Weaknesses of type CWE-287

2,432 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2021-33539HIGHWEIDMUELLER: WLAN devices affected by authentication bypass vulnerabilityEPSS 1.1%CVE-2022-25027HIGHThe Forgotten Password functionality of Rocket TRUfusion Portal v7.9.2.1 allows remote attackers to bypass authentication and access restricEPSS 1.1%CVE-2023-39349HIGHSentry vulnerable to privilege escalation via ApiTokensEndpointEPSS 1.1%CVE-2025-4268MEDIUMTOTOLINK A720R cstecgi.cgi missing authenticationEPSS 1.1%CVE-2020-8148—UniFi Cloud Key firmware < 1.1.6 contains a vulnerability that enables an attacker being able to change a device hostname by sending a malicEPSS 1.1%CVE-2022-44244MEDIUMAn authentication bypass in Lin-CMS v0.2.1 allows attackers to escalate privileges to Super Administrator.EPSS 1.1%CVE-2019-14910CRITICALA vulnerability was found in keycloak 7.x, when keycloak is configured with LDAP user federation and StartTLS is used instead of SSL/TLS froEPSS 1.1%CVE-2022-36092HIGHXWiki Platform Old Core vulnerable to Authentication Bypass Using the Login ActionEPSS 1.1%CVE-2026-23906CRITICALApache Druid: Authentication Bypass via LDAP Anonymous BindEPSS 1.1%CVE-2019-18318—A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker with network accessEPSS 1.1%CVE-2019-18317—A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker with network accessEPSS 1.1%CVE-2024-30299CRITICALTenable Vulnerability Disclosure | API Auth BypassEPSS 1.1%CVE-2019-18319—A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker with network accessEPSS 1.1%CVE-2025-64513CRITICALMilvus Proxy has Critical Authentication Bypass VulnerabilityEPSS 1.0%CVE-2023-41264CRITICALNetwrix Usercube before 6.0.215, in certain misconfigured on-premises installations, allows authentication bypass on deployment endpoints, lEPSS 1.0%CVE-2020-16102HIGHImproper Authentication vulnerability in Gallagher Command Centre Server allows an unauthenticated remote attacker to create items with invaEPSS 1.0%CVE-2022-43620HIGHThis vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-1935 1.03 routers. AutEPSS 1.0%CVE-2022-45173CRITICALAn issue was discovered in LIVEBOX Collaboration vDesk through v018. A Bypass of Two-Factor Authentication can occur under the /api/v1/vdeskEPSS 1.0%CVE-2021-32794MEDIUMAccidental removal of IPCPassword (< 5.1.2.4)EPSS 1.0%CVE-2022-45174CRITICALAn issue was discovered in LIVEBOX Collaboration vDesk through v018. A Bypass of Two-Factor Authentication for SAML Users can occur under thEPSS 1.0%