Weaknesses of type CWE-287

2,462 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2024-0130HIGHNVIDIA UFM Enterprise, UFM Appliance, and UFM CyberAI contain a vulnerability where an attacker can cause an improper authentication issue bEPSS 0.3%CVE-2025-7699HIGHAn improper access control vulnerability was found in the EZ Sync Manager of ADMEPSS 0.3%CVE-2025-24292MEDIUMA misconfigured query in UniFi Network (v9.1.120 and earlier) could allow users to authenticate to Enterprise WiFi or VPN Server (l2tp and OEPSS 0.3%CVE-2025-65127MEDIUMA lack of session validation in the web API component of Shenzhen Zhibotong Electronics ZBT WE2001 23.09.27 allows remote unauthenticated atEPSS 0.3%CVE-2023-42554MEDIUMImproper Authentication vulnerabiity in Samsung Pass prior to version 4.3.00.17 allows physical attackers to bypass authentication.EPSS 0.3%CVE-2026-53561HIGHApache Hive: Unauthenticated authentication bypass in HiveServer2 HTTP SAML bearer-token validation allows impersonation of any Hive userEPSS 0.3%CVE-2026-18221HIGHIBM i is Affected By Improper Authorization and Authentication Vulnerabilities in DDM / DRDA [, ]EPSS 0.3%CVE-2023-3591MEDIUMLack of previous password reset tokens on new token creationEPSS 0.3%CVE-2026-29193HIGHZITADEL: Bypassing Zitadel Login Behavior and Security Policy in Login V2EPSS 0.3%CVE-2025-15346CRITICALwolfSSL Python library `CERT_REQUIRED` mode fails to enforce client certificate requirementEPSS 0.3%CVE-2024-56335HIGHPrivilege escalation allows organization groups to be updated/deleted if their UUID is known in vaultwardenEPSS 0.3%CVE-2026-28800MEDIUMNatro Macro: Malicious actions allowed through Discord RC Commands by any userEPSS 0.3%CVE-2026-81237MEDIUMDell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Improper Authentication vulnerability. An unauthenticated attacker wiEPSS 0.3%CVE-2024-3826HIGHBroken SAML ValidationEPSS 0.3%CVE-2026-71326LOWTraefik: BasicAuth singleflight key collision allows authenticated identity spoofingEPSS 0.3%CVE-2026-17628MEDIUMLangflow is affected by improper authentication due to missing password verification in the password reset endpointEPSS 0.3%CVE-2026-44720MEDIUMOpenLearnX: Critical Authentication Bypass via JWT Signature Verification Disabled Leading to Account TakeoverEPSS 0.3%CVE-2026-84623HIGHAn authorization issue was addressed with improved state management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27. EPSS 0.3%CVE-2026-61188HIGHVulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Installation). The sEPSS 0.3%CVE-2026-62493HIGHVulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affEPSS 0.3%