Falhas do tipo CWE-304

41 resultados

Falha na implementação de autenticação por omissão de etapas

A aplicação implementa um mecanismo de autenticação, mas pula ou ignora uma ou mais etapas essenciais do fluxo, enfraquecendo a segurança. Isso pode ser um passo de validação, verificação de credenciais ou confirmação de identidade que deveria ser obrigatório. O risco: um atacante consegue contornar o controle de acesso sem fornecer credenciais válidas ou completas.

Exemplo

Um login de dois fatores que envia SMS, mas o código não valida se o SMS foi realmente confirmado antes de criar a sessão — basta navegar direto para o dashboard. Ou um formulário que checa apenas o usuário, mas pula a validação da senha porque uma condicional foi mal escrita.

Como mitigar

Auditar o fluxo completo de autenticação e garantir que TODAS as etapas sejam executadas em sequência, sem exceções. Use testes automatizados (unit e integração) que forçam cada passo do caminho crítico e falham se alguma validação for pulada.

CVE-2024-45764CRITICALDell Enterprise SONiC OS, version(s) 4.1.x, 4.2.x, contain(s) a Missing Critical Step in Authentication vulnerability. An unauthenticated atEPSS 0.5%CVE-2026-61466CRITICALApache CXF: OAuth2 Dynamic Client Registration Scope Self-EscalationEPSS 0.4%CVE-2026-49467HIGHTOTP enrollment hijack: password gate skipped due to unawaited promiseEPSS 0.4%CVE-2023-22833HIGHMandatory control bypass in Lime2EPSS 0.4%CVE-2026-67351HIGHSerendipity < 2.6.1 Authentication Bypass via Username CollisionEPSS 0.4%CVE-2024-7745MEDIUMMulti-Factor Authentication Bypass in Progress WS_FTP ServerEPSS 0.4%CVE-2026-30831HIGHRocket.Chat: 2FA bypass and login of deactivated users via EE ddp-streamerEPSS 0.3%CVE-2024-20153HIGHIn wlan STA, there is a possible way to trick a client to connect to an AP with spoofed SSID. This could lead to remote information disclosuEPSS 0.3%CVE-2026-54723MEDIUMdevpi: Database contents leakEPSS 0.3%CVE-2026-61143MEDIUMVulnerability in the Oracle Communications Convergent Charging Controller product of Oracle Communications (component: Prov IF). Supported EPSS 0.3%CVE-2025-55138HIGHLinkJoin through 882f196 mishandles token ownership in password reset.EPSS 0.3%CVE-2026-42452HIGHTermix: Pending-TOTP temporary token can regenerate backup codes and neutralize TOTPEPSS 0.3%CVE-2026-59564CRITICALAuthentication bypass between ZCC and client connector portalEPSS 0.3%CVE-2025-5715LOWSignal App Biometric Authentication missing critical step in authenticationEPSS 0.3%CVE-2024-52965MEDIUMA missing critical step in authentication vulnerability [CWE-304] in Fortinet FortiOS version 7.6.0 through 7.6.1, 7.4.0 through 7.4.5, 7.2.EPSS 0.3%CVE-2026-76207HIGHphpMyFAQ before 4.1.7 2FA Bypass via Remember-Me CookieEPSS 0.3%CVE-2024-11302HIGHMissing check_access in lollms_binding_infos in parisneo/lollmsEPSS 0.2%CVE-2025-43014MEDIUMIn JetBrains Toolbox App before 2.6 the SSH plugin established connections without sufficient user confirmationEPSS 0.2%CVE-2026-44547CRITICALChurchCRM: Incomplete fix for CVE-2026-40582: public API login still bypasses 2FA and account lockout in ChurchCRM 7.2.2EPSS 0.2%CVE-2025-43798LOWLiferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92 and 7.3 GA through update 35 allows a time-based one-time passwEPSS 0.2%