Weaknesses of type CWE-287

2,463 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2026-101050HIGHHeym before 0.0.53 Authentication Bypass via Telegram WebhookEPSS 0.3%CVE-2023-29062LOWUnsecure Identity VerificationEPSS 0.3%CVE-2023-43660MEDIUMSSH key password bypassed in warpgateEPSS 0.3%CVE-2026-10283MEDIUMBottelet DaybydayCRM Setting missing authenticationEPSS 0.3%CVE-2023-20012MEDIUMCisco Nexus 9300-FX3 Series Fabric Extender for UCS Fabric Interconnects Authentication Bypass VulnerabilityEPSS 0.3%CVE-2025-29627MEDIUMAn issue in KeeperChat IOS Application v.5.8.8 allows a physically proximate attacker to escalate privileges via the Biometric AuthenticatioEPSS 0.3%CVE-2024-40778LOWAn authentication issue was addressed with improved state management. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadEPSS 0.3%CVE-2025-22477HIGHDell Storage Center - Dell Storage Manager, version(s) 20.1.20, contain(s) an Improper Authentication vulnerability. An unauthenticated attaEPSS 0.3%CVE-2023-20199MEDIUMCisco Duo Two-Factor Authentication for macOS Authentication Bypass VulnerabilityEPSS 0.3%CVE-2026-16739MEDIUMEpeken All Kurir <= 2.1.4 - Unauthenticated Order Payment Confirmation ForgeryEPSS 0.3%CVE-2026-74240MEDIUMQuay: jwt claim validation bypasses in quay federated robot and sso authenticationEPSS 0.3%CVE-2026-12695HIGHminiOrange 2FA < 6.2.6 - 2FA Bypass via Attacker-Controlled ga_secretEPSS 0.3%CVE-2026-97063CRITICALX-SpringBoot through 6.0 Authentication Bypass via Login CodeEPSS 0.3%CVE-2026-73733MEDIUMAuthentication Bypasses in API allow Continued Authenticated Access in HPE Networking Fabric ComposerEPSS 0.3%CVE-2026-49848MEDIUMFreeSWITCH: Pre-authentication `userVariables` injection in `mod_verto`EPSS 0.3%CVE-2026-48117MEDIUMDroneAware's Improper Account Activation in Registration and SSO Flows Leads to Account TakeoverEPSS 0.3%CVE-2025-10772MEDIUMhuggingface LeRobot ZeroMQ Socket lekiwi_remote.py missing authenticationEPSS 0.3%CVE-2025-1024HIGHSession Hijacking via Reflected Cross-Site Scripting (XSS) in ChurchCRM EditEventAttendees.php EID ParameterEPSS 0.3%CVE-2025-56447CRITICALTM2 Monitoring v3.04 contains an authentication bypass and plaintext credential disclosure.EPSS 0.3%CVE-2026-53516HIGHBetter Auth: Account takeover via OAuth auto-link to unverified pre-registered emailEPSS 0.3%