Weaknesses of type CWE-287

2,463 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2026-30223HIGHOliveTin: JWT Audience Validation Bypass in Local Key and HMAC ModesEPSS 0.3%CVE-2025-41108CRITICALImproper Authentication vulnerability in Ghost Robotics' Vision 60EPSS 0.3%CVE-2025-55340HIGHWindows Remote Desktop Protocol Security Feature BypassEPSS 0.3%CVE-2024-0568HIGH CWE-287: Improper Authentication vulnerability exists that could cause unauthorized tampering of device configuration over NFC communicatioEPSS 0.3%CVE-2023-40282MEDIUMImproper authentication vulnerability in Rakuten WiFi Pocket all versions allows a network-adjacent attacker to log in to the product's ManaEPSS 0.3%CVE-2026-25922HIGHauthentik has a Signature Verification Bypass via SAML Assertion WrappingEPSS 0.3%CVE-2026-15087MEDIUMClean RESTful - Critical - Unsupported - SA-CONTRIB-2026-078EPSS 0.3%CVE-2026-100871HIGHSylius before 1.12.25, 1.13.17, 1.14.20, 2.1.16, and 2.2.9 JWT Audience Confusion Allows Admin API AuthenticationEPSS 0.3%CVE-2023-21467MEDIUMError in 3GPP specification implementation in Exynos baseband prior to SMR Apr-2023 Release 1 allows incorrect handling of unencrypted messaEPSS 0.3%CVE-2026-30836CRITICALStep CA: Unauthenticated Certificate Issuance via SCEP UpdateReq (MessageType=18)EPSS 0.3%CVE-2021-33076MEDIUMImproper authentication in firmware for some Intel(R) SSD DC Products may allow an unauthenticated user to potentially enable escalation of EPSS 0.3%CVE-2025-3659CRITICALImproper authentication handling for Digi PortServer TS; Digi One SP, SP IA, IA; Digi One IAPEPSS 0.3%CVE-2024-37897MEDIUMInsufficient access control for password reset in sftpgoEPSS 0.3%CVE-2023-50804LOWAn issue was discovered in Samsung Mobile Processor, and Modem Exynos 9820, Exynos 9825, Exynos 980, Exynos 990, Exynos 850, Exynos 1080, ExEPSS 0.3%CVE-2026-73764HIGHAuthentication Bypass Vulnerabilities Leading to Unauthorized Modification and Service Disruption in AOS-CXEPSS 0.3%CVE-2025-15671MEDIUMWelcart e-Commerce < 2.12.1 - Session Fixation via uscesid ParameterEPSS 0.3%CVE-2024-35775MEDIUMWordPress Slider by Soliloquy plugin <= 2.7.6 - Broken Access Control to XSS vulnerabilityEPSS 0.3%CVE-2024-10474CRITICALFocus was incorrectly allowing internal links to utilize the app scheme used for deeplinking, which could result in links potentially circumEPSS 0.3%CVE-2026-14216MEDIUMAmelia < 2.4.7 - Unauthenticated Notification Queue DispatchEPSS 0.3%CVE-2026-14305MEDIUMWP Delicious < 1.10.2 - Unauthenticated Arbitrary Post Meta Update via recipe_likesEPSS 0.3%