Falhas do tipo CWE-287

2.450 resultados

Autenticação Insuficiente ou Ausente

Quando um usuário ou sistema afirma ser quem diz que é, a aplicação não valida (ou valida mal) essa identidade antes de conceder acesso. Isso permite que um atacante se passe por outra pessoa sem fornecer credenciais válidas, obtendo privilégios indevidos.

Exemplo

Um sistema que aceita login apenas verificando um campo de e-mail na sessão (sem senha), ou uma API que confia em um identificador de usuário enviado no header HTTP sem validar um token assinado. Um atacante simplesmente muda o valor e acessa dados de terceiros.

Como mitigar

Implemente autenticação robusta: exija senha forte + MFA quando possível, valide tokens com assinatura criptográfica, revoque sessões expiradas, e nunca confie em dados controlados pelo cliente. Teste autenticação em cada endpoint crítico.

CVE-2025-14716MEDIUMUnauthorized access to informationEPSS 0.4%CVE-2026-58029MEDIUMFull Account Takeover from BotPasswords and OAuth via action=changeauthenticationdataEPSS 0.4%CVE-2022-40966HIGHAuthentication bypass vulnerability in multiple Buffalo network devices allows a network-adjacent attacker to bypass authentication and acceEPSS 0.4%CVE-2025-1231MEDIUMImproper password reset in PAM Module in Devolutions Server 2024.3.10.0 and earlier allows an authenticated user to reuse the oracle user paEPSS 0.4%CVE-2025-66174MEDIUMThere is an improper authentication vulnerability in some Hikvision DVR products. Due to the improper implementation of authentication for tEPSS 0.4%CVE-2025-24949MEDIUMIn JotUrl 2.0, is possible to bypass security requirements during the password change process.EPSS 0.3%CVE-2024-57491HIGHAuthentication Bypass vulnerability in jobx up to v1.0.1-RELEASE allows an attacker can exploit this vulnerability to access sensitive API wEPSS 0.3%CVE-2025-14908MEDIUMJeecgBoot Multi-Tenant Management SysTenantController.java improper authenticationEPSS 0.3%CVE-2023-0228HIGHImproper authentication vulnerability in S+ OperationsEPSS 0.3%CVE-2023-0863HIGHAuthentication to access the AC wallbox via its Bluetooth Low Energy (BLE) channel can be bypassed, EPSS 0.3%CVE-2025-11192HIGHFabric Engine (VOSS) AutoSense Authentication BypassEPSS 0.3%CVE-2026-72917MEDIUMAnythingLLM: Password recovery accepts one recovery code twice after whitespace normalizationEPSS 0.3%CVE-2026-30851HIGHCaddy forward_auth copy_headers Does Not Strip Client-Supplied Headers, Allowing Identity Injection and Privilege EscalationEPSS 0.3%CVE-2026-32804HIGHDell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Authentication vulnerability. An unauthenticated attacker with aEPSS 0.3%CVE-2026-78308CRITICALAuthentication Bypass in DIAEnergieEPSS 0.3%CVE-2022-30421HIGHImproper Authentication vulnerability in Toshiba Storage Security Software V1.2.0.7413 is that allows for sensitive information to be obtainEPSS 0.3%CVE-2026-73840MEDIUMOpenChoreo: Unauthenticated build/workflow trigger via git-provider confusion (webhook signature bypass)EPSS 0.3%CVE-2025-49012MEDIUMHimmelblau's Name-Based Group Matching in `pam_allow_groups` Leads to Potential Security BypassEPSS 0.3%CVE-2026-6729MEDIUMHKUDS OpenHarness Session Key Collision Privilege EscalationEPSS 0.3%CVE-2024-23792MEDIUMInsufficient access controlEPSS 0.3%