Weaknesses of type CWE-287

2,431 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2020-27254—Emerson Rosemount X-STREAM Gas AnalyzerX-STREAM enhanced XEGP, XEGK, XEFD, XEXF – all revisions, The affected products are vulnerable to impEPSS 1.3%CVE-2026-45434CRITICALApache OFBiz: Authentication Bypass via Password-Change Logic Flaw Leading to RCEEPSS 1.3%CVE-2021-41265HIGHImproper Authentication in Flask-AppBuilderEPSS 1.3%CVE-2024-38099MEDIUMWindows Remote Desktop Licensing Service Denial of Service VulnerabilityEPSS 1.3%CVE-2018-4856—A vulnerability has been identified in SICLOCK TC100 (All versions) and SICLOCK TC400 (All versions). An attacker with administrative accessEPSS 1.3%CVE-2019-12254CRITICALTECSON/GOK: Improper Authentication and Access Control on multiple devicesEPSS 1.3%CVE-2024-21390HIGHMicrosoft Authenticator Elevation of Privilege VulnerabilityEPSS 1.3%CVE-2020-14504MEDIUMThe web interface of the 1734-AENTR communication module mishandles authentication for HTTP POST requests. A remote, unauthenticated attackeEPSS 1.3%CVE-2020-8267—A security issue was found in UniFi Protect controller v1.14.10 and earlier.The authentication in the UniFi Protect controller API was usingEPSS 1.3%CVE-2024-22245CRITICALArbitrary Authentication Relay Vulnerability in Deprecated EAP Browser PluginEPSS 1.3%CVE-2023-37471CRITICALUser impersonation using SAMLv1.x SSO in Open Access Management EPSS 1.3%CVE-2018-0195—A vulnerability in the Cisco IOS XE Software REST API could allow an authenticated, remote attacker to bypass API authorization checks and uEPSS 1.3%CVE-2021-39196HIGHAuthenticated non-privileged user can request unfiltered data without adequate permissions in pcaptureEPSS 1.3%CVE-2023-0773CRITICALUnauthorized Access Control Vulnerability in Uniview IP CameraEPSS 1.3%CVE-2022-2553—The authfile directive in the booth config file is ignored, preventing use of authentication in communications from node to node. As a resulEPSS 1.3%CVE-2024-45115CRITICALAdobe Commerce | Improper Authentication (CWE-287)EPSS 1.3%CVE-2024-36132HIGHInsufficient verification of authentication controls in EPMM prior to 12.1.0.1 allows a remote attacker to bypass authentication and access EPSS 1.2%CVE-2023-45038MEDIUMMusic StationEPSS 1.2%CVE-2023-48228HIGHOAuth2: PKCE can be fully circumventedEPSS 1.2%CVE-2007-1966CRITICALSession fixation vulnerability in eXV2 CMS 2.0.4.3 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID cookiEPSS 1.2%