Weaknesses of type CWE-287

2,435 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2026-5570MEDIUMTechnostrobe HI-LED-WR120-G2 LoginCB index_config improper authenticationEPSS 1.0%CVE-2021-39138MEDIUMNew anonymous user session acts as if it's created with passwordEPSS 1.0%CVE-2020-10754MEDIUMIt was found that nmcli, a command line interface to NetworkManager did not honour 802-1x.ca-path and 802-1x.phase2-ca-path settings, when cEPSS 1.0%CVE-2020-3197MEDIUMCisco Meetings App Missing TURN Server Credentials Expiration VulnerabilityEPSS 1.0%CVE-2023-6353MEDIUMTyler Technologies Civil and Criminal Electronic Filing Upload.aspx allows authentication bypassEPSS 1.0%CVE-2023-6354MEDIUMTyler Technologies Magistrate Court Case Management Plus PDFViewer.aspx allows authentication bypassEPSS 1.0%CVE-2022-31686CRITICALVMware Workspace ONE Assist prior to 22.10 contains a Broken Authentication Method vulnerability. A malicious actor with network access to WEPSS 1.0%CVE-2021-0193HIGHImproper authentication in the Intel(R) In-Band Manageability software before version 2.13.0 may allow a privileged user to potentially enabEPSS 1.0%CVE-2026-75429CRITICALPowerJob versions 4.x through 5.1.2 contain an unauthenticated remote code execution vulnerability in the /friend/process endpoint of the SeEPSS 1.0%CVE-2023-7210HIGHOneNav API improper authenticationEPSS 1.0%CVE-2025-27112MEDIUMNavidrome has authentication bypass in Subsonic API with non-existent usernameEPSS 1.0%CVE-2023-6768CRITICALAuthentication bypass vulnerability in Amazing Little PollEPSS 1.0%CVE-2022-23769HIGHSecuever reverseWall-MDS Remote Code Execution VulnerabilityEPSS 1.0%CVE-2022-39251HIGHMatrix Javascript SDK vulnerable to Olm/Megolm protocol confusionEPSS 1.0%CVE-2026-76187CRITICALApache Airflow Keycloak provider: Any realm client's credentials mint an Airflow session JWTEPSS 1.0%CVE-2021-43834CRITICALIncorrect Authentication in elabftwEPSS 1.0%CVE-2024-0988MEDIUMSichuan Yougou Technology KuERP common.php checklogin improper authenticationEPSS 1.0%CVE-2021-38686HIGHImproper Authentication Vulnerability in VioStorEPSS 1.0%CVE-2026-58399HIGH@acastellon/auth has an authentication bypass via spoofable headers in validateToken()EPSS 1.0%CVE-2024-10511MEDIUMCWE-287: Improper Authentication vulnerability exists that could cause Denial of access to the web interface when someone on the local netwoEPSS 1.0%