Falhas do tipo CWE-287

2.461 resultados

Autenticação Insuficiente ou Ausente

Quando um usuário ou sistema afirma ser quem diz que é, a aplicação não valida (ou valida mal) essa identidade antes de conceder acesso. Isso permite que um atacante se passe por outra pessoa sem fornecer credenciais válidas, obtendo privilégios indevidos.

Exemplo

Um sistema que aceita login apenas verificando um campo de e-mail na sessão (sem senha), ou uma API que confia em um identificador de usuário enviado no header HTTP sem validar um token assinado. Um atacante simplesmente muda o valor e acessa dados de terceiros.

Como mitigar

Implemente autenticação robusta: exija senha forte + MFA quando possível, valide tokens com assinatura criptográfica, revoque sessões expiradas, e nunca confie em dados controlados pelo cliente. Teste autenticação em cada endpoint crítico.

CVE-2026-9398LOWBesen BS20 EV Charging Station BLE/WiFi authentication replayEPSS 0.4%CVE-2026-15210CRITICALLogin/Signup with Phone Number, OTP Verification < 1.8.71 - Unauthenticated Account Takeover via OTP Brute ForceEPSS 0.4%CVE-2026-16055HIGHContest Gallery < 30.0.7 - Unauthenticated Login-Protection and 2FA Bypass via post_cg_loginEPSS 0.4%CVE-2026-34727HIGHVikunja ahs a TOTP Two-Factor Authentication Bypass via OIDC Login PathEPSS 0.4%CVE-2026-49194CRITICALSCREEN_CLICK Authentication BypassEPSS 0.4%CVE-2022-48294HIGHThe IHwAttestationService interface has a defect in authentication. Successful exploitation of this vulnerability may affect data confidentiEPSS 0.4%CVE-2026-19971MEDIUMLB-Link WR1210M Backup Endpoint backup.cgi main missing authenticationEPSS 0.4%CVE-2020-8097HIGHImproper authentication vulnerability in Bitdefender Endpoint Security Tools and Endpoint Security SDK (VA-8646)EPSS 0.4%CVE-2026-1305MEDIUMJapanized for WooCommerce <= 2.8.4 - Missing Authorization to Unauthenticated Paidy Order ManipulationEPSS 0.4%CVE-2026-93984MEDIUMOpenPanel API Authentication Bypass via Unverified Client SecretEPSS 0.4%CVE-2026-12877CRITICALSoftware Issue Manager < 5.1.0 - Unauthenticated SQL Injection via Search ParameterEPSS 0.4%CVE-2025-67822CRITICALA vulnerability in the Provisioning Manager component of Mitel MiVoice MX-ONE 7.3 (7.3.0.0.50) through 7.8 SP1 (7.8.1.0.14) could allow an uEPSS 0.4%CVE-2025-46630MEDIUMImproper access controls in the web management portal of the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated remote attacker to enable 'EPSS 0.4%CVE-2026-60327HIGHVulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that EPSS 0.4%CVE-2026-57134HIGHPraisonAI MCPSecurity Basic/OAuth authentication policies accept invalid credentials without validationEPSS 0.4%CVE-2025-53889MEDIUMDirectus missing permission checks for manual trigger FlowsEPSS 0.4%CVE-2026-11345MEDIUMImproper Authentication Bypass in linqi CDN File AccessEPSS 0.4%CVE-2026-18074HIGHIBM Financial Transaction Manager (FTM) is Impacted by Multiple VulnerabilitiesEPSS 0.4%CVE-2025-70833CRITICALAn Authentication Bypass vulnerability in Smanga 3.2.7 allows an unauthenticated attacker to reset the password of any user (including the aEPSS 0.4%CVE-2022-47976HIGHThe DMSDP module of the distributed hardware has a vulnerability that may cause imposter control connections.Successful exploitation of thisEPSS 0.4%