Weaknesses of type CWE-287

2,463 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2019-6854—A CWE-287: Improper Authentication vulnerability exists in a folder within EcoStruxure Geo SCADA Expert (ClearSCADA) -with initial releases EPSS 0.2%CVE-2025-64517MEDIUMsudo-rs doesn't record authenticating user properly in timestampEPSS 0.2%CVE-2026-47272HIGHpam_usb: OTP pad authentication bypass via missing system pad check and uninitialized RNG bufferEPSS 0.2%CVE-2025-32875MEDIUMAn issue was discovered in the COROS application through 3.8.12 for Android. Bluetooth pairing and bonding is neither initiated nor enforcedEPSS 0.2%CVE-2025-65431MEDIUMAn issue was discovered in allauth-django before 65.13.0. Both Okta and NetIQ were using preferred_username as the identifier for third-partEPSS 0.2%CVE-2024-9133MEDIUMA user with administrator privileges is able to retrieve authentication tokensEPSS 0.2%CVE-2024-4601MEDIUMImproper Authentication vulnerability in Socomec Net VisionEPSS 0.2%CVE-2021-3784MEDIUMGaruda Linux Improper AuthorizationEPSS 0.2%CVE-2026-96456MEDIUMReachy Mini Bluetooth PIN authentication can be bypassed by racing an authenticated deviceEPSS 0.2%CVE-2026-57178HIGHsocial-auth-core: VK App backend accepts unsigned callback data when auth_key is missingEPSS 0.2%CVE-2025-26475MEDIUMDell Secure Connect Gateway (SCG) 5.0 Appliance - SRS, version(s) 5.26, Enables Live-Restore setting which enhances security by keeping contEPSS 0.2%CVE-2021-25430—Improper access control vulnerability in Bluetooth application prior to SMR July-2021 Release 1 allows untrusted application to access the BEPSS 0.2%CVE-2026-39969MEDIUMTypeBot: WhatsApp Webhook Endpoint Missing Signature VerificationEPSS 0.2%CVE-2022-37345HIGHImproper authentication in BIOS firmware[A1] for some Intel(R) NUC Kits before version RY0386 may allow an authenticated user to potentiallyEPSS 0.2%CVE-2022-36370HIGHImproper authentication in BIOS firmware for some Intel(R) NUC Boards and Intel(R) NUC Kits before version MYi30060 may allow a privileged uEPSS 0.2%CVE-2023-21460MEDIUMImproper authentication in SecSettings prior to SMR Mar-2023 Release 1 allows attacker to reset the setting.EPSS 0.2%CVE-2025-20083HIGHImproper authentication in the firmware for the Intel(R) Slim Bootloader may allow a privileged user to potentially enable escalation of priEPSS 0.2%CVE-2024-36266HIGHA vulnerability has been identified in PowerSys (All versions < V3.11). The affected application insufficiently protects responses to authenEPSS 0.2%CVE-2025-48909HIGHBypass vulnerability in the device management channel Impact: Successful exploitation of this vulnerability may affect service confidentialiEPSS 0.2%CVE-2024-38825MEDIUMCVE-2024-38825 Salt AdvisoryEPSS 0.2%