Weaknesses of type CWE-287

2,430 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2017-9939—A vulnerability was discovered in Siemens SiPass integrated (All versions before V2.70) that could allow an attacker with network access to EPSS 2.1%CVE-2022-29165CRITICALArgo CD will blindly trust JWT claims if anonymous access is enabledEPSS 2.1%CVE-2017-12196MEDIUMundertow before versions 1.4.18.SP1, 2.0.2.Final, 1.4.24.Final was found vulnerable when using Digest authentication, the server does not enEPSS 2.0%CVE-2026-0558HIGHUnauthenticated File Upload in parisneo/lollmsEPSS 2.0%CVE-2018-0382MEDIUMCisco Wireless LAN Controller Software Session Hijacking VulnerabilityEPSS 2.0%CVE-2017-12316—A vulnerability in the Guest Portal login page of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to peEPSS 2.0%CVE-2019-18284—A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). The AdminService is available wEPSS 2.0%CVE-2022-36436CRITICALOSU Open Source Lab VNCAuthProxy through 1.1.1 is affected by an vncap/vnc/protocol.py VNCServerAuthenticator authentication-bypass vulnerabEPSS 2.0%CVE-2017-7930—An Improper Authentication issue was discovered in OSIsoft PI Server 2017 PI Data Archive versions prior to 2017. PI Data Archive has protocEPSS 2.0%CVE-2024-48445CRITICALAn issue in compop.ca ONLINE MALL v.3.5.3 allows a remote attacker to execute arbitrary code via the rid, tid, et, and ts parameters.EPSS 2.0%CVE-2020-27780—A flaw was found in Linux-Pam in versions prior to 1.5.1 in the way it handle empty passwords for non-existing users. When the user doesn't EPSS 2.0%CVE-2026-4252CRITICALTenda AC8 IPv6 check_is_ipv6 ip address for authenticationEPSS 2.0%CVE-2022-1049—A flaw was found in the Pacemaker configuration tool (pcs). The pcs daemon was allowing expired accounts, and accounts with expired passwordEPSS 2.0%CVE-2017-12225—A vulnerability in the web functionality of the Cisco Prime LAN Management Solution could allow an authenticated, remote attacker to hijack EPSS 2.0%CVE-2021-38161—Not validating origin TLS certificateEPSS 1.9%CVE-2026-53595CRITICALFreeScout vulnerable to anonymous account takeover via /user-setup empty invite_hash on MySQLEPSS 1.9%CVE-2024-23465HIGHSolarWinds Access Rights Manager (ARM) ChangeHumster Exposed Dangerous Method Authentication Bypass VulnerabilityEPSS 1.9%CVE-2024-28992HIGHSolarWinds Access Rights Manager Directory Traversal and Information Disclosure VulnerabilityEPSS 1.9%CVE-2026-15981CRITICALSAML Single Sign On <= 5.4.4 - Unauthenticated Authentication Bypass via SAMLResponse ParameterEPSS 1.9%CVE-2021-22764MEDIUMA CWE-287: Improper Authentication vulnerability exists in PowerLogic PM55xx, PowerLogic PM8ECC, PowerLogic EGX100 and PowerLogic EGX300 (seEPSS 1.9%