Weaknesses of type CWE-287

2,442 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2026-34072HIGHcronmaster: Middleware authentication bypass enabling unauthorized page access and server-action executionEPSS 0.9%CVE-2026-41574CRITICALNhost Vulnerable to Account Takeover via OAuth Email Verification BypassEPSS 0.9%CVE-2024-21632HIGHomniauth-microsoft_graph vulnerable to account takeover (nOAuth)EPSS 0.9%CVE-2026-42822CRITICALAzure Local Disconnected Operations (ALDO) Elevation of Privilege VulnerabilityEPSS 0.9%CVE-2026-47280CRITICALAzure Resource Manager Elevation of Privilege VulnerabilityEPSS 0.9%CVE-2026-56162CRITICALAzure SQL Database Elevation of Privilege VulnerabilityEPSS 0.9%CVE-2026-56191CRITICALMicrosoft Exchange Online Tampering VulnerabilityEPSS 0.9%CVE-2026-45480CRITICALAzure Active Directory Elevation of Privilege VulnerabilityEPSS 0.9%CVE-2026-3192MEDIUMChia Blockchain RPC Credential rpc_server_base.py _authenticate improper authenticationEPSS 0.9%CVE-2026-1202MEDIUMCRMEB LoginController.php appleLogin improper authenticationEPSS 0.9%CVE-2024-7395CRITICALInsufficient AuthenticationEPSS 0.9%CVE-2026-3655CRITICALOTP Login With Phone Number, OTP Verification <= 1.8.60 - Unauthenticated Authentication Bypass via Firebase OTP VerificationEPSS 0.9%CVE-2026-76009HIGHNext-Cart Store to WooCommerce Migration <= 3.9.8 - Unauthenticated Authentication Bypass via Default '__token__' Fallback in REST Migration EndpointEPSS 0.9%CVE-2022-23600MEDIUMLimited ability to spoof SAML authentication with missing audience verificationEPSS 0.9%CVE-2021-29487HIGHAuthentication bypass in OctobercmsEPSS 0.9%CVE-2026-12761CRITICALminiOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) <= 7.7.0 - Unauthenticated Authentication Bypass to Administrator Account Takeover via Profile Completion OTP FlowEPSS 0.9%CVE-2022-3173MEDIUMImproper Authentication in snipe/snipe-itEPSS 0.9%CVE-2018-16464—A missing access check in Nextcloud Server prior to 14.0.0 could lead to continued access to password protected link shares when the owner hEPSS 0.9%CVE-2024-5732MEDIUMClash Proxy Port improper authenticationEPSS 0.9%CVE-2022-44620HIGHImproper authentication vulnerability in UDR-JA1604/UDR-JA1608/UDR-JA1616 firmware versions 71x10.1.107112.43A and earlier allows a remote aEPSS 0.9%