Weaknesses of type CWE-287

2,435 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2022-39387CRITICALXWiki OIDC Authenticator vulnerable to OpenID login bypass due to improper authentication EPSS 1.0%CVE-2023-1460MEDIUMSourceCodester Online Pizza Ordering System Password Change improper authenticationEPSS 1.0%CVE-2025-58060HIGHcups has Authentication bypass with AuthType NegotiateEPSS 1.0%CVE-2024-12510MEDIUMLDAP Authentication Sever Pass-back attackEPSS 1.0%CVE-2017-6617—A vulnerability in the session identification management functionality of the web-based GUI of Cisco Integrated Management Controller (IMC) EPSS 1.0%CVE-2013-10004MEDIUMTelecommunication Software SAMwin Contact Center Suite Password SAMwinLIBVB.dll passwordScramble improper authenticationEPSS 1.0%CVE-2022-30238HIGHA CWE-287: Improper Authentication vulnerability exists that could allow an attacker to take over the admin account when an attacker hijacksEPSS 1.0%CVE-2021-34578CRITICALWAGO: Authentication Vulnerability in Web-Based ManagementEPSS 1.0%CVE-2017-20237CRITICALHirschmann Industrial HiVision Authentication Bypass Remote Code ExecutionEPSS 1.0%CVE-2023-25264HIGHAn issue was discovered in Docmosis Tornado prior to version 2.9.5. An unauthenticated attacker can bypass the authentication check filter cEPSS 1.0%CVE-2022-1084HIGHSourceCodester One Church Management System Session userregister.php improper authenticationEPSS 1.0%CVE-2026-23600CRITICALA remote authentication bypass vulnerability  exists in HPE AutoPass License Server (APLS).EPSS 1.0%CVE-2024-5044MEDIUMEmlog Pro Cookie improper authenticationEPSS 1.0%CVE-2022-34155HIGHWordPress OAuth Single Sign On – SSO (OAuth Client) Plugin <= 6.23.3 is vulnerable to Broken AuthenticationEPSS 1.0%CVE-2023-28862CRITICALAn issue was discovered in LemonLDAP::NG before 2.16.1. Weak session ID generation in the AuthBasic handler and incorrect failure handling dEPSS 1.0%CVE-2021-4230LOWAirfield Online MySQL Backup improper authenticationEPSS 1.0%CVE-2022-47633HIGHAn image signature validation bypass vulnerability in Kyverno 1.8.3 and 1.8.4 allows a malicious image registry (or a man-in-the-middle attaEPSS 1.0%CVE-2022-4002HIGHA command injection vulnerability could allow an authenticated user to execute operating system commands as root via a specially crafted APIEPSS 1.0%CVE-2026-3794MEDIUMdoramart DoraCMS Email API send improper authenticationEPSS 1.0%CVE-2021-28174MEDIUMMitake Smart Stock Selection System - Broken AuthenticationEPSS 1.0%