Weaknesses of type CWE-287

2,446 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2026-88018CRITICALrclone serve s3: --auth-proxy without --auth-key authenticates nobody - full SigV4 signature bypassEPSS 0.8%CVE-2022-47508HIGHDisable NTLM: SAM 2022.4 EPSS 0.8%CVE-2022-23541MEDIUMjsonwebtoken's insecure implementation of key retrieval function could lead to Forgeable Public/Private Tokens from RSA to HMACEPSS 0.8%CVE-2026-35579HIGHCoreDNS TSIG authentication bypass on gRPC, QUIC, DoH, and DoH3 transportsEPSS 0.8%CVE-2023-4501CRITICALAuthentication bypass in OpenText (Micro Focus) Enterprise ServerEPSS 0.8%CVE-2024-38139HIGHMicrosoft Dataverse Elevation of Privilege VulnerabilityEPSS 0.8%CVE-2021-25445—Unprotected component vulnerability in Samsung Internet prior to version 14.2 allows untrusted application to access internal files in SamsuEPSS 0.8%CVE-2026-40139CRITICALCritical Pre-Authentication Vulnerability in BeyondTrust Remote Support and Privileged Remote AccessEPSS 0.8%CVE-2023-32682MEDIUMImproper checks for deactivated users during login in synapseEPSS 0.8%CVE-2023-3622MEDIUMAccess Control Bypass Vulnerability in the SolarWinds Platform EPSS 0.8%CVE-2021-25490MEDIUMA keyblob downgrade attack in keymaster prior to SMR Oct-2021 Release 1 allows attacker to trigger IV reuse vulnerability with privileged prEPSS 0.8%CVE-2024-11186CRITICALOn affected versions of the CloudVision Portal, improper access controls could enable a malicious authenticated user to take broader actions on managed EOS devices than intended. This advisory impacts the Arista CloudVision Portal products when run on-premEPSS 0.8%CVE-2026-26035HIGHAn Improper Authentication vulnerability [CWE-287] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, ForEPSS 0.8%CVE-2026-85636MEDIUMjofpin trape Login Endpoint stats.py missing authenticationEPSS 0.8%CVE-2026-88952CRITICALOAuth2 sign-in attached to an existing account without an email comparison in AshAuthenticationEPSS 0.7%CVE-2020-20402HIGHWestbrookadmin portfolioCMS v1.05 allows attackers to bypass password validation and access sensitive information via session fixation.EPSS 0.7%CVE-2025-46548MEDIUMApache Pekko Management, Apache Pekko Management, Apache Pekko Management, Akka Management, Akka Management, Akka Management: management API basic authentication is not effectiveEPSS 0.7%CVE-2026-18961HIGHSocial Login, Passkeys, Magic Link & Email OTP – Passwordless Login by VentraConnect <= 1.4.3 - Unauthenticated Authentication Bypass via Spotify OAuth CallbackEPSS 0.7%CVE-2026-76658CRITICALUnauthenticated Remote Code Execution in HPE Networking Fabric Composer SSH DaemonEPSS 0.7%CVE-2023-37283HIGHAuthentication Bypass via HTML Form & Identifier First AdapterEPSS 0.7%