Weaknesses of type CWE-287

2,443 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2026-32136CRITICALAdGuard Home: HTTP/2 Cleartext (h2c) Upgrade Authentication BypassEPSS 0.8%CVE-2025-7574CRITICALLB-LINK BL-WR9000 Web Interface lighttpd.cgi restore improper authenticationEPSS 0.8%CVE-2024-10963HIGHPam: improper hostname interpretation in pam_access leads to access control bypassEPSS 0.8%CVE-2022-31131MEDIUMOwnership check missing when updating or deleting mail attachments in Nextcloud mailEPSS 0.8%CVE-2022-22289MEDIUMImproper access control vulnerability in S Assistant prior to version 7.5 allows attacker to remotely get senstive information.EPSS 0.8%CVE-2024-25313HIGHCode-projects Simple School Managment System 1.0 allows Authentication Bypass via the username and password parameters at School/teacher_logEPSS 0.8%CVE-2026-42869CRITICALSOCFortress CoPilot: Hardcoded JWT secret allows unauthenticated full admin compromise and lateral movement into all integrated SOC toolsEPSS 0.8%CVE-2022-21692MEDIUMImproper Access Control in OnionshareEPSS 0.8%CVE-2024-1817HIGHDemososo DM Enterprise Website Building System Cookie indexDM_load.php dmlogin improper authenticationEPSS 0.8%CVE-2021-3424—A flaw was found in keycloak as shipped in Red Hat Single Sign-On 7.4 where IDN homograph attacks are possible. A malicious user can registeEPSS 0.8%CVE-2026-84839MEDIUMtsi-coop tsi-dpdp-cms Admin Console/DPO Compliance Console web.xml missing authenticationEPSS 0.8%CVE-2025-5512MEDIUMquequnlong shiyi-blog Administrator Backend verifyPassword improper authenticationEPSS 0.8%CVE-2025-3268MEDIUMqinguoyi TinyWebServer http_conn.cpp improper authenticationEPSS 0.8%CVE-2022-23505MEDIUMPassport-wsfed-saml2 vulnerable to Authentication Bypass for WSFed authenticationEPSS 0.8%CVE-2024-7012CRITICALPuppet-foreman: an authentication bypass vulnerability exists in foremanEPSS 0.8%CVE-2025-14567MEDIUMhaxxorsid Stock-Management-System employees missing authenticationEPSS 0.8%CVE-2023-5329MEDIUMField Logic DataCube4 Web API improper authenticationEPSS 0.8%CVE-2026-32174HIGHAzure Bot Service Elevation of Privilege VulnerabilityEPSS 0.8%CVE-2026-7722MEDIUMPrefectHQ prefect Health Check API health endswith improper authenticationEPSS 0.8%CVE-2026-91002MEDIUMstamparm maltrail Blacklist Endpoint httpd.py _blacklist missing authenticationEPSS 0.8%