Weaknesses of type CWE-287

2,463 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2021-25343MEDIUMCalling of non-existent provider in Samsung Members prior to version 2.4.81.13 (in Android O(8.1) and below) and 3.8.00.13 (in Android P(9.0EPSS 0.2%CVE-2021-25342MEDIUMCalling of non-existent provider in SMP sdk prior to version 3.0.9 allows unauthorized actions including denial of service attack by hijackiEPSS 0.2%CVE-2021-25341MEDIUMCalling of non-existent provider in S Assistant prior to version 6.5.01.22 allows unauthorized actions including denial of service attack byEPSS 0.2%CVE-2026-81703HIGHopenssl_encrypt before 1.4.9 Authentication Bypass via Unencrypted PQC KeyEPSS 0.2%CVE-2026-47202CRITICALKavita: Pre-Auth Account TakeoverEPSS 0.2%CVE-2025-11130HIGHiHongRen pptp-vpn XPC Service HelperTool.m shouldAcceptNewConnection missing authenticationEPSS 0.2%CVE-2020-36548MEDIUMGE Voluson S8 Service Browser users.cgi improper authenticationEPSS 0.2%CVE-2025-29906HIGHFinit bundled getty can bypass /bin/loginEPSS 0.2%CVE-2026-9084MEDIUMMISP OIDC authentication bypass via automatic email-based account linking under insecure IdP configurationsEPSS 0.2%CVE-2025-54154MEDIUMQNAP AuthenticatorEPSS 0.2%CVE-2026-71416HIGHHeadroom vulnerable to Cross-Site WebSocket Hijacking (CSWSH)EPSS 0.2%CVE-2025-10672HIGHwhuan132 AIBattery com.collweb.AIBatteryHelper BatteryXPCService.swift missing authenticationEPSS 0.2%CVE-2025-0981HIGHSession Hijacking via Stored Cross-Site Scripting (XSS) in ChurchCRM GroupEditor.php Description FieldEPSS 0.2%CVE-2025-10906HIGHMagnetism Studios Endurance NSXPC com.MagnetismStudios.endurance.helper loadModuleNamed:WithReply missing authenticationEPSS 0.2%CVE-2021-28493HIGHIn Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, a user may be abEPSS 0.2%CVE-2026-56294MEDIUMcapacitor-native-biometric - Authentication Bypass via Unvalidated CryptoObject in onAuthenticationSucceededEPSS 0.2%CVE-2026-12112HIGHForeman-mcp-server: mcp server: active session hijacking via insecure session state reuseEPSS 0.2%CVE-2026-54510HIGHSpeakr: CSRF bypass via unauthenticated API token parameter in csrf_exempt_for_api_tokens hookEPSS 0.2%CVE-2024-22247MEDIUMVMware SD-WAN Edge contains a missing authentication and protection mechanism vulnerability. A malicious actor with physical access to the EPSS 0.2%CVE-2025-0672LOWAuthentication Bypass in Multiple WSO2 Products via Stale FIDO Credential AssociationEPSS 0.2%