Weaknesses of type CWE-287

2,430 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2020-8206—An improper authentication vulnerability exists in Pulse Connect Secure <9.1RB that allows an attacker with a users primary credentials to bEPSS 3.0%CVE-2017-14008—GE Centricity PACS RA1000, diagnostic image analysis, all current versions are affected these devices use default or hard-coded credentials.EPSS 3.0%CVE-2017-6869—A vulnerability was discovered in Siemens ViewPort for Web Office Portal before revision number 1453 that could allow an unauthenticated remEPSS 3.0%CVE-2026-80099HIGHVarious Newfold Plugins Various Versions - Unauthenticated Authentication Bypass via Bearer Token Validation with Empty SecretEPSS 2.9%CVE-2025-30287HIGHColdFusion | Improper Authentication (CWE-287)EPSS 2.9%CVE-2026-48611CRITICALImproper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not configured or enabled leading to uEPSS 2.9%CVE-2022-24882CRITICALServer side NTLM does not properly check parameters in FreeRDPEPSS 2.8%CVE-2017-11429HIGHMultiple SAML libraries may allow authentication bypass via incorrect XML canonicalization and DOM traversalEPSS 2.7%CVE-2020-10918HIGHThis vulnerability allows remote attackers to bypass authentication on affected installations of C-MORE HMI EA9 Firmware version 6.52 touch EPSS 2.7%CVE-2023-46290HIGHRockwell Automation FactoryTalk Services Platform Elevated Privileges VulnerabilityEPSS 2.7%CVE-2017-7920—An Improper Authentication issue was discovered in ABB VSN300 WiFi Logger Card versions 1.8.15 and prior, and VSN300 WiFi Logger Card for ReEPSS 2.7%CVE-2022-40664CRITICALAuthentication Bypass Vulnerability in Shiro when forwarding or including via RequestDispatcherEPSS 2.7%CVE-2018-13804—A vulnerability has been identified in SIMATIC IT LMS (All versions), SIMATIC IT Production Suite (Versions V7.1 < V7.1 Upd3), SIMATIC IT UAEPSS 2.7%CVE-2018-5459—An Improper Authentication issue was discovered in WAGO PFC200 Series 3S CoDeSys Runtime versions 2.3.X and 2.4.X. An attacker can execute dEPSS 2.7%CVE-2018-5451—In Philips Alice 6 System version R8.0.2 or prior, when an actor claims to have a given identity, the software does not prove or insufficienEPSS 2.6%CVE-2017-7919—An Improper Authentication issue was discovered in Newport XPS-Cx and XPS-Qx. An attacker may bypass authentication by accessing a specific EPSS 2.6%CVE-2018-0271—A vulnerability in the API gateway of the Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated, remote attacker toEPSS 2.5%CVE-2017-7931—In ABB IP GATEWAY 3.39 and prior, by accessing a specific uniform resource locator (URL) on the web server, a malicious user is able to acceEPSS 2.5%CVE-2019-18337CRITICALA vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0). The Control Center Server (CCS) contains an authEPSS 2.5%CVE-2026-11374CRITICALAccount Takeover via Predictable SSO Ticket GenerationEPSS 2.5%