Weaknesses of type CWE-287

2,432 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2020-16098CRITICALIt is possible to enumerate access card credentials via an unauthenticated network connection to the server in versions of Command Centre v8EPSS 1.1%CVE-2021-3827—A flaw was found in keycloak, where the default ECP binding flow allows other authentication flows to be bypassed. By exploiting this behaviEPSS 1.1%CVE-2026-53913CRITICALApache Camel Keycloak: KeycloakSecurityPolicy verifies the bearer access token only inside its role and permission checks, so in the default configuration the token is never verified and any non-null bearer value is acceptedEPSS 1.1%CVE-2026-25893CRITICALFUXA Unauthenticated Remote Code Execution via Admin JWT MintingEPSS 1.1%CVE-2024-23629CRITICALMotorola MR2600 Authentication Bypass VulnerabilityEPSS 1.1%CVE-2022-42458CRITICALAuthentication bypass using an alternate path or channel vulnerability in bingo!CMS version1.7.4.1 and earlier allows a remote unauthenticatEPSS 1.1%CVE-2019-18312—A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 ServEPSS 1.1%CVE-2019-14909CRITICALA vulnerability was found in Keycloak 7.x where the user federation LDAP bind type is none (LDAP anonymous bind), any password, invalid or vEPSS 1.1%CVE-2025-7862MEDIUMTOTOLINK T6 Telnet Service cstecgi.cgi setTelnetCfg missing authenticationEPSS 1.1%CVE-2026-32173HIGHAzure SRE Agent Information Disclosure VulnerabilityEPSS 1.1%CVE-2017-12712—The authentication algorithm in Abbott Laboratories pacemakers manufactured prior to Aug 28, 2017, which involves an authentication key and EPSS 1.1%CVE-2022-24738HIGHAccount compromise in EvmosEPSS 1.1%CVE-2015-10083MEDIUMharrystech Dynosaur-Rails application_controller.rb basic_auth improper authenticationEPSS 1.1%CVE-2019-18320—A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker with network accessEPSS 1.1%CVE-2022-40602CRITICALA flaw in the Zyxel LTE3301-M209 firmware verisons prior to V1.00(ABLG.6)C0 could allow a remote attacker to access the device using an imprEPSS 1.1%CVE-2020-15269HIGHExpired token reuse in SpreeEPSS 1.1%CVE-2022-39249HIGHMatrix Javascript SDK vulnerable to impersonation via forwarded Megolm sessionsEPSS 1.1%CVE-2024-20738CRITICALAdobe FrameMaker Publishing Server Authentication Bypass Vulnerability | CVE-2023-44324 bypassEPSS 1.1%CVE-2023-2283—A vulnerability was found in libssh, where the authentication check of the connecting client can be bypassed in the`pki_verify_data_signaturEPSS 1.1%CVE-2018-0116—A vulnerability in the RADIUS authentication module of Cisco Policy Suite could allow an unauthenticated, remote attacker to be authorized aEPSS 1.1%