Weaknesses of type CWE-287

2,443 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2026-63456CRITICALAuthentication bypass via spoofed HTTP headers Orchestrator REST APIEPSS 0.8%CVE-2023-23612MEDIUMIssue with whitespace in JWT roles in OpenSearchEPSS 0.8%CVE-2020-25183HIGHMedtronic MyCareLink Smart Improper AuthenticationEPSS 0.8%CVE-2026-12795MEDIUMBerriAI litellm SSO Debug Flow ui_sso.py json.dumps missing authenticationEPSS 0.8%CVE-2024-3263CRITICALImproper authentication in YMS VIS ProEPSS 0.8%CVE-2023-39196MEDIUMApache Ozone: Missing mutual TLS authentication in one of the service internal Ozone Storage Container Manager endpointsEPSS 0.8%CVE-2026-1203MEDIUMCRMEB JSON Token LoginServices.php remoteRegister improper authenticationEPSS 0.8%CVE-2022-39267HIGHBrokercap Bifrost vulnerable to authentication bypass for admin and monitor user groupsEPSS 0.8%CVE-2020-14380—An account takeover flaw was found in Red Hat Satellite 6.7.2 onward. A potential attacker with proper authentication to the relevant externEPSS 0.8%CVE-2026-7714MEDIUMcrocodilestick Calibre-Web-Automated Admin Endpoint cwa_functions.py missing authenticationEPSS 0.8%CVE-2025-15099MEDIUMsimstudioai sim CRON Secret internal.ts improper authenticationEPSS 0.8%CVE-2022-32514CRITICALA CWE-287: Improper Authentication vulnerability exists that could allow an attacker to gain control of the device when logging into a web pEPSS 0.8%CVE-2024-10111HIGHOAuth Single Sign On – SSO (OAuth Client) <= 6.26.3 - Authentication BypassEPSS 0.8%CVE-2018-17926—The product M2M ETHERNET (FW Versions 2.22 and prior, ETH-FW Versions 1.01 and prior) is vulnerable in that an attacker can upload a malicioEPSS 0.8%CVE-2023-1464HIGHSourceCodester Medicine Tracker System improper authenticationEPSS 0.8%CVE-2023-24093CRITICALAn access control issue in H3C A210-G A210-GV100R005 allows attackers to authenticate without a password.EPSS 0.8%CVE-2017-12213—A vulnerability in the dynamic access control list (ACL) feature of Cisco IOS XE Software running on Cisco Catalyst 4000 Series Switches couEPSS 0.8%CVE-2023-21817HIGHWindows Kerberos Elevation of Privilege VulnerabilityEPSS 0.8%CVE-2026-14714MEDIUMzhayujie chatgpt-on-wechat CowAgent wx Endpoint common.py verify_server missing authenticationEPSS 0.8%CVE-2026-32136CRITICALAdGuard Home: HTTP/2 Cleartext (h2c) Upgrade Authentication BypassEPSS 0.8%