Falhas do tipo CWE-287

2.457 resultados

Autenticação Insuficiente ou Ausente

Quando um usuário ou sistema afirma ser quem diz que é, a aplicação não valida (ou valida mal) essa identidade antes de conceder acesso. Isso permite que um atacante se passe por outra pessoa sem fornecer credenciais válidas, obtendo privilégios indevidos.

Exemplo

Um sistema que aceita login apenas verificando um campo de e-mail na sessão (sem senha), ou uma API que confia em um identificador de usuário enviado no header HTTP sem validar um token assinado. Um atacante simplesmente muda o valor e acessa dados de terceiros.

Como mitigar

Implemente autenticação robusta: exija senha forte + MFA quando possível, valide tokens com assinatura criptográfica, revoque sessões expiradas, e nunca confie em dados controlados pelo cliente. Teste autenticação em cada endpoint crítico.

CVE-2025-64175HIGHGogs Vulnerable to 2FA Bypass via Recovery CodeEPSS 0.4%CVE-2026-21633HIGHA malicious actor with access to the adjacent network could obtain unauthorized access to a UniFi Protect Camera by exploiting a discovery pEPSS 0.4%CVE-2026-56219HIGHCapgo - Unauthenticated RBAC Bindings and Email Disclosure via get_org_user_access_rbac NULL-auth BypassEPSS 0.4%CVE-2023-46630HIGHWordPress Admin and Site Enhancements (ASE) plugin <= 5.7.1 - Password Protected View Bypass Vulnerability vulnerabilityEPSS 0.4%CVE-2026-13447CRITICALMStore API <= 4.20.0 - Unauthenticated Authentication Bypass via 'id_token' Parameter JWT ForgeryEPSS 0.4%CVE-2026-41081MEDIUMApache Storm Client: Anonymous principal assigned on TLS client certificate verification failureEPSS 0.4%CVE-2026-33665HIGHn8n: LDAP Email-Based Account Linking Allows Privilege Escalation and Account TakeoverEPSS 0.4%CVE-2026-40177CRITICALPassword bypass when 2FA is activatedEPSS 0.4%CVE-2021-41503HIGHDCS-5000L v1.05 and DCS-932L v2.17 and older are affecged by Incorrect Acess Control. The use of the basic authentication for the devices coEPSS 0.4%CVE-2026-45754MEDIUMSymfony: Mailjet Mailer Webhook Parser Never Verifies the Configured Secret — Unauthenticated Webhook Event InjectionEPSS 0.4%CVE-2026-52845HIGHCaddy: FastCGI header normalization bypass in `forward_auth copy_headers`EPSS 0.4%CVE-2025-15456MEDIUMbg5sbk MiniCMS Publish page-edit.php improper authenticationEPSS 0.4%CVE-2023-47256MEDIUMConnectWise ScreenConnect through 23.8.4 allows local users to connect to arbitrary relay servers via implicit trust of proxy settingsEPSS 0.4%CVE-2026-12359HIGHSecurity vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify AccessEPSS 0.4%CVE-2024-5012HIGHWhatsUp Gold Missing Authentication GetWindowsCredential Information Disclosure VulnerabilityEPSS 0.4%CVE-2023-50127MEDIUMHozard alarm system (Alarmsysteem) v1.0 is vulnerable to Improper Authentication. Commands sent via the SMS functionality are accepted from EPSS 0.4%CVE-2025-37106HIGHAn authentication bypass and disclosure of information vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.18.EPSS 0.4%CVE-2025-30114CRITICALAn issue was discovered on the Forvia Hella HELLA Driving Recorder DR 820. Bypassing of Device Pairing can occur. The pairing mechanism reliEPSS 0.4%CVE-2025-3910MEDIUMOrg.keycloak.authentication: two factor authentication bypassEPSS 0.4%CVE-2022-3119HIGHOAuth client Single Sign On for WordPress < 3.0.4 - Unauthenticated Settings Update to Authentication BypassEPSS 0.4%