Weaknesses of type CWE-287

2,437 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2026-17142CRITICALVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.9%CVE-2021-37172—A vulnerability has been identified in SIMATIC S7-1200 CPU family (incl. SIPLUS variants) (V4.5.0). Affected devices fail to authenticate agEPSS 0.9%CVE-2024-6057CRITICALImproper authentication in the vault password feature in Devolutions Remote Desktop Manager 2024.1.31.0 and earlier allows an attacker that EPSS 0.9%CVE-2025-2339MEDIUMotale Tale Blog logs improper authenticationEPSS 0.9%CVE-2022-2662CRITICALSequi PortBloque S Improper AuthenticationEPSS 0.9%CVE-2023-20214CRITICALA vulnerability in the request authentication validation for the REST API of Cisco SD-WAN vManage software could allow an unauthenticated, rEPSS 0.9%CVE-2021-26073HIGHBroken Authentication in Atlassian Connect Express (ACE) from version 3.0.2 before version 6.6.0: Atlassian Connect Express is a Node.js pacEPSS 0.9%CVE-2022-36960HIGHSolarWinds Platform Improper Input ValidationEPSS 0.9%CVE-2026-75816CRITICALFrontend Admin by DynamiApps <= 3.29.12 - Unauthenticated Account Takeover via '_acf_objects' Object IdentifierEPSS 0.9%CVE-2023-34388MEDIUMImproper authentication could lead to session hijackingEPSS 0.9%CVE-2024-46434HIGHTenda W18E V16.01.0.8(1625) suffers from authentication bypass in the web management portal allowing an unauthorized remote attacker to gainEPSS 0.9%CVE-2023-5970—Improper authentication in the SMA100 SSL-VPN virtual office portal allows a remote authenticated attacker to create an identical external dEPSS 0.9%CVE-2024-34103HIGHCustomer account takeover via web API call & subsequent password resetEPSS 0.9%CVE-2024-39340HIGHThe authentication system of Securepoint UTM mishandles OTP keys. This allows the bypassing of second-factor verification (when OTP is enablEPSS 0.9%CVE-2025-2771MEDIUMBEC Technologies Multiple Routers Authentication Bypass VulnerabilityEPSS 0.9%CVE-2022-39229MEDIUMGrafana users with email as a username can block other users from signing inEPSS 0.9%CVE-2022-39038HIGHFLOWRING Agentflow BPM - Broken Access ControlEPSS 0.9%CVE-2022-39366CRITICALDataHub missing JWT signature checkEPSS 0.9%CVE-2026-34072HIGHcronmaster: Middleware authentication bypass enabling unauthorized page access and server-action executionEPSS 0.9%CVE-2026-41574CRITICALNhost Vulnerable to Account Takeover via OAuth Email Verification BypassEPSS 0.9%