Weaknesses of type CWE-287

2,463 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2025-1880LOWi-Drive i11/i12 Device Pairing authentication bypassEPSS 0.3%CVE-2024-27835LOWThis issue was addressed through improved state management. This issue is fixed in iOS 17.5 and iPadOS 17.5. An attacker with physical accesEPSS 0.3%CVE-2026-0408MEDIUMPath traversal vulnerability in Netgear WiFi Range ExtendersEPSS 0.3%CVE-2026-14541HIGHAuthentication Bypass and Audience Confusion in MCP Toolbox OAuth ProviderEPSS 0.3%CVE-2025-31264MEDIUMAn authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS EPSS 0.3%CVE-2026-16892MEDIUMIBM i is Affected By An Improper Authentication Vulnerability in Network Authentication Service []EPSS 0.3%CVE-2025-41110HIGHImproper Authentication vulnerability in Ghost Robotics' Vision 60EPSS 0.3%CVE-2026-0407MEDIUMAuthentication bypass in NETGEAR WiFi Range Extenders via network adjacent attacksEPSS 0.3%CVE-2026-11366LOWMonsterInsights < 11.1.0 - Unauthenticated Measurement Protocol Secret Update via Empty-Key HMAC BypassEPSS 0.2%CVE-2022-39901MEDIUMImproper authentication in Exynos baseband prior to SMR DEC-2022 Release 1 allows remote attacker to disable the network traffic encryption EPSS 0.2%CVE-2026-54781HIGHCoreWCF: SAML SubjectConfirmation methods and holder-of-key proof keys are not enforcedEPSS 0.2%CVE-2026-60357LOWVulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: Siebel Server Sync for Exchange). Supported versions tEPSS 0.2%CVE-2020-12035—Baxter PrismaFlex all versions, PrisMax all versions prior to 3.x, The PrismaFlex device contains a hard-coded service password that provideEPSS 0.2%CVE-2025-68663MEDIUMOutline has a suspended user authentication bypass via WebSocket connectionsEPSS 0.2%CVE-2026-22764MEDIUMDell OpenManage Network Integration, versions prior to 3.9, contains an Improper Authentication vulnerability. A low privileged attacker witEPSS 0.2%CVE-2025-62398MEDIUMMoodle: possible to bypass mfaEPSS 0.2%CVE-2026-56727HIGHZammad: PGP signature spoofing via unvalidated verification returnEPSS 0.2%CVE-2024-38639MEDIUMQTSEPSS 0.2%CVE-2025-7630MEDIUMOTP Password Brute Forcing in DorukNet's WispotterEPSS 0.2%CVE-2025-6083MEDIUMExtremeCloud Universal ZTNA Improper AuthorizationEPSS 0.2%