Falhas do tipo CWE-287

2.456 resultados

Autenticação Insuficiente ou Ausente

Quando um usuário ou sistema afirma ser quem diz que é, a aplicação não valida (ou valida mal) essa identidade antes de conceder acesso. Isso permite que um atacante se passe por outra pessoa sem fornecer credenciais válidas, obtendo privilégios indevidos.

Exemplo

Um sistema que aceita login apenas verificando um campo de e-mail na sessão (sem senha), ou uma API que confia em um identificador de usuário enviado no header HTTP sem validar um token assinado. Um atacante simplesmente muda o valor e acessa dados de terceiros.

Como mitigar

Implemente autenticação robusta: exija senha forte + MFA quando possível, valide tokens com assinatura criptográfica, revoque sessões expiradas, e nunca confie em dados controlados pelo cliente. Teste autenticação em cada endpoint crítico.

CVE-2026-79787CRITICALAlluxio through 2.9.5 S3 REST Proxy Authentication Bypass via Unverified Request SignatureEPSS 0.5%CVE-2026-32879MEDIUMNew API has passkey-based secure step-up verification bypass for root-only channel secret disclosureEPSS 0.5%CVE-2026-44707MEDIUMChatwoot: Pre-Account Takeover via OAuth on Unconfirmed AccountsEPSS 0.5%CVE-2026-13597CRITICALQRcode Login for WeChat <= 1.3 - Unauthenticated Account TakeoverEPSS 0.5%CVE-2025-62169HIGHOctoPrint-SpoolManager Plugin APIs do not enforce authenticationEPSS 0.5%CVE-2026-93964MEDIUMNginxProxyManager nginx-proxy-manager Validate Route certificate.js internalCertificate.validate missing authenticationEPSS 0.5%CVE-2025-8546MEDIUMatjiu pybbs Verification Code login CaptchaEPSS 0.5%CVE-2026-56345CRITICALAVideo - Arbitrary User Session Hijacking via Meet Plugin uploadRecordedVideo EndpointEPSS 0.5%CVE-2021-45035MEDIUMVelneo vClient Improper authenticationEPSS 0.5%CVE-2025-5437MEDIUMMultilaser Sirius RE016 Password Change cstecgi.cgi improper authenticationEPSS 0.5%CVE-2022-35629—Velociraptor Client ID SpoofingEPSS 0.5%CVE-2025-10423MEDIUMnewbee-mall kaptcha mallKaptcha CaptchaEPSS 0.5%CVE-2021-45917HIGHSUN & MOON RISE CO., LTD. Shockwall - Improper AuthenticationEPSS 0.5%CVE-2023-47189MEDIUMWordPress Defender Security plugin <= 4.2.0 - Masked Login Area View Bypass vulnerabilityEPSS 0.5%CVE-2025-71279CRITICALXenForo Passkey Security BypassEPSS 0.5%CVE-2017-20235CRITICALProSoft Technology ICX35-HWC Authentication BypassEPSS 0.5%CVE-2025-12810MEDIUMFailure in Password Rotation and Check-in Mechanism in Secret Server Allows Reuse of CredentialsEPSS 0.5%CVE-2026-49202HIGHUnverified Meeting Recording Endpoints & Permissive CORSEPSS 0.4%CVE-2025-64175HIGHGogs Vulnerable to 2FA Bypass via Recovery CodeEPSS 0.4%CVE-2024-7870MEDIUMPixelYourSite – Your smart PIXEL (TAG) & API Manager <= 9.7.1 and PixelYourSite PRO <= 10.4.2 - Unauthenticated Information Exposure and Log DeletionEPSS 0.4%