Weaknesses of type CWE-287

2,463 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2026-53516HIGHBetter Auth: Account takeover via OAuth auto-link to unverified pre-registered emailEPSS 0.3%CVE-2026-100607CRITICALFlowise through 3.1.4 Authentication Bypass via Email-Only SSOEPSS 0.3%CVE-2020-8108HIGHInsufficient client validation in Bitdefender Endpoint Security for Mac (VA-8759)EPSS 0.3%CVE-2025-54786MEDIUMSuiteCRM: Legacy iCal service allows unauthenticated access to meeting dataEPSS 0.3%CVE-2023-49790MEDIUMApp PIN code can be bypassed in Nextcloud Files iOSEPSS 0.3%CVE-2026-100709HIGHFroxlor before 2.3.12 2FA Bypass via Namespace ConfusionEPSS 0.3%CVE-2024-21635HIGHMemos Access Tokens Stay Valid after User Password ChangeEPSS 0.3%CVE-2024-56445MEDIUMInstruction authentication bypass vulnerability in the Findnetwork module Impact: Successful exploitation of this vulnerability may cause feEPSS 0.3%CVE-2025-7703LOWAuthentication vulnerability in the mobile application(tech.palm.id)may lead to the risk of information leakage.EPSS 0.3%CVE-2026-56666MEDIUMZITADEL: Auto-linking by email: IdP-side email verification is not checkedEPSS 0.3%CVE-2026-85056HIGHZITADEL: MFA bypass via session reuse in Login V2EPSS 0.3%CVE-2025-68402HIGHFreshRSS has an authentication bypass due to truncated bcrypt hash [edge branch]EPSS 0.3%CVE-2024-45036MEDIUMImproper Access Control Vulnerability When Accessing a Maliciously Crafted Tophat LinkEPSS 0.3%CVE-2026-67335MEDIUMbetter-auth before 1.6.2 OAuth State Validation BypassEPSS 0.3%CVE-2026-23708MEDIUMA improper authentication vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR on-preEPSS 0.3%CVE-2022-41579MEDIUMThere is an insufficient authentication vulnerability in some Huawei band products. Successful exploit could allow the attacker to spoof theEPSS 0.3%CVE-2025-29773MEDIUMFroxlor allows Multiple Accounts to Share the Same Email Address Leading to Potential Privilege Escalation or Account TakeoverEPSS 0.3%CVE-2026-18960MEDIUMBlock User Account < 2.0.1 - Subscriber+ Account Block Bypass via Application PasswordsEPSS 0.3%CVE-2026-4829MEDIUMImproper authentication in the external OAuth authentication flow in Devolutions Server 2026.1.11 and earlier allows an authenticated user tEPSS 0.3%CVE-2026-24003MEDIUMEvseV2G has sequence state validation bypassEPSS 0.3%