Falhas do tipo CWE-287

2.449 resultados

Autenticação Insuficiente ou Ausente

Quando um usuário ou sistema afirma ser quem diz que é, a aplicação não valida (ou valida mal) essa identidade antes de conceder acesso. Isso permite que um atacante se passe por outra pessoa sem fornecer credenciais válidas, obtendo privilégios indevidos.

Exemplo

Um sistema que aceita login apenas verificando um campo de e-mail na sessão (sem senha), ou uma API que confia em um identificador de usuário enviado no header HTTP sem validar um token assinado. Um atacante simplesmente muda o valor e acessa dados de terceiros.

Como mitigar

Implemente autenticação robusta: exija senha forte + MFA quando possível, valide tokens com assinatura criptográfica, revoque sessões expiradas, e nunca confie em dados controlados pelo cliente. Teste autenticação em cada endpoint crítico.

CVE-2026-80192HIGHbetter-auth SSO before 1.6.27 Domain Ownership Authentication BypassEPSS 0.4%CVE-2026-44547CRITICALChurchCRM: Incomplete fix for CVE-2026-40582: public API login still bypasses 2FA and account lockout in ChurchCRM 7.2.2EPSS 0.4%CVE-2022-20662MEDIUMCisco Duo for macOS Authentication Bypass VulnerabilityEPSS 0.4%CVE-2026-16269MEDIUMNewsletters < 4.16 - Unauthenticated API Authentication Bypass via Type JugglingEPSS 0.4%CVE-2026-48896HIGHJoomla! Core - [20260511] - MFA Authentication BypassEPSS 0.4%CVE-2024-6107CRITICALDue to insufficient verification, an attacker could use a malicious client to bypass authentication checks and run RPC commands in a region.EPSS 0.4%CVE-2026-46705MEDIUMrussh server userauth state is not reset when authentication principal changesEPSS 0.4%CVE-2025-69822HIGHAn issue in Atomberg Atomberg Erica Smart Fan Firmware Version: V1.0.36 allows an attacker to obtain sensitive information and escalate privEPSS 0.4%CVE-2026-45283MEDIUMNextcloud: Files Lock app allows users to lock and unlock files of other usersEPSS 0.4%CVE-2024-5174MEDIUMBroken Authentication in GliffyEPSS 0.4%CVE-2023-33054CRITICALImproper Authentication in GPS HLOS DriverEPSS 0.4%CVE-2025-69197MEDIUMPterodactyl TOTPs can be reused during validity windowEPSS 0.4%CVE-2026-16257HIGHArvow AI SEO Writer < 1.5.4 - Unauthenticated Arbitrary Post Creation via Webhook Secret Type-JugglingEPSS 0.4%CVE-2025-25504MEDIUMAn issue in the /usr/local/bin/jncs.sh script of Gefen WebFWC (In AV over IP products) v1.85h, v1.86v, and v1.70 allows attackers with netwoEPSS 0.4%CVE-2025-45583CRITICALIncorrect access control in the FTP protocol of Audi UTR 2.0 Universal Traffic Recorder 2.0 allows attackers to authenticate into the servicEPSS 0.4%CVE-2026-11703MEDIUMMissing SNI/ALPN binding on stateful (session-ID) TLS session resumptionEPSS 0.4%CVE-2026-14830HIGHFlxWoo < 3.1.1 - Unauthenticated Payment BypassEPSS 0.4%CVE-2025-46573HIGHpassport-wsfed-saml2 Has SAML Authentication Bypass via Attribute SmugglingEPSS 0.4%CVE-2023-25556HIGH A CWE-287: Improper Authentication vulnerability exists that could allow a device to be compromised when a key of less than seven digits isEPSS 0.4%CVE-2022-32935MEDIUMA lock screen issue was addressed with improved state management. This issue is fixed in iOS 15.7.1 and iPadOS 15.7.1, iOS 16.1 and iPadOS 1EPSS 0.4%