Weaknesses of type CWE-287

2,442 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2023-35137HIGHAn improper authentication vulnerability in the authentication module of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmwEPSS 0.9%CVE-2025-48370LOWauth-js Vulnerable to Insecure Path Routing from Malformed User InputEPSS 0.9%CVE-2022-22523HIGHCarlo Gavazzi UWP 3.0 WebApp allows for authentication bypassEPSS 0.9%CVE-2026-5959HIGHGL.iNet GL-RM1/GL-RM10/GL-RM10RC/GL-RM1PE Factory Reset improper authenticationEPSS 0.9%CVE-2011-2054MEDIUMCisco ASA Secondary Authentication Bypass VulnerabilityEPSS 0.9%CVE-2025-6916HIGHTOTOLINK T6 formLoginAuth.htm Form_Login missing authenticationEPSS 0.9%CVE-2023-49340CRITICALAn issue was discovered in Newland Nquire 1000 Interactive Kiosk version NQ1000-II_G_V1.00.011, allows remote attackers to escalate privilegEPSS 0.9%CVE-2024-25128CRITICALFlask-AppBuilder incorrect authentication when using auth type OpenID EPSS 0.9%CVE-2022-21695MEDIUMImproper Access Control in OnionshareEPSS 0.9%CVE-2023-31634CRITICALIn TeslaMate before 1.27.2, there is unauthorized access to port 4000 for remote viewing and operation of user data. After accessing the IP EPSS 0.9%CVE-2026-48929HIGHRocket.Chat in versions <8.5.1, <8.4.4, <8.3.6, <8.2.6, <8.1.6, <8.0.7, <7.13.9, and <7.10.13 is vulnerable to unauthenticated file deletionEPSS 0.9%CVE-2019-5449—A missing check in the Nextcloud Server prior to version 15.0.1 causes leaking of calendar event names when adding or modifying confidentialEPSS 0.9%CVE-2020-7856HIGHA vulnerability of Helpcom could allow an unauthenticated attacker to execute arbitrary command. This vulnerability exists due to insufficieEPSS 0.9%CVE-2023-4562CRITICALInformation Disclosure, Information Tampering and Authentication Bypass Vulnerability in MELSEC-F Series main moduleEPSS 0.9%CVE-2022-39246HIGHmatrix-android-sdk2 vulnerable to impersonation via forwarded Megolm sessionsEPSS 0.8%CVE-2022-38336HIGHAn access control issue in MobaXterm before v22.1 allows attackers to make connections to the server via the SSH or SFTP protocols without aEPSS 0.8%CVE-2025-43995CRITICALDell Storage Center - Dell Storage Manager, version(s) 20.1.21, contain(s) an Improper Authentication vulnerability. An unauthenticated attaEPSS 0.8%CVE-2022-3465HIGHMediabridge Medialink index.asp improper authenticationEPSS 0.8%CVE-2026-15303CRITICAL6Storage Rentals <= 2.27.0 - Unauthenticated Account Takeover via 'email' ParameterEPSS 0.8%CVE-2026-86810MEDIUMOpen-Web-Analytics Controller Controller.php checkCapabilityAndAuthenticateUser improper authenticationEPSS 0.8%