Weaknesses of type CWE-287

2,463 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2023-28377MEDIUMImproper authentication in some Intel(R) NUC Kit NUC11PH USB firmware installation software before version 1.1 for Windows may allow an authEPSS 0.2%CVE-2026-39411MEDIUMLobeHub has an unauthenticated authentication bypass on `webapi` routes via forgeable `X-lobe-chat-auth` headerEPSS 0.2%CVE-2026-20683HIGHAn authentication issue was addressed with improved state management. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, macEPSS 0.2%CVE-2026-82843CRITICALWP OAuth Server < 6.4.0 - Subscriber+ Cross-User Account Takeover via OIDC ID Token SubstitutionEPSS 0.2%CVE-2026-55626HIGHxrdp: No authentication required with Xvnc backend on RHEL 9EPSS 0.2%CVE-2026-12504HIGHLoytec LINX firmware: Improper Authentication in PAM configurationEPSS 0.2%CVE-2023-26455MEDIUMRMI was not requiring authentication when calling ChronosRMIService:setEventOrganizer. Attackers with local or adjacent network access couldEPSS 0.2%CVE-2025-31267MEDIUMAn authentication issue was addressed with improved state management. This issue is fixed in App Store Connect 3.0. An attacker with physicaEPSS 0.2%CVE-2025-64434MEDIUMKubeVirt Improper TLS Certificate Management Handling Allows API Identity SpoofingEPSS 0.2%CVE-2026-11718CRITICALAn authentication bypass vulnerability exists in the generic opaque token validation path (validateOpaqueToken) of googleapis/mcp-toolbox. EPSS 0.2%CVE-2026-33314MEDIUMpyload-ng: Improper Authentication and Origin Validation ErrorEPSS 0.2%CVE-2026-48991MEDIUMXianYuLauncher: Legacy Microsoft account OAuth sign-in flow lacks PKCE and state validationEPSS 0.2%CVE-2022-2752MEDIUMPotential vulnerabilities in GM login processEPSS 0.2%CVE-2023-0036MEDIUMplatform_callback_stub in misc subsystem has an authentication bypass vulnerability which allows an "SA relay attack".EPSS 0.2%CVE-2021-33159HIGHImproper authentication in subsystem for Intel(R) AMT before versions 11.8.93, 11.22.93, 11.12.93, 12.0.92, 14.1.67, 15.0.42, 16.1.25 may alEPSS 0.2%CVE-2023-0035MEDIUMsoftbus_client_stub in communication subsystem has an authentication bypass vulnerability which allows an "SA relay attack".EPSS 0.2%CVE-2026-84091MEDIUMSUMIT Payment Gateway for WooCommerce < 4.0.0 - Unauthenticated Payment Confirmation Forgery via bit IPNEPSS 0.2%CVE-2022-42488HIGHStartup subsystem missed permission validation in param service. An malicious application installed on the device could elevate its privileges to the root user, disable security features, or cause DoS by disabling particular services.EPSS 0.2%CVE-2026-34990MEDIUMOpenPrinting CUPS: Local print admin token disclosure using temporary printersEPSS 0.2%CVE-2026-40995MEDIUMX.509 authentication bypasses Spring Security account checksEPSS 0.2%