Weaknesses of type CWE-287

2,434 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2022-29883MEDIUMA vulnerability has been identified in SICAM T (All versions < V3.0). Affected devices do not restrict unauthenticated access to certain pagEPSS 1.0%CVE-2026-28323CRITICALSolarWinds Web Help Desk SAML Authentication Bypass VulnerabilityEPSS 1.0%CVE-2022-34379CRITICALDell EMC CloudLink 7.1.2 and all prior versions contain an Authentication Bypass Vulnerability. A remote attacker, with the knowledge of theEPSS 1.0%CVE-2023-2586CRITICAL Teltonika’s Remote Management System versions 4.14.0 is vulnerable to an unauthorized attacker registering previously unregistered devices EPSS 1.0%CVE-2023-31007NONEApache Pulsar: Broker does not always disconnect client when authentication data expiresEPSS 1.0%CVE-2023-27582CRITICALFull authentication bypass if SASL authorization username is specifiedEPSS 1.0%CVE-2022-36073HIGHRubyGems allows creation of users with arbitrary unverified emailsEPSS 1.0%CVE-2026-12773MEDIUMBerriAI litellm MCP Proxy user_api_key_auth_mcp.py UserAPIKeyAuth improper authenticationEPSS 1.0%CVE-2022-31685CRITICALVMware Workspace ONE Assist prior to 22.10 contains an Authentication Bypass vulnerability. A malicious actor with network access to WorkspaEPSS 1.0%CVE-2024-36264CRITICALApache Submarine Commons Utils: default secretEPSS 1.0%CVE-2026-3053MEDIUMDataLinkDC dinky OpenAPI Endpoint AppConfig.java addInterceptors missing authenticationEPSS 1.0%CVE-2022-24813MEDIUMAuthentication Bypass Using an Alternate Path or Channel in CreateWikiEPSS 1.0%CVE-2026-62144CRITICALManagement Authentication Bypass and Privilege EscalationEPSS 1.0%CVE-2023-50275HIGHHPE OneView may allow clusterService Authentication Bypass resulting in denial of service.EPSS 1.0%CVE-2020-1718HIGHA flaw was found in the reset credential flow in all Keycloak versions before 8.0.0. This flaw allows an attacker to gain unauthorized accesEPSS 1.0%CVE-2020-16239MEDIUMPhilips SureSigns VS4 Improper AuthenticationEPSS 1.0%CVE-2022-39250HIGHMatrix JavaScript SDK vulnerable to key/device identifier confusion in SAS verificationEPSS 1.0%CVE-2023-1784MEDIUMjeecg-boot API Documentation improper authenticationEPSS 1.0%CVE-2022-2336CRITICALSofting Secure Integration Server Improper AuthenticationEPSS 1.0%CVE-2022-1101HIGHSourceCodester Royale Event Management System userregister.php improper authenticationEPSS 1.0%