Weaknesses of type CWE-287

2,431 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2021-26620HIGHIPTIME NAS2dual improper authentication vulnerabilityEPSS 1.4%CVE-2021-31917—A flaw was found in Red Hat DataGrid 8.x (8.0.0, 8.0.1, 8.1.0 and 8.1.1) and Infinispan (10.0.0 through 12.0.0). An attacker could bypass auEPSS 1.3%CVE-2025-53793HIGHAzure Stack Hub Information Disclosure VulnerabilityEPSS 1.3%CVE-2024-23471CRITICALSolarWinds Access Rights Manager (ARM) CreateFile Directory Traversal Remote Code Execution VulnerabilityEPSS 1.3%CVE-2021-38412CRITICALDigi PortServer TS 16 Improper AuthenticationEPSS 1.3%CVE-2026-94493CRITICALGigatech PDV5701 WebSocket Service index.html missing authenticationEPSS 1.3%CVE-2019-3798MEDIUMEscalation of Privileges in Cloud ControllerEPSS 1.3%CVE-2019-10966—In GE Aestiva and Aespire versions 7100 and 7900, a vulnerability exists where serial devices are connected via an added unsecured terminal EPSS 1.3%CVE-2026-78168CRITICALEFM ipTIME T24000M Session Validation httpcon_check_session_url improper authenticationEPSS 1.3%CVE-2026-19977CRITICALEFM ipTIME A3004T Session Validation httpcon_check_session_url improper authenticationEPSS 1.3%CVE-2023-24830HIGHApache IoTDB Workbench: apache/iotdb-web-workbench: create a user without authorizationEPSS 1.3%CVE-2008-3738CRITICALSession fixation vulnerability in SpaceTag LacoodaST 2.1.3 and earlier allows remote attackers to hijack web sessions via unspecified vectorEPSS 1.3%CVE-2020-8200—Improper authentication in Citrix StoreFront Server < 1912.0.1000 allows an attacker who is authenticated on the same Microsoft Active DirecEPSS 1.3%CVE-2021-40851HIGHTCMAN GIM SQL injection vulnerabilityEPSS 1.3%CVE-2025-6763CRITICALComet System H3531 Web-based Management setupA.cfg missing authenticationEPSS 1.3%CVE-2020-2018CRITICALPAN-OS: Panorama authentication bypass vulnerabilityEPSS 1.3%CVE-2026-22594HIGHGhost has Staff 2FA bypassEPSS 1.3%CVE-2020-14494—OpenClinic GA versions 5.09.02 and 5.89.05b contain an authentication mechanism within the system that does not provide sufficient complexitEPSS 1.3%CVE-2016-0796—WordPress Plugin mb.miniAudioPlayer-an HTML5 audio player for your mp3 files is prone to multiple vulnerabilities, including open proxy and EPSS 1.3%CVE-2022-2141CRITICALICSA-22-200-01 MiCODUS MV720 GPS tracker Improper AuthenticationEPSS 1.3%