Falhas do tipo CWE-287

2.446 resultados

Autenticação Insuficiente ou Ausente

Quando um usuário ou sistema afirma ser quem diz que é, a aplicação não valida (ou valida mal) essa identidade antes de conceder acesso. Isso permite que um atacante se passe por outra pessoa sem fornecer credenciais válidas, obtendo privilégios indevidos.

Exemplo

Um sistema que aceita login apenas verificando um campo de e-mail na sessão (sem senha), ou uma API que confia em um identificador de usuário enviado no header HTTP sem validar um token assinado. Um atacante simplesmente muda o valor e acessa dados de terceiros.

Como mitigar

Implemente autenticação robusta: exija senha forte + MFA quando possível, valide tokens com assinatura criptográfica, revoque sessões expiradas, e nunca confie em dados controlados pelo cliente. Teste autenticação em cada endpoint crítico.

CVE-2026-61225HIGHVulnerability in the Oracle Communications Converged Application Server product of Oracle Communications (component: Core). Supported versiEPSS 0.4%CVE-2026-61163HIGHVulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). TheEPSS 0.4%CVE-2026-60416HIGHVulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that EPSS 0.4%CVE-2026-4582LOWShenzhen HCC Technology MPOS M6 PLUS Bluetooth missing authenticationEPSS 0.4%CVE-2026-60558HIGHVulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are aEPSS 0.4%CVE-2026-62547HIGHVulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer). Supported versions that EPSS 0.4%CVE-2026-61137HIGHVulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version EPSS 0.4%CVE-2026-59224HIGHOpen WebUI: Terminal proxy forwards a spoofable, integrity-unbound user identity to the upstream (X-User-Id header and ws_terminal session_id query injection)EPSS 0.4%CVE-2026-33746CRITICALConvoy: JWT Signature Verification Bypass Allows Authentication as Arbitrary UsersEPSS 0.4%CVE-2025-60306CRITICALcode-projects Simple Car Rental System 1.0 has a permission bypass issue where low privilege users can forge high privilege sessions and perEPSS 0.4%CVE-2026-25937MEDIUMGLPI has a MFA bypassEPSS 0.4%CVE-2022-25685HIGHDenial of service in Modem module due to improper authorization while error handling in Snapdragon Auto, Snapdragon Compute, Snapdragon ConsEPSS 0.4%CVE-2020-7294MEDIUMWeb Gateway (MWG) - Privilege Escalation vulnerabilityEPSS 0.4%CVE-2025-54452HIGHImproper Authentication vulnerability in Samsung Electronics MagicINFO 9 Server allows Authentication Bypass.This issue affects MagicINFO 9 EPSS 0.4%CVE-2026-41896HIGHCoolify: Unauthenticated Deployment Trigger via Webhook HMAC Bypass with Null SecretEPSS 0.4%CVE-2019-13531MEDIUMMedtronic Valleylab FT10 and LS10 Improper AuthenticationEPSS 0.4%CVE-2026-32246HIGHTinyauth vulnerable to TOTP/2FA bypass via OIDC authorize endpointEPSS 0.4%CVE-2026-41720HIGHAuthentication Bypass with Empty Password in Spring LDAPEPSS 0.4%CVE-2018-1106—An authentication bypass flaw has been found in PackageKit before 1.1.10 that allows users without administrator privileges to install signeEPSS 0.4%CVE-2026-86248CRITICALApache Tomcat: Fix for CVE-2026-34500 was incomplete. OCSP checks sometimes soft-fail with FFM even when soft-fail is disabledEPSS 0.4%