Weaknesses of type CWE-287

2,463 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2025-2230HIGHPhilips Intellispace Cardiovascular (ISCV) Improper AuthenticationEPSS 0.2%CVE-2026-34123HIGHWhitelist Validation Bypass in TP-Link Tapo C520WSEPSS 0.2%CVE-2025-27425MEDIUMQR code user confirmation bypass with invalid protocolEPSS 0.2%CVE-2025-53013MEDIUMHimmelblau offline auth permits authentication with invalid Hello PINEPSS 0.2%CVE-2021-25451LOWA PendingIntent hijacking in NetworkPolicyManagerService prior to SMR Sep-2021 Release 1 allows attackers to get IMSI data.EPSS 0.2%CVE-2023-28646MEDIUMApp lockout in nextcloud Android app can be bypassed via thirdparty appsEPSS 0.2%CVE-2026-45289MEDIUMCloudburstMC Protocol: Partially missing validation for FULL type authentication tokensEPSS 0.2%CVE-2026-57175MEDIUMsocial-auth-core has an Improper Authentication issueEPSS 0.2%CVE-2026-40205MEDIUMAn attacker that holds an OAuth2 token granting only part of the required scopes can authenticate, because when more than one scope is requiEPSS 0.2%CVE-2026-49454CRITICALRelyra SAML SignatureValue not cryptographically verified -> authentication bypassEPSS 0.2%CVE-2026-19718HIGHBlogVault, MalCare and WP Remote 5.16 - 6.62 - Unauthenticated Site Takeover via Connection Key RecoveryEPSS 0.2%CVE-2026-43674MEDIUMAn authentication issue was addressed with improved state management. This issue is fixed in iOS 27 and iPadOS 27. An attacker with physicalEPSS 0.2%CVE-2021-25342MEDIUMCalling of non-existent provider in SMP sdk prior to version 3.0.9 allows unauthorized actions including denial of service attack by hijackiEPSS 0.2%CVE-2022-22284MEDIUMImproper authentication vulnerability in Samsung Internet prior to 16.0.2.19 allows attackers to bypass secret mode password authenticationEPSS 0.2%CVE-2021-25341MEDIUMCalling of non-existent provider in S Assistant prior to version 6.5.01.22 allows unauthorized actions including denial of service attack byEPSS 0.2%CVE-2021-25343MEDIUMCalling of non-existent provider in Samsung Members prior to version 2.4.81.13 (in Android O(8.1) and below) and 3.8.00.13 (in Android P(9.0EPSS 0.2%CVE-2022-25825MEDIUMImproper access control vulnerability in Samsung Account prior to version 13.1.0.1 allows attackers to access to the authcode for sign-in.EPSS 0.2%CVE-2026-47202CRITICALKavita: Pre-Auth Account TakeoverEPSS 0.2%CVE-2026-81703HIGHopenssl_encrypt before 1.4.9 Authentication Bypass via Unencrypted PQC KeyEPSS 0.2%CVE-2020-36548MEDIUMGE Voluson S8 Service Browser users.cgi improper authenticationEPSS 0.2%