Weaknesses of type CWE-287

2,463 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2026-39324CRITICALRack::Session::Cookie secrets: decrypt failure fallback enables secretless session forgery and Marshal deserializationEPSS 0.3%CVE-2025-54573MEDIUMCVAT vulnerable to email verification bypass by use of basic authenticationEPSS 0.3%CVE-2026-14561MEDIUMAuthora - Easy Login with Mobile Number < 1.7.7 - Unauthenticated Account Takeover via OTP DisclosureEPSS 0.3%CVE-2022-29838MEDIUMAuthentication issue with the encrypted volumes and auto mount feature in My Cloud devicesEPSS 0.3%CVE-2024-37408HIGHfprintd through 1.94.3 lacks a security attention mechanism, and thus unexpected actions might be authorized by "auth sufficient pam_fprintdEPSS 0.3%CVE-2026-35261MEDIUMVulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that EPSS 0.3%CVE-2020-10709—A security flaw was found in Ansible Tower when requesting an OAuth2 token with an OAuth2 application. Ansible Tower uses the token to proviEPSS 0.3%CVE-2025-7095MEDIUMComodo Internet Security Premium Update certificate validationEPSS 0.3%CVE-2026-60434MEDIUMVulnerability in the Oracle Transportation Management product of Oracle Supply Chain (component: Authentication). The supported version thEPSS 0.3%CVE-2024-38426MEDIUMImproper Authentication in ModemEPSS 0.3%CVE-2025-48746MEDIUMNetwrix Directory Manager (formerly Imanami GroupID) v.11.0.0.0 and before, as well as after v.11.1.25134.03 lacks Authentication for a CritEPSS 0.3%CVE-2025-0813HIGHCWE-287: Improper Authentication vulnerability exists that could cause an Authentication Bypass when an unauthorized user without permissionEPSS 0.3%CVE-2024-23219MEDIUMThe issue was addressed with improved authentication. This issue is fixed in iOS 17.3 and iPadOS 17.3. Stolen Device Protection may be unexpEPSS 0.3%CVE-2022-34887MEDIUMStandard users can directly operate and set printer configuration information , such as IP, in some Lenovo Printers without having to authenEPSS 0.3%CVE-2025-9815HIGHalaneuler batteryKid NSXPCListener PrivilegeHelper.swift missing authenticationEPSS 0.3%CVE-2026-94612HIGHauthentik: Authentication bypass via assertion confusion in SAML sourcesEPSS 0.3%CVE-2025-8964MEDIUMcode-projects Hostel Management System Login hostel_manage.exe improper authenticationEPSS 0.3%CVE-2024-6174HIGHWhen a non-x86 platform is detected, cloud-init grants root access to a hardcoded url with a local IP address. To prevent this, cloud-init dEPSS 0.3%CVE-2023-52210MEDIUMWordPress Product Delivery Date for WooCommerce – Lite plugin <= 2.7.0 - Broken Access Control vulnerabilityEPSS 0.3%CVE-2024-20301MEDIUMA vulnerability in Cisco Duo Authentication for Windows Logon and RDP could allow an authenticated, physical attacker to bypass secondary auEPSS 0.3%