Falhas do tipo CWE-289

44 resultados

Bypass de autenticação por nome alternativo

O sistema falha em validar que nomes alternativos, aliases ou representações diferentes de um mesmo recurso ou usuário referem-se à mesma entidade. Um atacante explora isso usando um nome alternativo não verificado para contornar controles de autenticação ou autorização, acessando recursos que deveria estar bloqueado.

Exemplo

Um servidor web autentica usuários por nome de login, mas não sincroniza a validação com o nome do sistema de domínio (LDAP/Active Directory). Um atacante usa 'usuario@dominio.local' em vez de 'usuario' para fazer login, contornando bloqueios de lista negra aplicados apenas ao primeiro formato.

Como mitigar

Normalize e canonicalize todos os formatos de identificação (usernames, paths, domínios) antes de qualquer validação de segurança. Mantenha uma única fonte da verdade para entidades e valide todas as representações alternativas contra essa fonte, não permitindo que diferentes formas do mesmo recurso tenham políticas de segurança divergentes.

CVE-2024-56511CRITICALDataEase has an unauthorized vulnerabilityEPSS 44.5%CVE-2021-34746CRITICALCisco Enterprise NFV Infrastructure Software Authentication Bypass VulnerabilityEPSS 17.7%CVE-2026-48618HIGHA flaw in Node.js TLS hostname handling can cause Node.js unicode dot separator handling can lead to tls wildcard-depth authentication bypasEPSS 3.2%CVE-2017-16590This vulnerability allows remote attackers to bypass authentication on vulnerable installations of NetGain Systems Enterprise Manager 7.2.69EPSS 3.0%CVE-2025-55130HIGHA flaw in Node.js’s Permissions model allows attackers to bypass `--allow-fs-read` and `--allow-fs-write` restrictions using crafted relativEPSS 1.7%CVE-2026-44492HIGHAxios: shouldBypassProxy does not recognize IPv4-mapped IPv6 addresses, allowing NO_PROXY bypass (incomplete fix for CVE-2025-62718)EPSS 0.9%CVE-2023-20046HIGHA vulnerability in the key-based SSH authentication feature of Cisco StarOS Software could allow an authenticated, remote attacker to elevatEPSS 0.9%CVE-2023-38487MEDIUMHedgeDoc API allows to hide existing notesEPSS 0.8%CVE-2023-1803CRITICALAuthentication Bypass in Redline RouterEPSS 0.8%CVE-2023-41890HIGHSustainsys.Saml2 Insufficient Identity Provider Issuer ValidationEPSS 0.8%CVE-2023-3263HIGHThe Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier is vulnerable to authentication bypass in the REST API due to the EPSS 0.7%CVE-2026-56091HIGHApache Shiro: Authentication bypass in Guice-Web integrationEPSS 0.7%CVE-2026-53622HIGHTraefik: HTTP/3 mTLS bypass via exact SNI TLSOptions lookup for wildcard and mixed-case hostsEPSS 0.6%CVE-2024-51996HIGHSymphony has an Authentication Bypass via RememberMeEPSS 0.6%CVE-2026-24058HIGHSoft Serve has Critical Authentication BypassEPSS 0.6%CVE-2026-9701CRITICALEventer <= 4.4.2 - Insecure Password Reset Mechanism to Unauthenticated Privilege EscalationEPSS 0.5%CVE-2026-39858HIGHTraefik: Forwarded alias spoofing top pre-auth decision bypassEPSS 0.5%CVE-2026-55075HIGHCoder vulnerable to OIDC account takeover via email-based user matching and email_verified bypassEPSS 0.5%CVE-2025-13613CRITICALElated Membership <= 1.2 - Authentication Bypass via Social LoginEPSS 0.5%CVE-2024-2098HIGHDownload Manager <= 3.2.89 - Improper Authorization via protectMediaLibraryEPSS 0.5%