Weaknesses of type CWE-287

2,437 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2014-125060HIGHholdennb CollabCal calenderServer.cpp handleGet improper authenticationEPSS 1.0%CVE-2021-26077CRITICALBroken Authentication in Atlassian Connect Spring Boot (ACSB) in version 1.1.0 before 2.1.3 and from version 2.1.4 before 2.1.5: Atlassian CEPSS 1.0%CVE-2022-36106MEDIUMMissing check for expiration time of password reset token in TYPO3EPSS 0.9%CVE-2020-26236HIGHVerification Code Hijacking in ScratchVerifierEPSS 0.9%CVE-2022-22730CRITICALImproper authentication in the Intel(R) Edge Insights for Industrial software before version 2.6.1 may allow an unauthenticated user to poteEPSS 0.9%CVE-2025-5495MEDIUMNetgear WNR614 URL improper authenticationEPSS 0.9%CVE-2021-32951MEDIUMAdvantech WebAccess/NMS Improper AuthenticationEPSS 0.9%CVE-2023-22303CRITICALTP-Link SG105PE firmware prior to 'TL-SG105PE(UN) 1.0_1.0.0 Build 20221208' contains an authentication bypass vulnerability. Under the certaEPSS 0.9%CVE-2023-31127CRITICALDMTF-2023-0001: SPDM mutual authentication bypassEPSS 0.9%CVE-2026-62827HIGHMicrosoft SharePoint Server Elevation of Privilege VulnerabilityEPSS 0.9%CVE-2023-6343MEDIUMTyler Technologies Court Case Management Plus use of Aquaforest TIFF Server tssp.aspx allows authentication bypassEPSS 0.9%CVE-2023-6344MEDIUMTyler Technologies Court Case Management Plus use of Aquaforest TIFF Server te003.aspx and te004.aspx allows authentication bypassEPSS 0.9%CVE-2018-7340HIGHMultiple SAML libraries may allow authentication bypass via incorrect XML canonicalization and DOM traversalEPSS 0.9%CVE-2021-28495HIGHIn Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, user authenticatEPSS 0.9%CVE-2023-0311MEDIUMImproper Authentication in thorsten/phpmyfaqEPSS 0.9%CVE-2021-44057HIGHImproper authentication in Photo StationEPSS 0.9%CVE-2018-0247—A vulnerability in Web Authentication (WebAuth) clients for the Cisco Wireless LAN Controller (WLC) and Aironet Access Points running Cisco EPSS 0.9%CVE-2021-44056HIGHImproper authentication in Video StationEPSS 0.9%CVE-2023-40660MEDIUMOpensc: potential pin bypass when card tracks its own login stateEPSS 0.9%CVE-2026-62825CRITICALAzure Key Vault Elevation of Privilege VulnerabilityEPSS 0.9%