Weaknesses of type CWE-287

2,463 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2026-65329MEDIUMAn authentication issue was addressed with improved state management. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, iOS 27 and iPadOSEPSS 0.2%CVE-2026-96445MEDIUMKeycloak-services: keycloak-services: conditional otp skip-header policy evaluated against untrusted proxy headersEPSS 0.2%CVE-2024-24554MEDIUMBludit - Insecure Token GenerationEPSS 0.2%CVE-2025-9265CRITICALAPI Authentication Bypass via Header Spoofing vulnerability in Kiloview NDI N30 ProductsEPSS 0.2%CVE-2021-3458MEDIUMThe Motorola MM1000 device configuration portal can be accessed without authentication, which could allow adapter settings to be modified.EPSS 0.2%CVE-2025-0663MEDIUMPotential cross-tenant account takeover vulnerability in Multiple WSO2 Products via Adaptive Authentication and Auto-LoginEPSS 0.2%CVE-2026-3194LOWChia Blockchain RPC Server Master Passphrase get_private_key missing authenticationEPSS 0.2%CVE-2022-3681MEDIUMA vulnerability has been identified in the MR2600 router v1.0.18 and earlier that could allow an attacker within range of the wireless netwoEPSS 0.2%CVE-2026-33246MEDIUMNATS: Leafnode connections allow spoofing of Nats-Request-Info identity headersEPSS 0.2%CVE-2023-32453MEDIUM Dell BIOS contains an improper authentication vulnerability. A malicious user with physical access to the system may potentially exploit thEPSS 0.2%CVE-2021-3519MEDIUMA vulnerability was reported in some Lenovo Desktop models that could allow unauthorized access to the boot menu, when the "BIOS Password AtEPSS 0.2%CVE-2026-75973HIGHApache Tomcat: Cross-context authentication mix-up with Jakarta Authentication configuredEPSS 0.2%CVE-2025-15484CRITICALOrder Notification for WooCommerce < 3.6.3 - Unauthenticated WooCommerce REST Permission BypassEPSS 0.2%CVE-2023-21419MEDIUMAn improper implementation logic in Secure Folder prior to SMR Jan-2023 Release 1 allows the Secure Folder container remain unlocked under cEPSS 0.2%CVE-2025-24904HIGHlibsignal-service-rs doesn't sanity check plaintext envelopes are not sanity-checkedEPSS 0.2%CVE-2024-52968MEDIUMAn improper authentication in Fortinet FortiClientMac 7.0.11 through 7.2.4 allows attacker to gain improper access to MacOS via empty passwoEPSS 0.2%CVE-2022-39245HIGHMist vulnerable to user providing a Sudo binary for authentication checksEPSS 0.2%CVE-2026-55962MEDIUMTLS 1.3 post-handshake authentication: server accepts Finished without client Certificate/CertificateVerifyEPSS 0.2%CVE-2022-27874MEDIUMImproper authentication in some Intel(R) XMM(TM) 7560 Modem software before version M2_7560_R_01.2146.00 may allow a privileged user to poteEPSS 0.2%CVE-2026-12526HIGHAdvanced Custom Fields: Extended < 0.9.2.7 - Unauthenticated Administrator Account Takeover via Front-End User Update ActionEPSS 0.2%