Weaknesses of type CWE-287

2,463 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2023-42935MEDIUMAn authentication issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.6.4. A local attacker may be aEPSS 0.2%CVE-2025-0249LOWHCL IEM is affected by an improper invalidation of access or JWT token vulnerabilityEPSS 0.2%CVE-2023-31189MEDIUMImproper authentication in some Intel(R) Server Product OpenBMC firmware before version egs-1.09 may allow an authenticated user to enable eEPSS 0.2%CVE-2026-101042HIGHParse Server 9.0.0 Authentication Bypass via Unverified Provider IdentityEPSS 0.2%CVE-2026-0633LOWMetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor <= 4.1.0 - Unauthenticated Form Submission Exposure via Forgeable Cookie ValueEPSS 0.2%CVE-2022-48254MEDIUMThere is a data processing error vulnerability in Leia-B29 2.0.0.49(M03). Successful exploitation could bypass lock screen authentication.EPSS 0.2%CVE-2026-40205MEDIUMAn attacker that holds an OAuth2 token granting only part of the required scopes can authenticate, because when more than one scope is requiEPSS 0.2%CVE-2026-44711HIGHpam_usb: Symlink attacks on pad directory and pad files enable authentication bypass and root file corruptionEPSS 0.2%CVE-2026-86890MEDIUMA logic issue was addressed with improved checks. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27. An attacker with phEPSS 0.2%CVE-2025-67859MEDIUMPolkit Authorization Check can be Bypassed in the TLP power daemonEPSS 0.2%CVE-2021-25377LOWIntent redirection in Samsung Experience Service versions 10.8.0.4 in Android P(9.0) below, and 12.2.0.5 in Android Q(10.0) above allows attEPSS 0.2%CVE-2025-25451MEDIUMAn issue in TAAGSOLUTIONS GmbH MyTaag v.2024-11-24 and before allows a physically proximate attacker to escalate privileges via the "2fa_autEPSS 0.2%CVE-2026-34204HIGHMinIO is Vulnerable to SSE Metadata Injection via Replication HeadersEPSS 0.2%CVE-2022-28790MEDIUMImproper authentication in Link to Windows Service prior to version 2.3.04.1 allows attacker to lock the device. The patch adds proper calleEPSS 0.2%CVE-2025-52294MEDIUMInsufficient validation of the screen lock mechanism in Trust Wallet v8.45 allows physically proximate attackers to bypass the lock screen aEPSS 0.2%CVE-2024-39767MEDIUMSpoofed push notifications from malicious serverEPSS 0.2%CVE-2023-20924MEDIUMIn (TBD) of (TBD), there is a possible way to bypass the lockscreen due to Biometric Auth Failure. This could lead to local escalation of prEPSS 0.2%CVE-2026-45153MEDIUMNextcloud: PIN bypass in PassCodeActivity via back buttonEPSS 0.2%CVE-2022-22283LOWImproper session management vulnerability in Samsung Health prior to 6.20.1.005 prevents logging out from Samsung Health App.EPSS 0.2%CVE-2026-43766MEDIUMAn authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOSEPSS 0.2%