Weaknesses of type CWE-287

2,430 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2026-20127CRITICALCisco Catalyst SD-WAN Controller Authentication Bypass VulnerabilityEPSS 88.2%KEVCVE-2022-0540CRITICALA vulnerability in Jira Seraph allows a remote, unauthenticated attacker to bypass authentication by sending a specially crafted HTTP requesEPSS 88.1%CVE-2023-28121—An issue in WooCommerce Payments plugin for WordPress (versions 5.6.1 and lower) allows an unauthenticated attacker to send requests on behaEPSS 86.5%CVE-2022-41678—Apache ActiveMQ: Insufficient API restrictions on Jolokia allow authenticated users to perform RCEEPSS 85.8%CVE-2026-50751CRITICALUser Authentication Bypass in VPN Remote Access and Mobile AccessEPSS 83.8%KEVCVE-2015-1187CRITICALThe ping tool in multiple D-Link and TRENDnet devices allow remote attackers to execute arbitrary code via the ping_addr parameter to ping.cEPSS 82.9%KEVCVE-2023-38096CRITICALNETGEAR ProSAFE Network Management System MyHandlerInterceptor Authentication Bypass VulnerabilityEPSS 82.0%CVE-2024-5806CRITICALMOVEit Transfer Authentication Bypass VulnerabilityEPSS 81.5%CVE-2023-27351HIGHThis vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). AuthenticEPSS 78.1%KEVCVE-2021-41303—Apache Shiro before 1.8.0, when using Apache Shiro with Spring Boot, a specially crafted HTTP request may cause an authentication bypassEPSS 76.7%CVE-2019-1937CRITICALCisco Integrated Management Controller Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data Authentication Bypass VulnerabilityEPSS 75.9%CVE-2023-32243CRITICALWordPress Essential Addons for Elementor Plugin 5.4.0-5.7.1 is vulnerable to Privilege EscalationEPSS 75.5%CVE-2025-1044CRITICALLogsign Unified SecOps Platform Authentication Bypass VulnerabilityEPSS 75.3%CVE-2024-28255CRITICALAuthentication Bypass in OpenMetadataEPSS 73.3%CVE-2023-27482CRITICALhomeassistant is an open source home automation tool. A remotely exploitable vulnerability bypassing authentication for accessing the SupervEPSS 72.2%CVE-2026-16232CRITICALAuthentication Bypass in the SmartConsole Login Process Using an Application TokenEPSS 72.1%KEVCVE-2020-4427CRITICALIBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 could allow a remote attacker to bypass security restrictions when configEPSS 70.0%KEVCVE-2020-26214CRITICALLDAP authentication bypass in AlertaEPSS 65.9%CVE-2023-6329CRITICALControl iD iDSecure passwordCustom Authentication BypassEPSS 65.0%CVE-2022-44574—An improper authentication vulnerability exists in Avalanche version 6.3.x and below allows unauthenticated attacker to modify properties onEPSS 64.8%