Weaknesses of type CWE-287

2,443 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2023-6847HIGHImproper Authentication in GitHub Enterprise Server leading to Authentication Bypass for Public Repository DataEPSS 0.8%CVE-2018-14637MEDIUMThe SAML broker consumer endpoint in Keycloak before version 4.6.0.Final ignores expiration conditions on SAML assertions. An attacker can eEPSS 0.8%CVE-2024-7923CRITICALPuppet-pulpcore: an authentication bypass vulnerability exists in pulpcoreEPSS 0.8%CVE-2026-46817CRITICALVulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affecteEPSS 0.8%KEVCVE-2021-43833HIGHAccount takeover in eLabFTWEPSS 0.8%CVE-2025-3621CRITICALRemote Code Execution in ProTNS ActADUREPSS 0.8%CVE-2021-38688HIGHImproper Authentication in QfileEPSS 0.8%CVE-2018-16465—Missing state in Nextcloud Server prior to 14.0.0 would not enforce the use of a second factor at login if the the provider of the second faEPSS 0.8%CVE-2026-42041MEDIUMAxios: Authentication Bypass via Prototype Pollution Gadget in `validateStatus` Merge StrategyEPSS 0.8%CVE-2019-5426—In Ubiquiti Networks EdgeSwitch X v1.1.0 and prior, an unauthenticated user can use the "local port forwarding" and "dynamic port forwardingEPSS 0.8%CVE-2026-26119HIGHWindows Admin Center Elevation of Privilege VulnerabilityEPSS 0.8%CVE-2024-11015CRITICALSign In With Google <= 1.8.0 - Authentication Bypass in authenticate_userEPSS 0.8%CVE-2024-52786CRITICALAn authentication bypass vulnerability in anji-plus AJ-Report up to v1.4.2 allows unauthenticated attackers to execute arbitrary code via a EPSS 0.8%CVE-2021-41309MEDIUMAffected versions of Atlassian Jira Server and Data Center allow a user who has had their Jira Service Management access revoked to export aEPSS 0.8%CVE-2020-15240HIGHRegression in JWT Signature ValidationEPSS 0.8%CVE-2026-84840MEDIUMtsi-coop tsi-dpdp-cms Bootstrap Setup Endpoint InterceptingFilter.java missing authenticationEPSS 0.8%CVE-2023-38372MEDIUMIBM Watson IoT Platform information disclosureEPSS 0.8%CVE-2021-27451HIGHMesa Labs AmegaView improper authenticationEPSS 0.8%CVE-2021-32753HIGHWeak password in API gateway in EdgeX Foundry Edinburgh, Fuji, Geneva, and Hanoi releases allows remote attackers to obtain authentication token via dictionary-based password attack when OAuth2 authentication method is enabled.EPSS 0.8%CVE-2022-39264HIGHnheko vulnerable to secret poisoning using MITM on secret requests by the homeserverEPSS 0.8%