Falhas do tipo CWE-287

2.449 resultados

Autenticação Insuficiente ou Ausente

Quando um usuário ou sistema afirma ser quem diz que é, a aplicação não valida (ou valida mal) essa identidade antes de conceder acesso. Isso permite que um atacante se passe por outra pessoa sem fornecer credenciais válidas, obtendo privilégios indevidos.

Exemplo

Um sistema que aceita login apenas verificando um campo de e-mail na sessão (sem senha), ou uma API que confia em um identificador de usuário enviado no header HTTP sem validar um token assinado. Um atacante simplesmente muda o valor e acessa dados de terceiros.

Como mitigar

Implemente autenticação robusta: exija senha forte + MFA quando possível, valide tokens com assinatura criptográfica, revoque sessões expiradas, e nunca confie em dados controlados pelo cliente. Teste autenticação em cada endpoint crítico.

CVE-2026-28606CRITICALIn handleBondStateChanged of AdapterService.java, there is a possible way to skip pairing due to a logic error in the code. This could lead EPSS 0.4%CVE-2025-9063HIGHRockwell Automation PanelView Plus 7 Performance Series B Authentication BypassEPSS 0.4%CVE-2026-49447MEDIUMCosmos-Server's constellation public-devices endpoint accepts arbitrary bearer tokensEPSS 0.4%CVE-2025-51451CRITICALIn TOTOLINK EX1200T firmware 4.1.2cu.5215, an attacker can bypass login by sending a specific request through formLoginAuth.htm.EPSS 0.4%CVE-2026-14836HIGHLogin/Signup Popup < 3.2.5 - Unauthenticated Account Takeover via Password Reset Rate Limit BypassEPSS 0.4%CVE-2026-12281HIGHShibboleth < 2.5.4 - Unauthenticated Administrator Account Creation via Identity Header SpoofingEPSS 0.4%CVE-2026-18469HIGHLogin & Register Forms < 4.0.2 - Unauthenticated Account Takeover via Password Reset Code Brute ForceEPSS 0.4%CVE-2026-14309HIGHChat On Desk < 1.0.9 - Unauthenticated Account Takeover via Password Reset OTP BypassEPSS 0.4%CVE-2026-16030HIGHMStore API < 4.21.0 - Unauthenticated Account Takeover via Firebase Phone AuthenticationEPSS 0.4%CVE-2026-97231MEDIUMvolotat Anagnorisis Socket.IO Connect app.py missing authenticationEPSS 0.4%CVE-2026-76688HIGHAuthentication Bypass Vulnerabilities in the Web-Based Management Interface of EdgeConnect SD-WAN OrchestratorEPSS 0.4%CVE-2026-1743LOWDJI Mavic Mini/Air/Spark/Mini SE Enhanced Wi-Fi Pairing authentication replayEPSS 0.4%CVE-2026-82183HIGHOAuth Single Sign On 6.25.0 - 7.0.0 - Unauthenticated Account Takeover via Unverified Steam OpenID AssertionEPSS 0.4%CVE-2026-14300HIGHminiOrange Social Login and Register < 7.8.0 - Unauthenticated Account TakeoverEPSS 0.4%CVE-2026-12585HIGHAbandoned Cart Lite for WooCommerce < 6.8.2 - Unauthenticated Account Takeover via Malleable Recovery-Link TokenEPSS 0.4%CVE-2026-18468HIGHLogin & Register Forms < 4.0.2 - Unauthenticated Account Takeover via Password Reset Verification State Keyed on a Client-Supplied Address HeaderEPSS 0.4%CVE-2026-58066CRITICALRocket.Chat's SAML SSO before versions 8.7.0, 8.6.1, 8.5.2, 8.4.5, 8.3.7, 8.2.7, 8.1.7, 8.0.8, and 7.10.14 verified XML signatures but did nEPSS 0.4%CVE-2025-21618HIGHNiceGUI On Air authentication issueEPSS 0.4%CVE-2026-28787HIGHOneUptime has WebAuthn 2FA bypass: server accepts client-supplied challenge instead of server-stored value, allowing credential replayEPSS 0.4%CVE-2026-0842MEDIUMFlycatcher Toys smART Sketcher Bluetooth Low Energy missing authenticationEPSS 0.4%