Weaknesses of type CWE-287

2,430 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2021-25315CRITICALsalt-api unauthenticated remote code executionEPSS 2.3%CVE-2014-0769—Festo CECX-X-(C1/M1) Controller Improper AuthenticationEPSS 2.3%CVE-2017-9625—An Improper Authentication issue was discovered in Envitech EnviDAS Ultimate Versions prior to v1.0.0.5. The web application lacks proper auEPSS 2.3%CVE-2019-18314—A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker with network accessEPSS 2.3%CVE-2022-21618MEDIUMVulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JGSS). Supported versions that EPSS 2.3%CVE-2017-14000—An Improper Authentication issue was discovered in Ctek SkyRouter Series 4200 and 4400, all versions prior to V6.00.11. By accessing a speciEPSS 2.3%CVE-2022-31020HIGHRemote code execution in Indy's NODE_UPGRADE transactionEPSS 2.3%CVE-2021-35029CRITICALAn authentication bypasss vulnerability in the web-based management interface of Zyxel USG/Zywall series firmware versions 4.35 through 4.64EPSS 2.3%CVE-2023-28125MEDIUMAn improper authentication vulnerability exists in Avalanche Premise versions 6.3.x and below that could allow an attacker to gain access toEPSS 2.3%CVE-2022-41912CRITICALcrewjam/saml go library is vulnerable to signature bypass via multiple Assertion elementsEPSS 2.2%CVE-2026-11387CRITICALSMS Alert <= 3.9.5 - Unauthenticated Privilege Escalation via Arbitrary Password ResetEPSS 2.2%CVE-2018-4835—A vulnerability has been identified in TeleControl Server Basic < V3.1. An attacker with network access to the TeleControl Server Basic's poEPSS 2.2%CVE-2022-37298CRITICALShinken Solutions Shinken Monitoring Version 2.4.3 affected is vulnerable to Incorrect Access Control. The SafeUnpickler class found in shinEPSS 2.2%CVE-2022-22576HIGHAn improper authentication vulnerability exists in curl 7.33.0 to and including 7.82.0 which might allow reuse OAUTH2-authenticated connectiEPSS 2.2%CVE-2020-10888MEDIUMThis vulnerability allows remote attackers to bypass authentication on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC17EPSS 2.2%CVE-2017-7934—An Improper Authentication issue was discovered in OSIsoft PI Server 2017 PI Data Archive versions prior to 2017. PI Network Manager using oEPSS 2.1%CVE-2021-20288—An authentication flaw was found in ceph in versions before 14.2.20. When the monitor handles CEPHX_GET_AUTH_SESSION_KEY requests, it doesn'EPSS 2.1%CVE-2022-22990HIGHLimited authentication bypass vulnerability on Western Digital My Cloud devicesEPSS 2.1%CVE-2024-57046HIGHA vulnerability in the Netgear DGN2200 router with firmware version v1.0.0.46 and earlier permits unauthorized individuals to bypass the autEPSS 2.1%CVE-2026-49869CRITICALKestra: Unauthenticated Remote Code Execution via Authentication Bypass in `AuthenticationFilter`EPSS 2.1%KEV