Weaknesses of type CWE-287

2,430 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2024-49757HIGHZitadel User Registration Bypass VulnerabilityEPSS 2.5%CVE-2018-0121—A vulnerability in the authentication functionality of the web-based service portal of Cisco Elastic Services Controller Software could alloEPSS 2.5%CVE-2019-18315—A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker with network accessEPSS 2.5%CVE-2017-13995—An Improper Authentication issue was discovered in iniNet Solutions iniNet Webserver, all versions prior to V2.02.0100. The webserver does nEPSS 2.5%CVE-2025-32975CRITICALQuest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.0.x before 14.0.341 EPSS 2.5%KEVCVE-2023-22964CRITICALZoho ManageEngine ServiceDesk Plus MSP before 10611, and 13x before 13004, is vulnerable to authentication bypass when LDAP authentication iEPSS 2.4%CVE-2017-7420—An Authentication Bypass (CWE-287) vulnerability in ESMAC (aka Enterprise Server Monitor and Control) in Micro Focus Enterprise Developer anEPSS 2.4%CVE-2017-11428HIGHMultiple SAML libraries may allow authentication bypass via incorrect XML canonicalization and DOM traversalEPSS 2.4%CVE-2022-48066CRITICALAn issue in the component global.so of Totolink A830R V4.1.2cu.5182 allows attackers to bypass authentication via a crafted cookie.EPSS 2.4%CVE-2020-3125HIGHCisco Adaptive Security Appliance Software Kerberos Authentication Bypass VulnerabilityEPSS 2.4%CVE-2017-11430HIGHMultiple SAML libraries may allow authentication bypass via incorrect XML canonicalization and DOM traversalEPSS 2.4%CVE-2026-49003CRITICALUnauthenticated RCE Vulnerability in ZTE ZXDU68 S202 V5.0 ProductEPSS 2.4%CVE-2018-1112HIGHglusterfs server before versions 3.10.12, 4.0.2 is vulnerable when using 'auth.allow' option which allows any unauthenticated gluster clientEPSS 2.4%CVE-2021-43786CRITICALAPI token verification can be bypassedEPSS 2.4%CVE-2020-3361HIGHCisco Webex Meetings and Cisco Webex Meetings Server Token Handling Unauthorized Access VulnerabilityEPSS 2.4%CVE-2022-24883HIGHFreeRDP Server authentication might allow invalid credentials to passEPSS 2.4%CVE-2022-39205CRITICALAccess Control Bypass in OnedevEPSS 2.4%CVE-2026-21891CRITICALZimaOS has Authentication Bypass via System-Level UsernameEPSS 2.4%CVE-2024-37152MEDIUMUnauthenticated Access to sensitive settings in Argo CDEPSS 2.3%CVE-2020-7533—CWE-287: Improper Authentication vulnerability exists which could cause the execution of commands on the webserver without authentication whEPSS 2.3%