Falhas do tipo CWE-287

2.446 resultados

Autenticação Insuficiente ou Ausente

Quando um usuário ou sistema afirma ser quem diz que é, a aplicação não valida (ou valida mal) essa identidade antes de conceder acesso. Isso permite que um atacante se passe por outra pessoa sem fornecer credenciais válidas, obtendo privilégios indevidos.

Exemplo

Um sistema que aceita login apenas verificando um campo de e-mail na sessão (sem senha), ou uma API que confia em um identificador de usuário enviado no header HTTP sem validar um token assinado. Um atacante simplesmente muda o valor e acessa dados de terceiros.

Como mitigar

Implemente autenticação robusta: exija senha forte + MFA quando possível, valide tokens com assinatura criptográfica, revoque sessões expiradas, e nunca confie em dados controlados pelo cliente. Teste autenticação em cada endpoint crítico.

CVE-2023-48747MEDIUMWordPress Booster for WooCommerce plugin <= 7.1.2 - Authenticated Production Creation/Modification VulnerabilityEPSS 0.4%CVE-2026-10777MEDIUMealpha072 Student-Management-System Administrative Backend config.php improper authenticationEPSS 0.4%CVE-2026-15089CRITICALCommerce guest registration - Critical - Unsupported - SA-CONTRIB-2026-079EPSS 0.4%CVE-2026-18215MEDIUMKeycloak-services: keycloak-services: microsoft external access-token exchange bypasses configured tenantEPSS 0.4%CVE-2026-4476MEDIUMYi Technology YI Home Camera CGI Endpoint ipc missing authenticationEPSS 0.4%CVE-2026-45567HIGHRoxy-WI: Authentication bypass via 'api' substring in URL + unauthenticated /api/gptEPSS 0.4%CVE-2023-21455MEDIUMImproper authorization implementation in Exynos baseband prior to SMR Mar-2023 Release 1 allows incorrect handling of unencrypted message.EPSS 0.4%CVE-2018-16877HIGHA flaw was found in the way pacemaker's client-server authentication was implemented in versions up to and including 2.0.0. A local attackerEPSS 0.4%CVE-2025-58065MEDIUMFlask App Builder has an Authentication Bypass vulnerability when using non AUTH_DB methodsEPSS 0.4%CVE-2025-31271HIGHThis issue was addressed through improved state management. This issue is fixed in macOS Tahoe 26. Incoming FaceTime calls can appear or be EPSS 0.4%CVE-2023-38367MEDIUMIBM Cloud Pak for Automation authentication bypassEPSS 0.4%CVE-2026-56223CRITICALCapgo - Account Takeover via Cross-Domain SSO Email Assertion in provision-userEPSS 0.4%CVE-2024-42336HIGHServision - CWE-287: Improper AuthenticationEPSS 0.4%CVE-2026-8185MEDIUMUGREEN CM933 Administrative missing authenticationEPSS 0.4%CVE-2024-37313HIGHNextcloud server allows the by-pass the second factorEPSS 0.4%CVE-2026-28471MEDIUMOpenClaw 2026.1.14-1 < 2026.2.2 - Allowlist Bypass via displayName and Cross-Homeserver localpart Matching in Matrix PluginEPSS 0.4%CVE-2026-11618MEDIUMDTStack Taier Source Connection Test Endpoint LoginInterceptor.java preHandle improper authenticationEPSS 0.4%CVE-2025-68640MEDIUMThe Apple Find My backend service through 2025-12-17 allows an attacker in possession of a valid PET (Private Endpoint Token) to enumerate dEPSS 0.4%CVE-2026-56737HIGHphpMyFAQ's two-factor authentication login bypasses the password factorEPSS 0.4%CVE-2026-10617MEDIUMnextlevelbuilder GoClaw Webhook Verification auth.go resolveAuth missing authenticationEPSS 0.4%