Falhas do tipo CWE-287

2.446 resultados

Autenticação Insuficiente ou Ausente

Quando um usuário ou sistema afirma ser quem diz que é, a aplicação não valida (ou valida mal) essa identidade antes de conceder acesso. Isso permite que um atacante se passe por outra pessoa sem fornecer credenciais válidas, obtendo privilégios indevidos.

Exemplo

Um sistema que aceita login apenas verificando um campo de e-mail na sessão (sem senha), ou uma API que confia em um identificador de usuário enviado no header HTTP sem validar um token assinado. Um atacante simplesmente muda o valor e acessa dados de terceiros.

Como mitigar

Implemente autenticação robusta: exija senha forte + MFA quando possível, valide tokens com assinatura criptográfica, revoque sessões expiradas, e nunca confie em dados controlados pelo cliente. Teste autenticação em cada endpoint crítico.

CVE-2025-70841CRITICALDokans Multi-Tenancy Based eCommerce Platform SaaS 3.9.2 allows unauthenticated remote attackers to obtain sensitive application configuratiEPSS 0.4%CVE-2025-30168MEDIUMParse Server has an OAuth login vulnerabilityEPSS 0.4%CVE-2025-62717LOWEmlog Pro session verification code error due to clearing logic errorEPSS 0.4%CVE-2025-14942CRITICALAuthentication BypassEPSS 0.4%CVE-2025-46630MEDIUMImproper access controls in the web management portal of the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated remote attacker to enable 'EPSS 0.4%CVE-2025-30733MEDIUMVulnerability in the RDBMS Listener component of Oracle Database Server. Supported versions that are affected are 19.3-19.26, 21.3-21.17 anEPSS 0.4%CVE-2026-53958HIGH4gaBoards: SSO Pre-Account Takeover / Hijacking via Mass AssignmentEPSS 0.4%CVE-2026-19806HIGHSupport Genix <= 1.4.52 - Authenticated (Subscriber+) Authentication Bypass to Administrator Account Takeover via 'p' Parameter Forged Guest TokenEPSS 0.4%CVE-2026-12196HIGHHestiaCP Admin TakeoverEPSS 0.4%CVE-2026-12341HIGHSailPoint IdentityIQ Improper Bearer Token Validation VulnerabilityEPSS 0.4%CVE-2023-52540HIGHVulnerability of improper authentication in the Iaware module. Impact: Successful exploitation of this vulnerability will affect availabilitEPSS 0.4%CVE-2026-39976HIGHLaravel Passport's TokenGuard Authenticates Unrelated User for Client Credentials TokensEPSS 0.4%CVE-2026-40910MEDIUMfrp: Authentication bypass in frp HTTP vhost routing when routeByHTTPUser is used for access controlEPSS 0.4%CVE-2022-41738HIGHIBM Spectrum Scale security bypassEPSS 0.4%CVE-2025-25227HIGH[20250402] - Joomla Core - MFA Authentication BypassEPSS 0.4%CVE-2018-10597—IntelliVue Patient Monitors MP Series (including MP2/X2/MP30/MP50/MP70/NP90/MX700/800) Rev B-M, IntelliVue Patient Monitors MX (MX400-550) REPSS 0.4%CVE-2022-39019MEDIUMBroken access controls on PDFtron WebviewerUI in M-Files HubshareEPSS 0.4%CVE-2026-8293HIGHReally Simple Security < 9.5.10.1 - Authentication Bypass via Two-Factor OTP SkipEPSS 0.4%CVE-2024-42172MEDIUMHCL MyXalytics is affected by broken authenticationEPSS 0.4%CVE-2026-61225HIGHVulnerability in the Oracle Communications Converged Application Server product of Oracle Communications (component: Core). Supported versiEPSS 0.4%