Falhas do tipo CWE-287

2.461 resultados

Autenticação Insuficiente ou Ausente

Quando um usuário ou sistema afirma ser quem diz que é, a aplicação não valida (ou valida mal) essa identidade antes de conceder acesso. Isso permite que um atacante se passe por outra pessoa sem fornecer credenciais válidas, obtendo privilégios indevidos.

Exemplo

Um sistema que aceita login apenas verificando um campo de e-mail na sessão (sem senha), ou uma API que confia em um identificador de usuário enviado no header HTTP sem validar um token assinado. Um atacante simplesmente muda o valor e acessa dados de terceiros.

Como mitigar

Implemente autenticação robusta: exija senha forte + MFA quando possível, valide tokens com assinatura criptográfica, revoque sessões expiradas, e nunca confie em dados controlados pelo cliente. Teste autenticação em cada endpoint crítico.

CVE-2026-44961NONEThe XML‑RPC API addUser method has a validation bypass introduced in the fix for CVE‑2025‑55129. As a result, API users could create usernamEPSS 0.4%CVE-2026-13690HIGHUsersWP < 1.2.67 - Two-Factor Authentication BypassEPSS 0.4%CVE-2026-10281MEDIUMEnderfga claw-orchestrator API Endpoint embedded-server.ts EmbeddedServer missing authenticationEPSS 0.4%CVE-2026-4583LOWShenzhen HCC Technology MPOS M6 PLUS Bluetooth authentication replayEPSS 0.4%CVE-2021-22943—A vulnerability found in UniFi Protect application V1.18.1 and earlier permits a malicious actor who has already gained access to a network EPSS 0.4%CVE-2026-2756LOWOmniPEMF NeoRhythm BLE missing authenticationEPSS 0.4%CVE-2026-75807HIGHSAML Single Sign On <= 5.4.6 - Unauthenticated Authentication Bypass via X.509 Certificate PoisoningEPSS 0.4%CVE-2024-35670MEDIUMWordPress Integrate Google Drive plugin <= 1.3.93 - Broken Access Control vulnerabilityEPSS 0.4%CVE-2025-27086HIGHA vulnerability in the HPE Performance Cluster Manager (HPCM) GUI could allow an attacker to bypass authentication.EPSS 0.4%CVE-2025-5597CRITICALWF Steuerungstechnik GmbH - airleader MASTER - Authentication BypassEPSS 0.4%CVE-2022-39018HIGHBroken access controls on PDFtron data in M-Files HubshareEPSS 0.4%CVE-2026-85716LOWAsyncHttpClient: SCRAM and Digest mutual-authentication responses are not verifiedEPSS 0.4%CVE-2026-10167MEDIUMOUSL-GROUP-BrinaryBrains School Student Management System MY_Controller Login.php sign_auth_cookie improper authenticationEPSS 0.4%CVE-2026-14596HIGHDynamicKit for Elementor < 1.0.3 - Unauthenticated Account Takeover via Password Reset Link Host InjectionEPSS 0.4%CVE-2026-28428MEDIUMTalishar: Authentication Bypass via Empty authKey Parameter Allows Unauthenticated Game ActionsEPSS 0.4%CVE-2026-40946CRITICALOxia: OIDC token audience validation bypass via SkipClientIDCheckEPSS 0.4%CVE-2026-77826HIGHRegistrationMagic 5.0.1.8 - 6.0.9.8 - Unauthenticated Authentication Bypass via Missing Facebook Token Audience ValidationEPSS 0.4%CVE-2025-30214HIGHFrappe vulnerable to information disclosure leading to account takeoverEPSS 0.4%CVE-2026-55689MEDIUMOpenFGA: OIDC audience validation skipped when --authn-oidc-audience is unsetEPSS 0.4%CVE-2025-14738MEDIUMConfiguration Disclosure Vulnerability in TP-Link WA850REEPSS 0.4%