Weaknesses of type CWE-287

2,430 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2024-29849CRITICALVeeam Backup Enterprise Manager allows unauthenticated users to log in as any user to enterprise manager web interface.EPSS 38.4%CVE-2019-6814—A CWE-287: Improper Authentication vulnerability exists in the NET55XX Encoder with firmware prior to version 2.1.9.7 which could cause impaEPSS 36.6%CVE-2019-19006CRITICALSangoma FreePBX 115.0.16.26 and below, 14.0.13.11 and below, 13.0.197.13 and below have Incorrect Access Control.EPSS 36.6%KEVCVE-2024-57045CRITICALA vulnerability in the D-Link DIR-859 router with firmware version A3 1.05 and earlier permits unauthorized individuals to bypass the authenEPSS 32.2%CVE-2025-68926CRITICALRustFS has a gRPC Hardcoded Token Authentication BypassEPSS 31.1%CVE-2019-1867CRITICALCisco Elastic Services Controller REST API Authentication Bypass VulnerabilityEPSS 30.3%CVE-2017-9946HIGHA vulnerability has been identified in Siemens APOGEE PXC and TALON TC BACnet Automation Controllers in all versions <V3.5. An attacker withEPSS 25.0%CVE-2024-21899CRITICALQTS, QuTS hero, QuTScloudEPSS 24.4%CVE-2026-45434CRITICALApache OFBiz: Authentication Bypass via Password-Change Logic Flaw Leading to RCEEPSS 22.4%CVE-2024-6235CRITICALSensitive information disclosureEPSS 21.2%CVE-2025-49001HIGHDataease Authentication Bypass VulnerabilityEPSS 21.1%CVE-2025-4978CRITICALNetgear DGND3700 Basic Authentication BRS_top.html improper authenticationEPSS 21.0%CVE-2026-62144CRITICALManagement Authentication Bypass and Privilege EscalationEPSS 20.8%CVE-2022-31125CRITICALAuthentication Bypass in Roxy-wiEPSS 20.3%CVE-2017-3167—In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, use of the ap_get_basic_auth_pw() by third-party modules outside of the authentEPSS 20.2%CVE-2025-55234HIGHWindows SMB Elevation of Privilege VulnerabilityEPSS 20.1%CVE-2024-24496CRITICALAn issue in Daily Habit Tracker v.1.0 allows a remote attacker to manipulate trackers via the home.php, add-tracker.php, delete-tracker.php,EPSS 19.5%CVE-2025-54918HIGHWindows NTLM Elevation of Privilege VulnerabilityEPSS 19.4%CVE-2016-7836CRITICALSKYSEA Client View Ver.11.221.03 and earlier allows remote code execution via a flaw in processing authentication on the TCP connection withEPSS 19.2%KEVCVE-2026-41679CRITICALPaperclip Vulnerable to Unauthenticated Remote Code Execution via Import Authorization BypassEPSS 18.9%