Weaknesses of type CWE-287

2,431 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2020-36533LOWKlapp App JSON Web Token improper authenticationEPSS 1.5%CVE-2026-78167CRITICALEFM ipTIME T16000M Session Validation httpcon_check_session_url improper authenticationEPSS 1.5%CVE-2023-29463HIGHPavilion8 Security Misconfiguration VulnerabilityEPSS 1.5%CVE-2020-8272—Authentication Bypass resulting in exposure of SD-WAN functionality in Citrix SD-WAN Center versions before 11.2.2, 11.1.2b and 10.2.8EPSS 1.5%CVE-2022-39042CRITICALaEnrich a+HRD - Improper AuthenticationEPSS 1.5%CVE-2019-6832—A CWE-287: Authentication vulnerability exists in spaceLYnk (all versions before 2.4.0) and Wiser for KNX (all versions before 2.4.0 - formeEPSS 1.5%CVE-2021-21329HIGHMulti Factor Authentication Token Improperly Validated On User LoginEPSS 1.5%CVE-2019-1724HIGHCisco Small Business RV320 and RV325 Routers Session Hijacking VulnerabilityEPSS 1.5%CVE-2023-47504MEDIUMWordPress Elementor plugin <= 3.16.4 - Auth. Arbitrary Attachment Read vulnerabilityEPSS 1.5%CVE-2025-1723HIGHAccount takeoverEPSS 1.4%CVE-2021-23847CRITICALUnauthenticated Information Extraction VulnerabilityEPSS 1.4%CVE-2022-31013CRITICALAuthentication bypass in Vartalap chat-serverEPSS 1.4%CVE-2019-1946MEDIUMCisco Enterprise NFV Infrastructure Software Web-Based Management Interface Authentication Bypass VulnerabilityEPSS 1.4%CVE-2022-43504MEDIUMImproper authentication vulnerability in WordPress versions prior to 6.0.3 allows a remote unauthenticated attacker to obtain the email addrEPSS 1.4%CVE-2023-41999CRITICALArcserve UDP Management Authentication Bypass EPSS 1.4%CVE-2022-37913CRITICALVulnerabilities in the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow an unauthenticated remote attEPSS 1.4%CVE-2022-37914CRITICALVulnerabilities in the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow an unauthenticated remote attEPSS 1.4%CVE-2023-34340CRITICALApache Accumulo: Accumulo 2.1.0 may incorrectly validate cached credentialsEPSS 1.4%CVE-2021-39177HIGHUser impersonation due to incorrect handling of the login JWTEPSS 1.4%CVE-2026-82693CRITICALTenda AC1206 Web UI telnet TendaTelnet missing authenticationEPSS 1.4%