVE-2026-68760MEDIUMPotential remember-me authentication bypass in JFrog ArtifactoryEPSS 0.5%CVE-2024-14034CRITICALHirschmann HiEOS Authentication Bypass via HTTP Management ModuleEPSS 0.5%CVE-2026-76684HIGHAuthentication Bypass Vulnerabilities in HPE Networking EdgeConnect SD-WAN Orchestrator APIEPSS 0.5%CVE-2026-79938HIGHDell PowerProtect Cyber Recovery, versions prior to 20.3, contain an Improper Authentication vulnerability. A low privileged attacker with rEPSS 0.5%