Weaknesses of type CWE-287

2,431 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2026-82693CRITICALTenda AC1206 Web UI telnet TendaTelnet missing authenticationEPSS 1.4%CVE-2026-19924CRITICALTenda AC10 httpd R7WebsSecurityHandler improper authenticationEPSS 1.4%CVE-2019-19104CRITICALABB/Busch-Jaeger Telephone Gateway TG/S 3.2 Improper Authentication and Access ControlEPSS 1.4%CVE-2026-82695CRITICALTenda AC18 Telnet telnet missing authenticationEPSS 1.4%CVE-2017-12195MEDIUMA flaw was found in all Openshift Enterprise versions using the openshift elasticsearch plugin. An attacker with knowledge of the given nameEPSS 1.4%CVE-2022-23652HIGHPrivilege escalation using hop-by-hop Connection headerEPSS 1.4%CVE-2022-35248—A improper authentication vulnerability exists in Rocket.Chat <v5, <v4.8.2 and <v4.7.5 that allowed two factor authentication can be bypasseEPSS 1.4%CVE-2019-10150MEDIUMIt was found that OpenShift Container Platform versions 3.6.x - 4.6.0 does not perform SSH Host Key checking when using ssh key authenticatiEPSS 1.4%CVE-2022-28666MEDIUMWordPress Custom Product Tabs for WooCommerce plugin <= 1.7.7 - Broken Access Control vulnerabilityEPSS 1.4%CVE-2021-32693MEDIUMAuthentication granted with multiple firewallsEPSS 1.4%CVE-2021-1542HIGHCisco Small Business 220 Series Smart Switches VulnerabilitiesEPSS 1.4%CVE-2023-37918MEDIUMAPI token authentication bypass in HTTP endpoints in DaprEPSS 1.4%CVE-2019-11272—PlaintextPasswordEncoder authenticates encoded passwords that are nullEPSS 1.4%CVE-2020-14299—A flaw was found in JBoss EAP, where the authentication configuration is set-up using a legacy SecurityRealm, to delegate to a legacy PicketEPSS 1.4%CVE-2023-44324CRITICALZDI-CAN-21344: Adobe FrameMaker Publishing Server Authentication Bypass VulnerabilityEPSS 1.4%CVE-2023-36004HIGHWindows DPAPI (Data Protection Application Programming Interface) Spoofing VulnerabilityEPSS 1.4%CVE-2024-38225HIGHMicrosoft Dynamics 365 Business Central Elevation of Privilege VulnerabilityEPSS 1.4%CVE-2024-27923HIGHRemote Code Execution by uploading a phar file using frontmatterEPSS 1.4%CVE-2022-1248HIGHSAP Information System POST Request add_admin.php improper authenticationEPSS 1.4%CVE-2023-37544HIGHApache Pulsar WebSocket Proxy: Improper Authentication for WebSocket Proxy Endpoint Allows DoSEPSS 1.4%