Weaknesses of type CWE-287

2,463 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2020-3151MEDIUMCisco Connected Mobile Experiences Restricted Shell Escape VulnerabilityEPSS 0.3%CVE-2026-18651MEDIUM389-ds-base: 389-ds-base: sasl plain bind installs connection credentials before account-lock check, allowing continued access as a locked accountEPSS 0.3%CVE-2026-49203HIGHUnauthenticated eSIM Configuration ManipulationEPSS 0.3%CVE-2026-33215MEDIUMNATS is vulnerable to MQTT hijacking via Client IDEPSS 0.3%CVE-2024-27137MEDIUMApache Cassandra: unrestricted deserialization of JMX authentication credentialsEPSS 0.3%CVE-2026-14214LOWAmelia < 2.4.4 - Amelia Manager+ Arbitrary User-Field Modification via Mass AssignmentEPSS 0.3%CVE-2026-40178MEDIUMajenti.plugin.core has a race conditions in 2FAEPSS 0.3%CVE-2024-40648MEDIUM`UserIdentity::is_verified` not checking verification status of own user identity while performing the check in matrix-rust-sdkEPSS 0.3%CVE-2020-7276MEDIUMUnrestricted Policy Management using MfeUpgradeTool.exeEPSS 0.3%CVE-2024-45347CRITICALMi Connect Service APP protocol flaws lead to unauthorized accessEPSS 0.3%CVE-2023-28647MEDIUMApp pin of the iOS app can be bypassed in Nextcloud iOSEPSS 0.3%CVE-2026-100876MEDIUMmathurvishal CloudClassroom-PHP-Project loginlinkstudent.php missing authenticationEPSS 0.3%CVE-2023-52111HIGHAuthorization vulnerability in the BootLoader module. Successful exploitation of this vulnerability may affect service integrity.EPSS 0.3%CVE-2026-14563CRITICALAdvanced Customized Prompts <= 1.0.1 - Unauthenticated Account TakeoverEPSS 0.3%CVE-2026-77244CRITICAL[mcp-atlassian] Authentication bypass in HTTP transport: AtlassianOpaqueTokenVerifier accepts any non-empty tokenEPSS 0.3%CVE-2026-14559CRITICALTeddy Bear Customize Addon <= 1.0.5 - Unauthenticated Account TakeoverEPSS 0.3%CVE-2026-90623MEDIUMandreashappe cochise SSH Host Key ssh_connection.py asyncssh.connect certificate validationEPSS 0.3%CVE-2026-14561MEDIUMAuthora - Easy Login with Mobile Number < 1.7.7 - Unauthenticated Account Takeover via OTP DisclosureEPSS 0.3%CVE-2026-39324CRITICALRack::Session::Cookie secrets: decrypt failure fallback enables secretless session forgery and Marshal deserializationEPSS 0.3%CVE-2025-65128HIGHA missing authentication mechanism in the web management API components of Shenzhen Zhibotong Electronics ZBT WE2001 23.09.27 allows unautheEPSS 0.3%