Falhas do tipo CWE-287

2.459 resultados

Autenticação Insuficiente ou Ausente

Quando um usuário ou sistema afirma ser quem diz que é, a aplicação não valida (ou valida mal) essa identidade antes de conceder acesso. Isso permite que um atacante se passe por outra pessoa sem fornecer credenciais válidas, obtendo privilégios indevidos.

Exemplo

Um sistema que aceita login apenas verificando um campo de e-mail na sessão (sem senha), ou uma API que confia em um identificador de usuário enviado no header HTTP sem validar um token assinado. Um atacante simplesmente muda o valor e acessa dados de terceiros.

Como mitigar

Implemente autenticação robusta: exija senha forte + MFA quando possível, valide tokens com assinatura criptográfica, revoque sessões expiradas, e nunca confie em dados controlados pelo cliente. Teste autenticação em cada endpoint crítico.

CVE-2025-37107HIGHAn authentication bypass vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.18.EPSS 0.4%CVE-2025-6926HIGHSecurity Authentication Bypass in CentralAuthEPSS 0.4%CVE-2020-3216MEDIUMCisco IOS XE SD-WAN Software Authentication Bypass VulnerabilityEPSS 0.4%CVE-2026-85596HIGHTraefik v3.7 Authentication Bypass via TLS Option ConflictEPSS 0.4%CVE-2026-33124HIGHFrigate has insecure password change functionalityEPSS 0.4%CVE-2026-45690MEDIUMNextcloud: Two-Factor Authentication Bypass via Pending Session Token ReplayEPSS 0.4%CVE-2025-11625CRITICALHost verification bypass and credential leakEPSS 0.4%CVE-2026-55672HIGHZITADEL: Missing client_id binding in OIDC authorization code exchange and refresh token flows (RFC 6749 Section 4.1.3 violation)EPSS 0.4%CVE-2026-45691MEDIUMNextcloud: Bypass of second factor authentication on DAV endpointsEPSS 0.4%CVE-2026-27856HIGHDoveadm credentials are verified using direct comparison which is susceptible to timing oracle attack. An attacker can use this to determineEPSS 0.4%CVE-2024-22395MEDIUMImproper access control vulnerability has been identified in the SMA100 SSL-VPN virtual office portal, which in specific conditions could poEPSS 0.4%CVE-2026-27611HIGHFileBrowser Quantum: Password Protection Not Enforced on Shared File LinksEPSS 0.4%CVE-2026-61149HIGHVulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience MaEPSS 0.4%CVE-2026-46937HIGHVulnerability in the Oracle iSetup product of Oracle E-Business Suite (component: General Ledger Update Transform, Reports). Supported versEPSS 0.4%CVE-2026-61168HIGHVulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security). The supported version that is affected is 9.3.EPSS 0.4%CVE-2026-61010HIGHVulnerability in the Oracle Process Manufacturing Systems product of Oracle E-Business Suite (component: Internal Operations). Supported veEPSS 0.4%CVE-2026-60863HIGHVulnerability in the Oracle Advanced Pricing product of Oracle E-Business Suite (component: Pricing Installation). Supported versions that EPSS 0.4%CVE-2026-62534HIGHVulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Web Utilities). Supported versions that aEPSS 0.4%CVE-2026-60898HIGHVulnerability in the Oracle Warehouse Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions thEPSS 0.4%CVE-2026-60423HIGHVulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affectEPSS 0.4%