Weaknesses of type CWE-287

2,463 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2026-59208HIGHn8n: Cross-Issuer Token Exchange Account Binding via Subject-Only Identity ResolutionEPSS 0.3%CVE-2018-25030LOWMirmay Secure Private Browser / File Manager Auto Lock improper authenticationEPSS 0.3%CVE-2024-13088MEDIUMQHoraEPSS 0.3%CVE-2024-7956HIGHSensitive Data Exposure and Escalating Privileges Vulnerabilities in DataMosaix™ Private CloudEPSS 0.3%CVE-2026-42008MEDIUMForwarding information received from a host listed as a trusted proxy is not kept separate from Dovecot's own authentication fields, so a vaEPSS 0.3%CVE-2026-4587MEDIUMHybridAuth SSL Curl.php certificate validationEPSS 0.3%CVE-2025-25452MEDIUMAn issue in TAAGSOLUTIONS GmbH MyTaag v.2024-11-24 and before allows a remote attacker to escalate privileges via the "/user" endpointEPSS 0.3%CVE-2025-25450MEDIUMAn issue in TAAGSOLUTIONS GmbH MyTaag v.2024-11-24 and before allows a remote attacker to escalate privileges via the deactivation of the acEPSS 0.3%CVE-2025-59704HIGHEntrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow an attaEPSS 0.3%CVE-2025-11633MEDIUMTomofun Furbo 360/Furbo Mini HTTP Traffic collect_logs.sh upload_file_to_s3 certificate validationEPSS 0.3%CVE-2026-19842HIGHSAML Single Sign On 4.8.85 - 5.4.6 - Unauthenticated Administrator Account Takeover via SAML Trust Anchor OverwriteEPSS 0.3%CVE-2025-3634MEDIUMMoodle: moodle allows course self-enrolment before completing mfaEPSS 0.3%CVE-2024-38822LOWCVE-2024-38822 Salt AdvisoryEPSS 0.3%CVE-2026-17013MEDIUMWP Photo Album Plus < 9.2.07.002 - Reflected XSS via lbstartEPSS 0.3%CVE-2026-73726MEDIUMAuthentication Bypass in HPE Networking Fabric Composer allows Unauthorized Administrative AccessEPSS 0.3%CVE-2026-19766CRITICALAuthentication Bypass leads to Administrative control of adjacent network hosts in HPE Networking Fabric ComposerEPSS 0.3%CVE-2024-13309MEDIUMLogin Disable - Critical - Access bypass - SA-CONTRIB-2024-073EPSS 0.3%CVE-2023-43551CRITICALImproper Authentication in Multi-Mode Call ProcessorEPSS 0.3%CVE-2025-2572MEDIUMWhatsUp Gold NmConfigurationManager.exe database manipulation vulnerabilityEPSS 0.3%CVE-2025-65925MEDIUMAn issue was discovered in Zeroheight (SaaS) prior to 2025-06-13. A legacy user creation API pathway allowed accounts to be created without EPSS 0.3%