Weaknesses of type CWE-287

2,446 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2023-37283HIGHAuthentication Bypass via HTML Form & Identifier First AdapterEPSS 0.7%CVE-2026-56169HIGHWindows Admin Center Elevation of Privilege VulnerabilityEPSS 0.7%CVE-2024-22394CRITICALAn improper authentication vulnerability has been identified in SonicWall SonicOS SSL-VPN feature, which in specific conditions could allow EPSS 0.7%CVE-2026-76657CRITICALAuthentication Bypass in HPE Networking Fabric Composer API allows Administrative AccessEPSS 0.7%CVE-2026-20129CRITICALCisco Catayst SD-WAN Authentication Bypass VulnerabilityEPSS 0.7%CVE-2023-6787MEDIUMKeycloak: session hijacking via re-authenticationEPSS 0.7%CVE-2026-85637MEDIUMjofpin trape Admin Endpoint sockets.py join_room missing authenticationEPSS 0.7%CVE-2025-63216CRITICALThe Itel DAB Gateway (IDGat build c041640a) is vulnerable to Authentication Bypass due to improper JWT validation across devices. Attackers EPSS 0.7%CVE-2021-38679MEDIUMImproper Authentication in Kazoo ServerEPSS 0.7%CVE-2024-28012CRITICALImproper authentication vulnerability in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WEPSS 0.7%CVE-2018-16496—In Versa Director, the un-authentication request found.EPSS 0.7%CVE-2024-33110CRITICALD-Link DIR-845L router v1.01KRb03 and before is vulnerable to Permission Bypass via the getcfg.php component.EPSS 0.7%CVE-2022-2533MEDIUMAn issue has been discovered in GitLab affecting all versions starting from 12.10 before 15.1.6, all versions starting from 15.2 before 15.2EPSS 0.7%CVE-2022-43549CRITICALImproper authentication in Veeam Backup for Google Cloud v1.0 and v3.0 allows attackers to bypass authentication mechanisms.EPSS 0.7%CVE-2026-23813CRITICALAuthentication Bypass in Web Interface allows Unauthenticated Admin Password ResetEPSS 0.7%CVE-2023-21841HIGHVulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected areEPSS 0.7%CVE-2024-12264CRITICALPayU CommercePro Plugin <= 3.8.3 - Unauthenticated Privilege EscalationEPSS 0.7%CVE-2026-97864MEDIUMGibbonEdu Gibbon Unit Planner units_add_blockAjax.php makeBlock missing authenticationEPSS 0.7%CVE-2026-44058MEDIUMAuthentication bypass via admin auth userEPSS 0.7%CVE-2023-3638CRITICALGeoVision GV-ADR2701 Improper AuthenticationEPSS 0.7%