Weaknesses of type CWE-287

2,463 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2024-38351MEDIUMPassword auth and OAuth2 unverified email linkingEPSS 0.3%CVE-2026-44166MEDIUMPocketbase: Account pre-hijacking via OAuth2 unverfied->verified autolinking upgradeEPSS 0.3%CVE-2026-80128MEDIUMDell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper AuthentiEPSS 0.3%CVE-2025-52054MEDIUMAn issue was discovered in Tenda AC8 v4.0 AC1200 Dual-band Gigabit Wireless Router AC8v4.0 Firmware 16.03.33.05. The root password of the deEPSS 0.3%CVE-2023-5502HIGHOn affected platforms running Arista EOS with 802.1x authentication configured on the access/trunk ports, a malicious supplicant may bypass authentication.EPSS 0.3%CVE-2026-8508MEDIUMAn improper authentication vulnerability in the "social_login.cgi" CGI program in Zyxel WAX650S firmware versions through 7.10(ABRM.4)C0 couEPSS 0.3%CVE-2025-53545MEDIUMPress has a potential 2FA bypassEPSS 0.3%CVE-2026-24170HIGHNVIDIA UFM Enterprise contains a vulnerability in the web interface authorization component, where an authenticated user could cause impropeEPSS 0.3%CVE-2026-33512HIGHAVideo has an unauthenticated decrypt oracle leaking any ciphertextEPSS 0.3%CVE-2025-65397MEDIUMAn insecure authentication mechanism in the safe_exec.sh startup script of Blurams Flare Camera version 24.1114.151.929 and earlier allows aEPSS 0.3%CVE-2024-40713HIGHA vulnerability that allows a user who has been assigned a low-privileged role within Veeam Backup & Replication to alter Multi-Factor AutheEPSS 0.3%CVE-2024-7487MEDIUMImproper Authentication in WSO2 Identity Server 7.0.0 Allows Bypass of App-Native AuthenticationEPSS 0.3%CVE-2026-1524LOWAuth misconfiguration when multiple providers enabledEPSS 0.3%CVE-2025-31228MEDIUMThe issue was addressed with improved authentication. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7. An attacker with physiEPSS 0.3%CVE-2025-66515LOWNextcloud Approval app allows users to request approval for other users fileEPSS 0.3%CVE-2025-21450CRITICALImproper Authentication in GPS_GNSSEPSS 0.3%CVE-2022-31011HIGHTiDB authentication bypass vulnerabilityEPSS 0.3%CVE-2025-10463HIGHImproper Authentication in Birtech Information Technologies' SensawayEPSS 0.3%CVE-2024-50341LOWSecurity::login does not take into account custom user_checker in symfony/security-bundleEPSS 0.3%CVE-2025-22232MEDIUMSpring Cloud Config Server May Not Use Vault Token Sent By ClientsEPSS 0.3%