Falhas do tipo CWE-287

2.461 resultados

Autenticação Insuficiente ou Ausente

Quando um usuário ou sistema afirma ser quem diz que é, a aplicação não valida (ou valida mal) essa identidade antes de conceder acesso. Isso permite que um atacante se passe por outra pessoa sem fornecer credenciais válidas, obtendo privilégios indevidos.

Exemplo

Um sistema que aceita login apenas verificando um campo de e-mail na sessão (sem senha), ou uma API que confia em um identificador de usuário enviado no header HTTP sem validar um token assinado. Um atacante simplesmente muda o valor e acessa dados de terceiros.

Como mitigar

Implemente autenticação robusta: exija senha forte + MFA quando possível, valide tokens com assinatura criptográfica, revoque sessões expiradas, e nunca confie em dados controlados pelo cliente. Teste autenticação em cada endpoint crítico.

CVE-2026-9830HIGHBookingPress Pro < 5.7.3 - Unauthenticated Customer PII Disclosure and Booking Tampering via Permission Callback BugEPSS 0.4%CVE-2026-41671MEDIUMAdmidio: OIDC Token Introspection Endpoint Returns Active for All Tokens Without ValidationEPSS 0.4%CVE-2026-16036HIGHminiOrange 2FA < 6.2.7 - 2FA Bypass via Password-Only Second-Factor RebindingEPSS 0.4%CVE-2026-17000HIGHVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.4%CVE-2026-87176CRITICALVulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is EPSS 0.4%CVE-2026-83201CRITICALVulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affEPSS 0.4%CVE-2025-27422HIGHFACTION Allows Authentication Bypass via User CreationEPSS 0.4%CVE-2022-39892LOWImproper access control in Samsung Pass prior to version 4.0.05.1 allows attackers to unauthenticated access via keep open feature.EPSS 0.4%CVE-2026-87217CRITICALVulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is EPSS 0.4%CVE-2026-83202CRITICALVulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affEPSS 0.4%CVE-2026-73944CRITICALVulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that EPSS 0.4%CVE-2026-73952CRITICALVulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Portlet Services). Supported versions that areEPSS 0.4%CVE-2026-83154CRITICALVulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: Open UI). Supported versions that are affected are 17.0-2EPSS 0.4%CVE-2026-83104CRITICALVulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). Supported versions that aEPSS 0.4%CVE-2026-87129CRITICALVulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supportEPSS 0.4%CVE-2026-87173CRITICALVulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is EPSS 0.4%CVE-2026-60326CRITICALVulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that EPSS 0.4%CVE-2026-87170CRITICALVulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is EPSS 0.4%CVE-2026-87128CRITICALVulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supportEPSS 0.4%CVE-2026-0629HIGHAuthentication Bypass in Password Recovery Feature via Local Web App on Multiple VIGI CamerasEPSS 0.4%