Falhas do tipo CWE-345

549 resultados

Verificação insuficiente de autenticidade de dados

A aplicação recebe dados de fontes externas (rede, arquivo, entrada do usuário) mas não valida adequadamente se eles realmente vieram de quem diz vir ou se não foram alterados no caminho. Isso permite que um atacante forje, intercepte ou modifique dados sem que o sistema detecte, comprometendo integridade e confiança.

Exemplo

Um serviço REST que confia cegamente em um campo 'user_id' vindo do cliente, sem verificar assinatura ou token, permitindo que alguém mude a URL para acessar dados de outro usuário. Ou um arquivo de configuração lido sem validar sua hash, permitindo execução de código malicioso se o arquivo for corrompido.

Como mitigar

Use mecanismos criptográficos de autenticação (HMAC, assinatura digital, certificados TLS) para garantir a origem e integridade dos dados. No lado do servidor, nunca confie em identificadores ou claims do cliente — valide contra seu próprio estado autorizado (sessão, JWT assinado, etc).

CVE-2026-84043MEDIUMePayco Payment Gateway for WooCommerce < 8.4.7 - Unauthenticated Payment Confirmation BypassEPSS 0.1%CVE-2026-83537MEDIUMWP Express Checkout < 2.5.0 - Unauthenticated Payment Bypass via wpec_process_empty_paymentEPSS 0.1%CVE-2026-83533MEDIUMWP Express Checkout < 2.4.9 - Unauthenticated Payment Bypass via wpec_process_paymentEPSS 0.1%CVE-2026-82215MEDIUMWC PayPay Gateway 0.5 - 0.9.3 - Unauthenticated Payment Bypass via Unverified WebhookEPSS 0.1%CVE-2026-86809MEDIUMPersian Elementor < 2.8.2 - Unauthenticated ZarinPal Payment Callback Authority BypassEPSS 0.1%CVE-2026-15148MEDIUMWP Events Manager < 2.2.5 - Unauthenticated Payment Bypass and Booking Status Update via IDOREPSS 0.1%CVE-2021-26396MEDIUMInsufficient validation of address mapping to IO in ASP (AMD Secure Processor) may result in a loss of memory integrity in the SNP guest. EPSS 0.1%CVE-2026-78296MEDIUMWordPress FluentAuth plugin <= 2.1.2 - Email Verification Bypass vulnerabilityEPSS 0.1%CVE-2026-15211MEDIUMSubscriptions for WooCommerce < 2.0.1 - Payment Bypass via Attacker-Supplied PayPal Capture TokenEPSS 0.1%CVE-2026-24775MEDIUMOpenProject has Forced Actions, Content Spoofing, and Persistent DoS via ID Manipulation in OpenProject Blocknote Editor ExtensionEPSS 0.1%CVE-2026-15239MEDIUMSimple CAPTCHA with Cloudflare Turnstile < 1.42.0 - Unauthenticated Turnstile Protection Bypass via Reusable Forminator Cache KeyEPSS 0.1%CVE-2026-45792MEDIUMRTK improperly trusts project-local filter configuration, allowing silent tampering of command output shown to LLMEPSS 0.1%CVE-2026-33243HIGHbarebox: FIT Signature Verification Bypass VulnerabilityEPSS 0.1%CVE-2026-15246MEDIUMRealHomes Memberships < 3.1.0 - Subscriber+ Membership Payment BypassEPSS 0.1%CVE-2026-46654HIGHPlonky3 MultiField32Challenger: transcript malleability and challenge entropy lossEPSS 0.1%CVE-2026-28145MEDIUMWordPress MasterStudy LMS plugin <= 3.7.39 - Broken Access Control vulnerabilityEPSS 0.1%CVE-2026-32323HIGHMullvad VPN for macOS: Local Privilege Escalation via unverified bundle path in installerEPSS 0.1%CVE-2026-78417MEDIUMInsufficient verification of data authenticity in the IronVNC client in Devolutions Remote Desktop Manager 2026.2.17.0 and earlier, 2026.1.2EPSS 0.1%CVE-2026-10827LOWSpectra (Ultimate Addons for Gutenberg) < 2.20.0 - Contributor+ Stored CSS Injection via Block AttributesEPSS 0.1%CVE-2026-62995LOWjoserfc accepts JWT with padding, leading to JWT malleabilityEPSS 0.1%