Weaknesses of type CWE-287

2,463 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2022-30749LOWImproper access control vulnerability in Smart Things prior to 1.7.85.25 allows local attackers to add arbitrary smart devices by bypassing EPSS 0.2%CVE-2022-45118MEDIUMTelephony in communication subsystem sends public events with personal data, but the permission is not set.EPSS 0.2%CVE-2023-28073HIGH Dell BIOS contains an improper authentication vulnerability. A locally authenticated malicious user may potentially exploit this vulnerabilEPSS 0.2%CVE-2022-37931HIGHA vulnerability in NetBatch-Plus software allows unauthorized access to the applicationEPSS 0.2%CVE-2026-86781MEDIUMSSL Zen < 4.7.40 - Subscriber+ TLS Private Key DisclosureEPSS 0.2%CVE-2022-33862MEDIUMImproper access control mechanism in IPPEPSS 0.2%CVE-2026-102364MEDIUMmall4j through 4.0 Improper Authentication Accepts Storefront Tokens on Admin APIEPSS 0.2%CVE-2026-40109LOWFlux notification-controller GCR Receiver missing email validation allows unauthorized reconciliation triggeringEPSS 0.2%CVE-2026-11717CRITICALAn authentication bypass vulnerability exists in the generic opaque token validation path (validateOpaqueToken) of googleapis/mcp-toolbox. EPSS 0.2%CVE-2022-45877HIGHPIN code is transmitted to the peer device in plain text during cross-device authentication, which reduces the difficulty of man-in-the-middle attacks.EPSS 0.2%CVE-2024-12310HIGHBypass of Login Screen on Shared Kiosk WorkstationsEPSS 0.2%CVE-2022-43900MEDIUMIBM WebSphere Automation for IBM Cloud Pak for Watson AIOps security bypassEPSS 0.2%CVE-2026-64745LOWThis issue was addressed with additional restrictions on the lock screen. This issue is fixed in macOS Sequoia 15.7.8, macOS Tahoe 26.6. A pEPSS 0.2%CVE-2023-31292MEDIUMAn issue was discovered in Sesami Cash Point & Transport Optimizer (CPTO) 6.3.8.6 (#718), allows local attackers to obtain sensitive informaEPSS 0.2%CVE-2022-26858MEDIUMDell BIOS versions contain an Improper Authentication vulnerability. A locally authenticated malicious user could potentially exploit this vEPSS 0.2%CVE-2026-61687HIGHhatchet - Unauthenticated OAuth state CSRF / login-CSRF via empty-state collision in ValidateOAuthStateEPSS 0.2%CVE-2025-41459HIGHInsecure authentication due to missing bruteforce protection and runtime manipulation in Two App Studio Journey 5.5.6 for iOSEPSS 0.2%CVE-2026-18759HIGHAn improper authentication and path traversal vulnerability exists in ASUSTOR Backup Plan and ASUSTOR EZ Sync.EPSS 0.2%CVE-2025-22236HIGHCVE-2025-22236 salt advisoryEPSS 0.2%CVE-2026-33248MEDIUMNATS has mTLS verify_and_map authentication bypass via incorrect Subject DN matchingEPSS 0.2%