Weaknesses of type CWE-287

2,431 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2023-2706HIGHOTP Login Woocommerce & Gravity Forms <= 2.2 - Authentication Bypass to Privilege EscalationEPSS 1.7%CVE-2020-25165—BD Alaris PC Unit, Model 8015, Versions 9.33.1 and earlier and BD Alaris Systems Manager, Versions 4.33 and earlier The affected products arEPSS 1.7%CVE-2021-21378HIGHJWT authentication bypass with unknown issuer tokenEPSS 1.7%CVE-2021-43445CRITICALONLYOFFICE all versions as of 2021-11-08 is affected by Incorrect Access Control. An attacker can authenticate with the web socket service oEPSS 1.7%CVE-2020-8253—Improper authentication in Citrix XenMobile Server 10.12 before RP2, Citrix XenMobile Server 10.11 before RP4, Citrix XenMobile Server 10.10EPSS 1.7%CVE-2022-35925MEDIUMMissing rate limit in Authentication in bookwyrmEPSS 1.7%CVE-2020-25719—A flaw was found in the way Samba, as an Active Directory Domain Controller, implemented Kerberos name-based authentication. The Samba AD DCEPSS 1.7%CVE-2021-36368LOWAn issue was discovered in OpenSSH before 8.9. If a client is using public-key authentication with agent forwarding but without -oLogLevel=vEPSS 1.7%CVE-2025-26326HIGHA vulnerability was identified in the NVDA Remote (version 2.6.4) and Tele NVDA Remote (version 2025.3.3) remote connection add-ons, which aEPSS 1.7%CVE-2019-20464HIGHAn issue was discovered on Sannce Smart HD Wifi Security Camera EAN 2 950004 595317 devices. By default, a mobile application is used to strEPSS 1.7%CVE-2022-23635HIGHUnauthenticated control plane denial of service attack in IstioEPSS 1.7%CVE-2019-14856MEDIUMansible before versions 2.8.6, 2.7.14, 2.6.20 is vulnerable to a NoneEPSS 1.7%CVE-2021-21335MEDIUMBasic Authentication can be bypassed using a malformed usernameEPSS 1.7%CVE-2018-5387—Wizkunde SAMLBase may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be aEPSS 1.7%CVE-2018-3761—Nextcloud Server before 12.0.8 and 13.0.3 suffer from improper authentication on the OAuth2 token endpoint. Missing checks potentially allowEPSS 1.7%CVE-2020-15136MEDIUMImproper authentication in etcdEPSS 1.6%CVE-2026-44551CRITICALOpen WebUI: LDAP Empty Password Authentication BypassEPSS 1.6%CVE-2019-15585—Improper authentication exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE) in the GitEPSS 1.6%CVE-2022-22935LOWAn issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. A minion authentication denial of service can cause a MEPSS 1.6%CVE-2019-18341MEDIUMA vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0). The SFTP service (default port 22/tcp) of the CoEPSS 1.6%