Weaknesses of type CWE-287

2,446 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2026-79395CRITICALAn improper authentication vulnerability in the WS-Security (wsse:UsernameToken) verification routine within the Sofia IPC daemon in XiongmaEPSS 0.8%CVE-2024-13111MEDIUMBeijing Yunfan Internet Technology Yunfan Learning Examination System JWT Token SysUserControl improper authenticationEPSS 0.8%CVE-2018-17928—The product CMS-770 (Software Versions 1.7.1 and prior)is vulnerable that an attacker can read sensitive configuration files by bypassing thEPSS 0.8%CVE-2026-25748HIGHauthentik has a forward authentication bypass with broken cookieEPSS 0.8%CVE-2019-15620—Improper access control in Nextcloud Talk 6.0.3 leaks the existance and the name of private conversations when linked them to another sharedEPSS 0.8%CVE-2021-25466MEDIUMImproper scheme check vulnerability in Samsung Internet prior to version 15.0.2.47 allows attackers to perform Man-in-the-middle attack and EPSS 0.8%CVE-2021-20238—It was found in OpenShift Container Platform 4 that ignition config, served by the Machine Config Server, can be accessed externally from clEPSS 0.8%CVE-2024-7401HIGHClient Enrollment Process BypassEPSS 0.8%CVE-2026-4959MEDIUMOpenBMB XAgent ShareServer WebSocket Endpoint share.py check_user missing authenticationEPSS 0.8%CVE-2026-15192MEDIUMmettle sendportal APIv1 Webhooks mailjet missing authenticationEPSS 0.8%CVE-2022-39184CRITICALEXFO - BV-10 Performance Endpoint Unit Authentication bypassEPSS 0.8%CVE-2022-41436CRITICALAn issue in OXHOO TP50 OXH1.50 allows unauthenticated attackers to access the administrative panel via browsing to the URL http://device_ip/EPSS 0.8%CVE-2022-44569HIGHA locally authenticated attacker with low privileges can bypass authentication due to insecure inter-process communication.EPSS 0.8%CVE-2021-32543MEDIUMSysJust CTS Web - Broken AuthenticationEPSS 0.8%CVE-2022-24748MEDIUMIncorrect Authentication in shopwareEPSS 0.8%CVE-2026-15038CRITICALInfiniteWP Client < 1.13.6 - Unauthenticated Administrator Account Takeover on MultisiteEPSS 0.8%CVE-2026-87924MEDIUMRizwan17 inventory-management-system Invoice Generation invoice_bill.php missing authenticationEPSS 0.8%CVE-2026-90513MEDIUMsimalexan api-lambda-send-email-ses API Gateway Endpoint template.yml SES.sendEmail missing authenticationEPSS 0.8%CVE-2026-86293MEDIUMSourceCodester Simple Traffic Offense System Deletion Endpoint delete-user.php missing authenticationEPSS 0.8%CVE-2026-82547MEDIUMLinux Foundation Magma Registration Complete Message amf_fsm.cpp improper authenticationEPSS 0.8%