Weaknesses of type CWE-287

2,442 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2026-86810MEDIUMOpen-Web-Analytics Controller Controller.php checkCapabilityAndAuthenticateUser improper authenticationEPSS 0.8%CVE-2022-46170HIGHCodeIgniter is vulnerable to improper authentication via Session HandlersEPSS 0.8%CVE-2022-39289CRITICALDatabase log access in ZoneMinderEPSS 0.8%CVE-2026-56185MEDIUMWindows Admin Center Information Disclosure VulnerabilityEPSS 0.8%CVE-2022-35135HIGHBoodskap IoT Platform v4.4.9-02 allows attackers to escalate privileges via a crafted request sent to /api/user/upsert/<uuid>.EPSS 0.8%CVE-2026-86808MEDIUMmoltis-org moltis vault.rs vault_recovery_handler missing authenticationEPSS 0.8%CVE-2026-59822HIGHLiteLLM: MCP Authentication Bypass via OAuth2 Passthrough FallbackEPSS 0.8%KEVCVE-2021-41311HIGHAffected versions of Atlassian Jira Server and Data Center allow attackers with access to an administrator account that has had its access rEPSS 0.8%CVE-2026-9192CRITICALAuthentication bypass in Progress MarkLogic Server ODBC App ServerEPSS 0.8%CVE-2025-4018MEDIUM20120630 Novel-Plus CrawlController.java addCrawlSource missing authenticationEPSS 0.8%CVE-2024-1735CRITICALA vulnerability has been identified in armeria-saml versions less than 1.27.2, allowing the use of malicious SAML messages to bypass authentEPSS 0.8%CVE-2026-71467HIGHAcm-search-v2-api-rhel9: search-v2-api: authentication bypass on /federated via upgrade: websocket header spoofingEPSS 0.8%CVE-2022-39355CRITICALDiscourse Patreon vulnerable to improper validation of email during Patreon authenticationEPSS 0.8%CVE-2017-7557—dnsdist version 1.1.0 is vulnerable to a flaw in authentication mechanism for REST API potentially allowing CSRF attack.EPSS 0.8%CVE-2022-21684MEDIUMUser can bypass approval when invited to DiscourseEPSS 0.8%CVE-2025-4015MEDIUM20120630 Novel-Plus SessionController.java list missing authenticationEPSS 0.8%CVE-2026-5722CRITICALMoreConvert Pro <= 1.9.14 - Authentication Bypass via Waitlist Guest Verification Token ReuseEPSS 0.8%CVE-2025-44083CRITICALAn issue in D-Link DI-8100 16.07.26A1 allows a remote attacker to bypass administrator login authenticationEPSS 0.8%CVE-2025-30432MEDIUMA logic issue was addressed with improved state management. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sonoma 14.EPSS 0.8%CVE-2021-26253HIGHBypass of Splunk Enterprise's implementation of DUO MFAEPSS 0.8%