Weaknesses of type CWE-287

2,463 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2018-17923—SAGA1-L8B with any firmware versions prior to A0.10 are vulnerable to an attack that an attacker with physical access to the product may ablEPSS 0.3%CVE-2026-42602HIGHazureauthextension Authenticate method does not validate bearer tokens, allowing auth bypass via replayEPSS 0.3%CVE-2026-31946CRITICALOpenOLAT: Authentication bypass via forged JWT in OIDC implicit flowEPSS 0.3%CVE-2024-55886MEDIUMOpenTelemetry Logs source may lack authentication with some custom pluginsEPSS 0.3%CVE-2026-52793HIGHFroxlor: API Authentication bypasses 2FA AuthenticationEPSS 0.3%CVE-2025-52571CRITICALHikka vulnerable to RCE through edits in a channelEPSS 0.3%CVE-2023-29117HIGHAuthentication Bypass in JuiceBox Web Manager interfaceEPSS 0.3%CVE-2026-55759HIGHRocket.Chat: Apple Sign-In skips JWT claims validation, allowing expired and cross-audience token replayEPSS 0.3%CVE-2026-15240HIGHCustomer Switching for WooCommerce < 2.1.3 - Customer+ Privilege Escalation to Administrator via Insecure Operator ResolutionEPSS 0.3%CVE-2026-19709MEDIUMMembership For WooCommerce < 3.1.2 - Unauthenticated Member Data Disclosure via REST Consumer Secret BypassEPSS 0.3%CVE-2026-77771HIGHminiOrange 2FA (Free & Pro) - 2FA Bypass via Session-Scoped OTP LockoutEPSS 0.3%CVE-2025-10224MEDIUMIncorrect Evaluation of LDAP Nested Groups during Login in AxxonSoft Axxon One (C-Werk)EPSS 0.3%CVE-2026-73208HIGHAn attacker that holds a token intended for a different purpose can authenticate, because when an OAuth2 token response does not contain a sEPSS 0.3%CVE-2026-11923HIGHSecurity vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify AccessEPSS 0.3%CVE-2026-76548HIGHProfile Builder < 4.0.1 - Unauthenticated Unpublished Content and Media Modification via Front-End Upload Auth BypassEPSS 0.3%CVE-2026-65121HIGHNVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause an improper authentication issue. A succeEPSS 0.3%CVE-2024-41589HIGHDrayTek Vigor310 devices through 4.3.2.6 use unencrypted HTTP for authentication requests.EPSS 0.3%CVE-2024-38351MEDIUMPassword auth and OAuth2 unverified email linkingEPSS 0.3%CVE-2025-54761HIGHAn issue was discovered in PPress 0.0.9 allowing attackers to gain escilated privlidges via crafted session cookie.EPSS 0.3%CVE-2026-18891HIGHLangflow is affected by multiple authentication bypass, path traversal, authorization, and server-side request forgery vulnerabilitiesEPSS 0.3%