Weaknesses of type CWE-287

2,462 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2026-73840MEDIUMOpenChoreo: Unauthenticated build/workflow trigger via git-provider confusion (webhook signature bypass)EPSS 0.3%CVE-2026-78308CRITICALAuthentication Bypass in DIAEnergieEPSS 0.3%CVE-2022-30421HIGHImproper Authentication vulnerability in Toshiba Storage Security Software V1.2.0.7413 is that allows for sensitive information to be obtainEPSS 0.3%CVE-2026-32804HIGHDell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Authentication vulnerability. An unauthenticated attacker with aEPSS 0.3%CVE-2026-6729MEDIUMHKUDS OpenHarness Session Key Collision Privilege EscalationEPSS 0.3%CVE-2022-45456LOWDenial of service due to unauthenticated API endpoint. The following products are affected: Acronis Agent (Windows, macOS, Linux) before buiEPSS 0.3%CVE-2024-23792MEDIUMInsufficient access controlEPSS 0.3%CVE-2025-67507HIGHFilament's multi-factor authentication (app) recovery codes can be used multiple timesEPSS 0.3%CVE-2025-49012MEDIUMHimmelblau's Name-Based Group Matching in `pam_allow_groups` Leads to Potential Security BypassEPSS 0.3%CVE-2024-51997HIGHThe Attestation Results Token can be arbitrarily modified without being detected in TrusteeEPSS 0.3%CVE-2026-49502HIGHDell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Authentication vulnerability. An unauthenticated attacker with aEPSS 0.3%CVE-2024-58363MEDIUMSurrealDB before 1.5.4 Authentication Bypass via Database SwitchEPSS 0.3%CVE-2024-5798LOWVault Incorrectly Validated JSON Web Tokens (JWT) Audience ClaimsEPSS 0.3%CVE-2026-14568MEDIUMWP User Frontend < 4.3.8 - Unauthenticated Author-less Attachment DeletionEPSS 0.3%CVE-2026-18056HIGHHivePress Authentication <= 1.1.4 - Unauthenticated Authentication Bypass via 'access_token' Parameter to Facebook AuthenticatorEPSS 0.3%CVE-2025-65781HIGHAn issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Attachment upload API treats the AEPSS 0.3%CVE-2026-89080HIGHReally Simple Security < 9.8.1 - Unauthenticated 2FA Bypass via Email Provider State DemotionEPSS 0.3%CVE-2022-4001HIGHAn authentication bypass vulnerability could allow an attacker to access API functions without authentication.EPSS 0.3%CVE-2025-64423HIGHCoolify has a Privilege Escalation - low privileged users can see and use admin invitation linksEPSS 0.3%CVE-2026-63238MEDIUMAuthentication bypass vulnerabilityEPSS 0.3%