Falhas do tipo CWE-287

2.461 resultados

Autenticação Insuficiente ou Ausente

Quando um usuário ou sistema afirma ser quem diz que é, a aplicação não valida (ou valida mal) essa identidade antes de conceder acesso. Isso permite que um atacante se passe por outra pessoa sem fornecer credenciais válidas, obtendo privilégios indevidos.

Exemplo

Um sistema que aceita login apenas verificando um campo de e-mail na sessão (sem senha), ou uma API que confia em um identificador de usuário enviado no header HTTP sem validar um token assinado. Um atacante simplesmente muda o valor e acessa dados de terceiros.

Como mitigar

Implemente autenticação robusta: exija senha forte + MFA quando possível, valide tokens com assinatura criptográfica, revoque sessões expiradas, e nunca confie em dados controlados pelo cliente. Teste autenticação em cada endpoint crítico.

CVE-2026-83202CRITICALVulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affEPSS 0.4%CVE-2022-39892LOWImproper access control in Samsung Pass prior to version 4.0.05.1 allows attackers to unauthenticated access via keep open feature.EPSS 0.4%CVE-2026-34834HIGHBulwark Webmail: Authentication Bypass in verifyIdentity() due to missing cookie validationEPSS 0.4%CVE-2026-27134HIGHStrimzi: All CAs from a custom CA chain consisting of multiple CAs are trusted for mTLS user autenticationEPSS 0.4%CVE-2025-55293CRITICALMeshtastic allows crafting of specific NodeInfo packets that overwrite any publicKey saved in the NodeDBEPSS 0.4%CVE-2024-57490HIGHGuangzhou Hongfan Technology Co., LTD. iOffice20 has any user login vulnerability. An attacker can log in to any system account including thEPSS 0.4%CVE-2026-39322CRITICALPolarLearn: Any password authenticates banned accounts and grants API accessEPSS 0.4%CVE-2024-44821MEDIUMZZCMS 2023 contains a vulnerability in the captcha reuse logic located in /inc/function.php. The checkyzm function does not properly refreshEPSS 0.4%CVE-2026-71277CRITICALrust-iot-platform Authentication Bypass via Non-Validated Authorization HeaderEPSS 0.4%CVE-2026-34873CRITICALAn issue was discovered in Mbed TLS 3.5.0 through 4.0.0. Client impersonation can occur while resuming a TLS 1.3 session.EPSS 0.4%CVE-2023-31279HIGHImproper AuthenticationEPSS 0.4%CVE-2026-46485HIGHDash: Users can write to config despire permissions (OIDC tested)EPSS 0.4%CVE-2024-3487LOWBroken Authentication vulnerability in iManagerEPSS 0.4%CVE-2026-10157MEDIUMOpen5GS NGAP PathSwitchRequest Message ngap-handler.c improper authenticationEPSS 0.4%CVE-2026-58075HIGHA vulnerability allowing an unauthenticated attacker to read arbitrary files from the host, which can be further leveraged toescalate privilEPSS 0.4%CVE-2024-37233MEDIUMWordPress Play.ht plugin <= 3.6.4 - Broken Access Control vulnerabilityEPSS 0.4%CVE-2022-46313MEDIUMThe sensor privacy module has an authentication vulnerability. Successful exploitation of this vulnerability may cause unavailability of theEPSS 0.4%CVE-2026-83961HIGHColdFusion | Improper Authentication (CWE-287)EPSS 0.4%CVE-2026-15210CRITICALLogin/Signup with Phone Number, OTP Verification < 1.8.71 - Unauthenticated Account Takeover via OTP Brute ForceEPSS 0.4%CVE-2026-19714CRITICALSimple JWT Login < 3.6.8 - Unauthenticated Account Takeover via Missing Google id_token Audience ValidationEPSS 0.4%