Weaknesses of type CWE-287

2,463 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2026-14547MEDIUMEstatik Real Estate Plugin < 4.3.3 - Unauthenticated Arbitrary-Recipient Mail Relay via Request FormEPSS 0.3%CVE-2022-43978MEDIUMLimited Authentication bypass due to hardcoded secretEPSS 0.3%CVE-2026-15315HIGHUnauthenticated Administrative Authentication Bypass via device_confirm Replay in TP-Link Tapo C120 and C200EPSS 0.3%CVE-2026-14305MEDIUMWP Delicious < 1.10.2 - Unauthenticated Arbitrary Post Meta Update via recipe_likesEPSS 0.3%CVE-2026-16282MEDIUMAppointment Hour Booking < 1.5.88 - Unauthenticated Booking Price Manipulation via tcost ParameterEPSS 0.3%CVE-2023-30560MEDIUM PCU Configuration Lacks AuthenticationEPSS 0.3%CVE-2026-54047CRITICALLaci Synchroni Backend Vulnerable to Account Takeover / User Impersonation via Client-Side Configuration ManipulationEPSS 0.3%CVE-2022-42463HIGHSoftbus_server in communication subsystem has a authenication bypass vulnerability in a callback handler function. Attackers can launch attacks on distributed networks by sending Bluetooth rfcomm packets to any remote device and executing arbitrary co ...EPSS 0.3%CVE-2026-44810HIGHMicrosoft Cryptographic Services Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-79974MEDIUMDell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper AuthentiEPSS 0.3%CVE-2026-22099HIGHMissing authentication for Bluetooth communicationEPSS 0.3%CVE-2026-60908HIGHVulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: Create Item Instance). Supported versions that arEPSS 0.3%CVE-2026-82980MEDIUMAny authenticated user can lock or unlock files they do not own by targeting absolute WebDAV paths of other users. The DAV plugin resolves fEPSS 0.3%CVE-2026-34389MEDIUMFleet's user account creation via invite does not enforce invited email addressEPSS 0.3%CVE-2026-19273MEDIUMThe Dashboard of IBM Sterling B2B Integrator and IBM Sterling File Gateway are Vulnerable to Improper Access ControlEPSS 0.3%CVE-2026-57107HIGHWindows Admin Center Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-26141HIGHHybrid Worker Extension (Arc‑enabled Windows VMs) Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-61049HIGHVulnerability in the Oracle Production Scheduling product of Oracle E-Business Suite (component: Internal Operations). Supported versions tEPSS 0.3%CVE-2026-101050HIGHHeym before 0.0.53 Authentication Bypass via Telegram WebhookEPSS 0.3%CVE-2026-101049HIGHHeym before 0.0.53 Slack Webhook Signature Verification BypassEPSS 0.3%