Weaknesses of type CWE-287

2,463 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2025-61679HIGHAnyquery Unauthenticated Access Vulnerability Exposes Private Integration DataEPSS 0.2%CVE-2022-48575LOWA person with access to a Mac may be able to bypass Login Window. A consistency issue was addressed with improved state handling. This issueEPSS 0.2%CVE-2026-15384MEDIUMManual Image Crop < 1.15 - Subscriber+ Arbitrary Attachment Image Overwrite via IDOREPSS 0.2%CVE-2023-21437MEDIUMImproper access control vulnerability in Phone application prior to SMR Feb-2023 Release 1 allows local attackers to access sensitive informEPSS 0.2%CVE-2023-21425MEDIUMImproper access control vulnerability in telecom application prior to SMR JAN-2023 Release 1 allows local attackers to get sensitive informaEPSS 0.2%CVE-2023-21484MEDIUMImproper access control vulnerability in AppLock prior to SMR May-2023 Release 1 allows local attackers without proper permission to executeEPSS 0.1%CVE-2024-24279HIGHAn issue in secdiskapp 1.5.1 (management program for NewQ Fingerprint Encryption Super Speed Flash Disk) allows attackers to gain escalated EPSS 0.1%CVE-2025-43281HIGHThe issue was addressed with improved authentication. This issue is fixed in macOS Sequoia 15.6. A local attacker may be able to elevate theEPSS 0.1%CVE-2026-20885HIGHImproper authentication in the Intel(R) TDX module for some Intel(R) platforms within Ring 0: Trust Domain may allow an information disclosuEPSS 0.1%CVE-2026-1568CRITICALRapid7 InsightVM Signature Validation VulnerabilityEPSS 0.1%CVE-2023-21487MEDIUMImproper access control vulnerability in Telephony framework prior to SMR May-2023 Release 1 allows local attackers to change a call settingEPSS 0.1%CVE-2023-41751MEDIUMSensitive information disclosure due to improper token expiration validation. The following products are affected: Acronis Agent (Windows) bEPSS 0.1%CVE-2025-53169HIGHVulnerability of bypassing the process to start SA and use related functions on distributed cameras Impact: Successful exploitation of this EPSS 0.1%CVE-2023-33070HIGHImproper Authentication in Automotive OSEPSS 0.1%CVE-2022-33242HIGHImproper authentication in Qualcomm IPCEPSS 0.1%CVE-2025-25201MEDIUMImproper Validation of Admin Key in PIV SmartcardEPSS 0.1%CVE-2022-41737HIGHIBM Spectrum Scale security bypassEPSS 0.1%CVE-2026-10548MEDIUMNousResearch hermes-agent Credential Pool Synchronization credential_pool.py _sync_anthropic_entry_from_credentials_file improper authenticationEPSS 0.1%CVE-2022-48305MEDIUMThere is an identity authentication bypass vulnerability in Huawei Children Smart Watch (Simba-AL00) 1.1.1.274. Successful exploitation of tEPSS 0.1%CVE-2026-20752MEDIUMImproper authentication for some Intel(R) PROSet/Wireless WiFi Software within Ring 0: Kernel may allow an information disclosure. System soEPSS 0.1%