Falhas do tipo CWE-287

2.449 resultados

Autenticação Insuficiente ou Ausente

Quando um usuário ou sistema afirma ser quem diz que é, a aplicação não valida (ou valida mal) essa identidade antes de conceder acesso. Isso permite que um atacante se passe por outra pessoa sem fornecer credenciais válidas, obtendo privilégios indevidos.

Exemplo

Um sistema que aceita login apenas verificando um campo de e-mail na sessão (sem senha), ou uma API que confia em um identificador de usuário enviado no header HTTP sem validar um token assinado. Um atacante simplesmente muda o valor e acessa dados de terceiros.

Como mitigar

Implemente autenticação robusta: exija senha forte + MFA quando possível, valide tokens com assinatura criptográfica, revoque sessões expiradas, e nunca confie em dados controlados pelo cliente. Teste autenticação em cada endpoint crítico.

CVE-2024-30939MEDIUMAn issue discovered in Yealink VP59 Teams Editions with firmware version 91.15.0.118 allows a physically proximate attacker to gain control EPSS 0.4%CVE-2022-29083MEDIUMPrior Dell BIOS versions contain an Improper Authentication vulnerability. An unauthenticated attacker with physical access to the system coEPSS 0.4%CVE-2024-45051HIGHBypass of email address validation via encoded email addresses in DiscourseEPSS 0.4%CVE-2026-16972MEDIUMVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.4%CVE-2024-2244MEDIUMREST service authentication anomaly with “valid username/no password” credential combination for batch job processing resulting in successfuEPSS 0.4%CVE-2026-26128HIGHWindows SMB Server Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2026-48780HIGHForem vulnerable to bypass of email address domain restrictionsEPSS 0.4%CVE-2026-46355HIGHBigBlueButton: Unauthenticated Session Hijack via Exposed /bigbluebutton/api/handleJoinExistingUserEPSS 0.4%CVE-2022-3156HIGHRockwell Automation Studio 5000 Logix Emulate Vulnerable to a Remote Code Execution VulnerabilityEPSS 0.4%CVE-2025-46607MEDIUMDell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 8.4 through 8.5 contain an improper authEPSS 0.4%CVE-2022-43528MEDIUMUnder certain configurations, an attacker can login to Aruba EdgeConnect Enterprise Orchestrator without supplying a multi-factor authenticaEPSS 0.4%CVE-2026-58253HIGHNATS Server: Route API Auth BypassEPSS 0.4%CVE-2025-54419CRITICALNode-SAML Contains SAML Signature Verification VulnerabilityEPSS 0.4%CVE-2022-35646MEDIUMIBM Security Verify Governance, Identity Manager security bypassEPSS 0.4%CVE-2026-0405MEDIUMAuthentication Bypass in NETGEAR Orbi DevicesEPSS 0.4%CVE-2026-55235MEDIUMlanggraph-api: Relative webhook targets in LangGraph Server can reach in-process routes without authenticationEPSS 0.4%CVE-2017-14018—An improper authentication issue was discovered in Johnson & Johnson Ethicon Endo-Surgery Generator Gen11, all versions released before NoveEPSS 0.4%CVE-2026-78425HIGHSAML Audience Confusion Allows Cross-SP AuthenticationEPSS 0.4%CVE-2026-45363CRITICAL`jwt` (Ruby gem) - empty-key HMAC bypassEPSS 0.4%CVE-2026-48897HIGHJoomla! Core - [20260512] - MFA Authentication BypassEPSS 0.4%