Falhas do tipo CWE-345

557 resultados

Verificação insuficiente de autenticidade de dados

A aplicação recebe dados de fontes externas (rede, arquivo, entrada do usuário) mas não valida adequadamente se eles realmente vieram de quem diz vir ou se não foram alterados no caminho. Isso permite que um atacante forje, intercepte ou modifique dados sem que o sistema detecte, comprometendo integridade e confiança.

Exemplo

Um serviço REST que confia cegamente em um campo 'user_id' vindo do cliente, sem verificar assinatura ou token, permitindo que alguém mude a URL para acessar dados de outro usuário. Ou um arquivo de configuração lido sem validar sua hash, permitindo execução de código malicioso se o arquivo for corrompido.

Como mitigar

Use mecanismos criptográficos de autenticação (HMAC, assinatura digital, certificados TLS) para garantir a origem e integridade dos dados. No lado do servidor, nunca confie em identificadores ou claims do cliente — valide contra seu próprio estado autorizado (sessão, JWT assinado, etc).

CVE-2026-58002HIGHWWBN AVideo Authorization Bypass via Users_affiliations add.json.phpEPSS 0.1%CVE-2026-39969MEDIUMTypeBot: WhatsApp Webhook Endpoint Missing Signature VerificationEPSS 0.1%CVE-2025-23415LOWBIG-IP APM Endpoint Inspection vulnerabilityEPSS 0.1%CVE-2026-54579LOWmport mirror-selection ping accepts insufficiently validated ICMP repliesEPSS 0.1%CVE-2026-81702CRITICALopenssl_encrypt before 1.4.9 Key Substitution via Identity LoadEPSS 0.1%CVE-2026-2428HIGHFluent Forms Pro Add On Pack <= 6.1.17 - Missing Authorization to Unauthenticated Payment Status modificationEPSS 0.1%CVE-2026-71858MEDIUMNotepad++: shortcuts.xml Macro HMAC Bypass Enables Conditional Elevated Command ExecutionEPSS 0.1%CVE-2022-22567MEDIUMSelect Dell Client Commercial and Consumer platforms are vulnerable to an insufficient verification of data authenticity vulnerability. An aEPSS 0.1%CVE-2026-53728HIGHMedplum - Improper Validation of Redirect URI in External Auth Callback allows Authorization Code LeakageEPSS 0.1%CVE-2026-10079HIGHStackrox: stackrox: deploy-time policy enforcement and visibility bypass via label injectionEPSS 0.1%CVE-2023-36858HIGHBIG-IP Edge Client for Windows and macOS vulnerabilityEPSS 0.1%CVE-2026-54586MEDIUMmport permits repository and package mirror fetches over insecure transportEPSS 0.1%CVE-2026-85641MEDIUMFormidable Forms 6.34 - Unauthenticated Stored Content Injection via 'updated_by' ParameterEPSS 0.1%CVE-2026-82462MEDIUMpac4j-oidc before 6.5.6 Authentication Bypass via Access Token SubstitutionEPSS 0.1%CVE-2026-81706CRITICALopenssl_encrypt before 1.4.9 Key Substitution via Identity ShadowingEPSS 0.1%CVE-2026-73450HIGHSecurity Advisory 0161EPSS 0.1%CVE-2024-39805HIGHInsufficient verification of data authenticity in some Intel(R) DSA software before version 23.4.39 may allow an authenticated user to potenEPSS 0.1%CVE-2025-56438MEDIUMAn issue in the firmware update mechanism of Nous W3 Smart WiFi Camera v1.33.50.82 allows unauthenticated and physically proximate attackersEPSS 0.1%CVE-2023-43636HIGHRootfs Not ProtectedEPSS 0.1%CVE-2026-49331MEDIUMOpenshift/oauth-proxy: openshift/oauth-proxy: unauthenticated identity header injection on whitelisted pathsEPSS 0.1%