Falhas do tipo CWE-290

607 resultados

Autenticação vulnerável a falsificação de identidade

Ocorre quando o sistema implementa mecanismos de autenticação de forma incorreta, permitindo que um atacante se passe por outro usuário sem fornecer credenciais válidas. A falha geralmente está em lógica fraca de validação de identidade, como confiar em dados facilmente manipuláveis (headers HTTP, cookies não assinados) ou em esquemas de autenticação incompletos que não verificam adequadamente quem está fazendo a requisição.

Exemplo

Um aplicativo web que valida login apenas verificando se existe um cookie com o nome 'user_id=123', sem assinatura criptográfica. Um atacante pode simplesmente adicionar esse cookie em sua requisição e o sistema o autenticará como o usuário 123. Outro caso comum: APIs que usam IP de origem como forma de autenticação, facilmente spoofada.

Como mitigar

Implemente autenticação robusta baseada em padrões estabelecidos (OAuth 2.0, JWT com assinatura, sessões server-side com tokens opacos). Valide identidade em cada requisição através de mecanismos criptográficos. Nunca confie unicamente em dados do cliente (headers customizados, cookies não assinados) como prova de identidade; sempre verifique contra estado confiável no servidor.

CVE-2026-16101HIGHforced re-pairing with already bonded deviceEPSS 0.2%CVE-2026-33223MEDIUMNATS Server: Incomplete Stripping of Nats-Request-Info Header Allows Identity SpoofingEPSS 0.2%CVE-2026-19291HIGHBluetooth re-pairing can use a lower security level than previousEPSS 0.2%CVE-2026-5792MEDIUMAuthentication Bypass in Hedef Media's Related Marketing Cloud (RMC)EPSS 0.2%CVE-2026-28480MEDIUMOpenClaw < 2026.2.14 - Identity Spoofing via Mutable Username in Telegram Allowlist AuthorizationEPSS 0.2%CVE-2026-89327LOWFluentBoards < 2.0.15 - Board Member+ Comment Author Spoofing via 'comment_by' ParameterEPSS 0.2%CVE-2026-53823HIGHOpenClaw < 2026.5.3 - Privilege Escalation via Mutable Slack Display Names in allowFromEPSS 0.2%CVE-2026-54763HIGHTraefik: headerField underscore-variant identity spoofing in BasicAuth / DigestAuth / ForwardAuthEPSS 0.2%CVE-2025-48906HIGHAuthentication bypass vulnerability in the DSoftBus module Impact: Successful exploitation of this vulnerability may affect availability.EPSS 0.2%CVE-2026-88879MEDIUMTraefik before v2.11.56 Identity Spoofing via Header AliasEPSS 0.2%CVE-2026-72809HIGHSiYuan before v3.7.4 Authentication Bypass via Localhost TrustEPSS 0.2%CVE-2026-66674MEDIUMWordPress Simple Cloudflare Turnstile plugin <= 1.42.1 - Captcha Bypass vulnerabilityEPSS 0.2%CVE-2026-64797HIGHJoomla Extension - regularlabs.com - IP spoofing vulnerability in IP login extensionEPSS 0.2%CVE-2026-8676HIGHAn attacker is able to downgrade the security of a Bluetooth LE connection by deleting an existing bond, spoofing the bonded device and creaEPSS 0.2%CVE-2026-93511MEDIUMPremium Packages < 7.2.1 - Unauthenticated PayPal Webhook Signature Verification BypassEPSS 0.2%CVE-2025-66270MEDIUMThe KDE Connect protocol 8 before 2025-11-28 does not correlate device IDs across two packets. This affects KDE Connect before 25.12 on deskEPSS 0.2%CVE-2026-84766MEDIUMWordPress FluentBooking Pro plugin <= 2.2.1 - Bypass Vulnerability vulnerabilityEPSS 0.2%CVE-2025-36119HIGHIBM i authentication bypassEPSS 0.2%CVE-2024-39341MEDIUMEntrust Instant Financial Issuance (On Premise) Software (formerly known as Cardwizard) 6.10.0, 6.9.0, 6.9.1, 6.9.2, and 6.8.x and earlier lEPSS 0.2%CVE-2024-36557MEDIUMThe device ID is based on IMEI in Forever KidsWatch Call Me KW50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h and Forever KidsWatch CallEPSS 0.2%