Weaknesses of type CWE-287

2,432 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2023-1778CRITICALDefault Credential Vulnerability in GajShield Data Security FirewallEPSS 1.1%CVE-2023-25601—Apache DolphinScheduler 3.0.0 to 3.1.1 python gateway has improper authenticationEPSS 1.1%CVE-2020-10916HIGHThis vulnerability allows network-adjacent attackers to escalate privileges on affected installations of TP-Link TL-WA855RE Firmware Ver: 85EPSS 1.1%CVE-2024-34340CRITICALAuthentication Bypass when using using older password hashesEPSS 1.1%CVE-2023-44302HIGH Dell DM5500 5.14.0.0 and prior contain an improper authentication vulnerability. A remote unauthenticated attacker could potentially exploiEPSS 1.1%CVE-2021-3046MEDIUMPAN-OS: Improper SAML Authentication Vulnerability in GlobalProtect PortalEPSS 1.1%CVE-2026-8305MEDIUMOpenClaw bluebubbles Webhook monitor.ts handleBlueBubblesWebhookRequest improper authenticationEPSS 1.1%CVE-2019-18906CRITICALcryptctl: client side password hashing is equivalent to clear text password storageEPSS 1.1%CVE-2019-14880MEDIUMA vulnerability was found in Moodle versions 3.7 before 3.7.3, 3.6 before 3.6.7, 3.5 before 3.5.9 and earlier. OAuth 2 providers who do not EPSS 1.1%CVE-2025-37093CRITICALAn authentication bypass vulnerability exists in HPE StoreOnce Software.EPSS 1.1%CVE-2023-52161HIGHThe Access Point functionality in eapol_auth_key_handle in eapol.c in iNet wireless daemon (IWD) before 2.14 allows attackers to gain unauthEPSS 1.1%CVE-2022-38119CRITICALPOWERCOM CO., LTD. UPSMON PRO - Broken AuthenticationEPSS 1.1%CVE-2026-5229CRITICALReceive Notifications After Form Submitting – Form Notify for Any Forms <= 1.1.10 - Unauthenticated Authentication Bypass via LINE OAuth CallbackEPSS 1.1%CVE-2022-20733MEDIUMCisco Identity Services Engine Authentication Bypass VulnerabilityEPSS 1.1%CVE-2023-2024CRITICALImproper Authentication for OpenBlue Enterprise Manager Data CollectorEPSS 1.1%CVE-2018-0435—Cisco Umbrella API Unauthorized Access VulnerabilityEPSS 1.1%CVE-2023-29032HIGHApache OpenMeetings: allows bypass authenticationEPSS 1.1%CVE-2025-11942MEDIUM70mai X200 Pairing missing authenticationEPSS 1.1%CVE-2021-41126HIGHDeleted Admin Can Sign In to Admin InterfaceEPSS 1.1%CVE-2022-2765MEDIUMSourceCodester Company Website CMS settings improper authenticationEPSS 1.1%