Weaknesses of type CWE-287

2,442 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2022-44620HIGHImproper authentication vulnerability in UDR-JA1604/UDR-JA1608/UDR-JA1616 firmware versions 71x10.1.107112.43A and earlier allows a remote aEPSS 0.9%CVE-2022-48195CRITICALAn issue was discovered in Mellium mellium.im/sasl before 0.3.1. When performing SCRAM-based SASL authentication, if the remote end advertisEPSS 0.9%CVE-2022-37397HIGHThe software is vulnerable when using LDAP-based authentication in YCQL with Microsoft’s Active DirectoryEPSS 0.9%CVE-2026-37006CRITICALA vulnerability in the WebSocket endpoint of gpt-researcher v0.14.7 and before allows an unauthenticated remote attacker to achieve code exeEPSS 0.9%CVE-2022-2572CRITICALIn affected versions of Octopus Server where access is managed by an external authentication provider, it was possible that the API key/keysEPSS 0.9%CVE-2026-57216MEDIUMRabbitMQ: AMQP 1.0, AMQP 0-9-1, Stream Protocol loopback enforcement can lead to remote guest sessions due to listener-address loopback checksEPSS 0.9%CVE-2020-5148—SonicWall SSO-agent default configuration uses NetAPI to probe the associated IP's in the network, this client probing method allows a potenEPSS 0.9%CVE-2025-14746MEDIUMNingyuanda TC155 RTSP Live Video Stream Endpoint improper authenticationEPSS 0.9%CVE-2022-23555CRITICALauthentik vulnerable to Improper Authentication via invitation URL token reuseEPSS 0.9%CVE-2025-27641CRITICALVasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.951 Application 20.0.2368 allows Unauthenticated APIs for Single-SigEPSS 0.9%CVE-2023-21721MEDIUMMicrosoft OneNote Elevation of Privilege VulnerabilityEPSS 0.9%CVE-2026-35030CRITICALLiteLLM has an authentication bypass via OIDC userinfo cache key collisionEPSS 0.9%CVE-2023-22334MEDIUMUse of password hash instead of password for authentication vulnerability in CONPROSYS HMI System (CHS) Ver.3.4.5 and earlier allows a remotEPSS 0.9%CVE-2020-11101CRITICALSierra Wireless AirLink Mobility Manager (AMM) before 2.17 mishandles sessions and thus an unauthenticated attacker can obtain a login sessiEPSS 0.9%CVE-2022-36093HIGHXWiki Platform Web Templates vulnerable to Unauthorized User Registration Through the Distribution WizardEPSS 0.9%CVE-2021-28494CRITICALIn Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, authentication iEPSS 0.9%CVE-2025-34186CRITICALIlevia EVE X1/X5 Server 4.7.18.0.eden Authentication BypassEPSS 0.9%CVE-2023-28609CRITICALapi/auth.go in Ansible Semaphore before 2.8.89 mishandles authentication.EPSS 0.9%CVE-2026-15459HIGHWPMU DEV Dashboard <= 5.0.0 - Authentication Bypass to Arbitrary Plugin Installation (Remote Code Execution) via Forged WDP_AUTH HMAC on ?wpmudev-hub= EndpointEPSS 0.9%CVE-2020-15222HIGHReplay of private_key_jwt possible in ORY FositeEPSS 0.9%