Weaknesses of type CWE-287

2,430 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2017-7546—PostgreSQL versions before 9.2.22, 9.3.18, 9.4.13, 9.5.8 and 9.6.4 are vulnerable to incorrect authentication flaw allowing remote attackersEPSS 61.6%CVE-2015-7755CRITICALJuniper ScreenOS 6.2.0r15 through 6.2.0r18, 6.3.0r12 before 6.3.0r12b, 6.3.0r13 before 6.3.0r13b, 6.3.0r14 before 6.3.0r14b, 6.3.0r15 beforeEPSS 61.1%KEVCVE-2023-5830HIGHColumbiaSoft Document Locator WebTools login improper authenticationEPSS 60.8%CVE-2023-42442HIGHJumpServer session replays download without authenticationEPSS 58.5%CVE-2023-4415HIGHRuijie RG-EW1200G login improper authenticationEPSS 58.3%CVE-2022-24422CRITICALDell iDRAC9 versions 5.00.00.00 and later but prior to 5.10.10.00, contain an improper authentication vulnerability. A remote unauthenticateEPSS 57.8%CVE-2021-27651CRITICALIn versions 8.2.1 through 8.5.2 of Pega Infinity, the password reset functionality for local accounts can be used to bypass local authenticaEPSS 53.8%CVE-2024-26331HIGHReCrystallize Server 5.10.0.0 uses a authorization mechanism that relies on the value of a cookie, but it does not bind the cookie value to EPSS 51.3%CVE-2024-2862CRITICALPassword reset vulnerability without authorization on LG LED AssistantEPSS 51.0%CVE-2020-12812CRITICALAn improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6.2.3, 6.0.9 and below may result in a user being able to logEPSS 49.3%KEVCVE-2023-50919CRITICALAn issue was discovered on GL.iNet devices before version 4.5.0. There is an NGINX authentication bypass via Lua string pattern matching. ThEPSS 47.8%CVE-2025-53778HIGHWindows NTLM Elevation of Privilege VulnerabilityEPSS 47.6%CVE-2021-22893CRITICALPulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication bypass vulnerability exposed by the Windows File Share BrowseEPSS 47.2%KEVCVE-2024-8181CRITICALFlowise Authentication BypassEPSS 45.1%CVE-2024-3080CRITICALASUS Router - Improper AuthenticationEPSS 43.5%CVE-2023-49105CRITICALAn issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker can access, modify, or delete any file without authentication EPSS 43.2%KEVCVE-2022-42233CRITICALTenda 11N with firmware version V5.07.33_cn suffers from an Authentication Bypass vulnerability.EPSS 42.7%CVE-2021-37580—Apache ShenYu Admin bypass JWT authenticationEPSS 41.9%CVE-2022-25369CRITICALAn issue was discovered in Dynamicweb before 9.12.8. An attacker can add a new administrator user without authentication. This flaw exists dEPSS 40.0%CVE-2025-32815MEDIUMAn issue was discovered in Infoblox NETMRI before 7.6.1. Authentication Bypass via a Hardcoded credential can occur.EPSS 39.7%