Weaknesses of type CWE-287

2,462 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2026-44351CRITICALfast-jwt: Empty HMAC secret accepted via async key resolver - JWT auth bypassEPSS 0.3%CVE-2022-46774MEDIUMIBM Manage Application security bypassEPSS 0.3%CVE-2026-60679HIGHVulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected areEPSS 0.3%CVE-2026-60927HIGHVulnerability in the Oracle Public Sector Financials product of Oracle E-Business Suite (component: Internal Operations). Supported versionEPSS 0.3%CVE-2026-61188HIGHVulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Installation). The sEPSS 0.3%CVE-2025-6505HIGHUnauthorized access and impersonation can occur in versions 4.6.2.3226 and below of Progress Software's Hybrid Data Pipeline Server on LinuxEPSS 0.3%CVE-2025-26438HIGHIn smp_process_secure_connection_oob_data of smp_act.cc, there is a possible way to bypass SMP authentication due to Incorrect implementatioEPSS 0.3%CVE-2026-1410MEDIUMBeetel 777VR1 UART missing authenticationEPSS 0.3%CVE-2026-100684CRITICALBudibase Server 3.41.0 before 3.45.0 Authentication Bypass via OIDCEPSS 0.3%CVE-2025-3627MEDIUMMoodle: partial data exposure in moodle before completing multi-factor authenticationEPSS 0.3%CVE-2025-64103HIGHZitadel Bypass Second Authentication FactorEPSS 0.3%CVE-2025-15135MEDIUMjoey-zhou xiaozhi-esp32-server-java Cookie AuthenticationInterceptor.java tryAuthenticateWithCookies improper authenticationEPSS 0.3%CVE-2024-28188MEDIUMjupyter-scheduler's endpoint is missing authenticationEPSS 0.3%CVE-2026-56353MEDIUMn8n - Authentication Bypass in Chat Trigger NodeEPSS 0.3%CVE-2018-19937MEDIUMA local, authenticated attacker can bypass the passcode in the VideoLAN VLC media player app before 3.1.5 for iOS by opening a URL and turniEPSS 0.3%CVE-2025-56578MEDIUMAn issue in RTSPtoWeb v.2.4.3 allows a remote attacker to obtain sensitive information and executearbitrary code via the lack of authenticatEPSS 0.3%CVE-2026-27968MEDIUMPackistry accepts expired access tokensEPSS 0.3%CVE-2020-7323MEDIUMAuthentication Protection Bypass vulnerability in ENS for WindowsEPSS 0.3%CVE-2024-49755LOWDuende IdentityServer has insufficient validation of DPoP cnf claim in Local APIsEPSS 0.3%CVE-2018-17923—SAGA1-L8B with any firmware versions prior to A0.10 are vulnerable to an attack that an attacker with physical access to the product may ablEPSS 0.3%