Weaknesses of type CWE-287

2,431 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2021-39215HIGHAuthentication Bypass: Forged Tokens Allow Access to Arbitrary RoomsEPSS 1.2%CVE-2021-22858HIGHChanGate EnterPrise Co., Ltd property management system - Broken AuthenticationEPSS 1.2%CVE-2018-3775—Improper Authentication in Nextcloud Server prior to version 12.0.3 would allow an attacker that obtained user credentials to bypass the 2 FEPSS 1.2%CVE-2023-24831CRITICALApache IoTDB grafana-connector Login Bypass VulnerabilityEPSS 1.2%CVE-2024-6248HIGHWyze Cam v3 Cloud Infrastructure Improper Authentication Remote Code Execution VulnerabilityEPSS 1.2%CVE-2023-6248CRITICALData leakage and arbitrary remote code execution in Syrus cloud devicesEPSS 1.2%CVE-2026-65400CRITICALAn authentication issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.7.9, macEPSS 1.2%KEVCVE-2023-6483CRITICALImproper Authentication Vulnerability in ADiTaaS EPSS 1.2%CVE-2024-49076HIGHWindows Virtualization-Based Security (VBS) Enclave Elevation of Privilege VulnerabilityEPSS 1.2%CVE-2019-6527—PR100088 Modbus gateway versions prior to Release R02 (or Software Version 1.1.13166) may allow an attacker to be able to change the passworEPSS 1.2%CVE-2021-41312HIGHAffected versions of Atlassian Jira Server and Data Center allow a remote attacker who has had their access revoked from Jira Service ManageEPSS 1.2%CVE-2026-1368HIGHVideo Conferencing with Zoom API < 4.6.6 - Unauthenticated SDK Signature GenerationEPSS 1.2%CVE-2022-46145HIGHauthentik vulnerable to unauthorized user creation and potential account takeoverEPSS 1.2%CVE-2020-24675CRITICALWeak Authentication in Symphony PlusEPSS 1.2%CVE-2023-6907MEDIUMcodelyfe Stupid Simple CMS Deletion Interface delete.php improper authenticationEPSS 1.2%CVE-2022-46146MEDIUMPrometheus Exporter Toolkit vulnerable to basic authentication bypassEPSS 1.2%CVE-2021-43444HIGHONLYOFFICE all versions as of 2021-11-08 is affected by Incorrect Access Control. Signed document download URLs can be forged due to a weak EPSS 1.2%CVE-2021-22796—A CWE-287: Improper Authentication vulnerability exists that could allow remote code execution when a malicious file is uploaded. Affected PEPSS 1.2%CVE-2020-15243CRITICALWebApi Authentication attribute missing in SmartstoreEPSS 1.2%CVE-2022-2133—OAuth Single Sign On < 6.22.6 - Authentication BypassEPSS 1.2%