Weaknesses of type CWE-287

2,449 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2023-46942HIGHLack of authentication in NPM's package @evershop/evershop before version 1.0.0-rc.8, allows remote attackers to obtain sensitive informatioEPSS 0.7%CVE-2026-40920CRITICALApache Ranger: Privilege Escalation via URL ParameterEPSS 0.7%CVE-2022-36133CRITICALThe WebConfig functionality of Epson TM-C3500 and TM-C7500 devices with firmware version WAM31500 allows authentication bypass.EPSS 0.7%CVE-2026-4021HIGHContest Gallery <= 28.1.5 - Unauthenticated Privilege Escalation Admin Account Takeover via Registration Confirmation Email-to-ID Type ConfusionEPSS 0.7%CVE-2023-51982CRITICALCrateDB 5.5.1 is contains an authentication bypass vulnerability in the Admin UI component. After configuring password authentication and_ LEPSS 0.7%CVE-2024-45148HIGHAdobe Commerce | Improper Authentication (CWE-287)EPSS 0.7%CVE-2026-94493CRITICALGigatech PDV5701 WebSocket Service index.html missing authenticationEPSS 0.7%CVE-2021-40507CRITICALAn issue was discovered in the ALU unit of the OR1200 (aka OpenRISC 1200) processor 2011-09-10 through 2015-11-11. The overflow flag is not EPSS 0.7%CVE-2026-17182CRITICALIBM Db2 Mirror for i is affected by multiple vulnerabilitiesEPSS 0.7%CVE-2021-40506CRITICALAn issue was discovered in the ALU unit of the OR1200 (aka OpenRISC 1200) processor 2011-09-10 through 2015-11-11. The overflow flag is not EPSS 0.7%CVE-2020-5425HIGHUser Impersonation possible in Tanzu SSOEPSS 0.7%CVE-2026-28514CRITICALRocket.Chat: Users can login with any password via the EE ddp-streamer-serviceEPSS 0.7%CVE-2023-30945CRITICALCVE-2023-30945 EPSS 0.7%CVE-2026-8979CRITICALAuthentication BypassEPSS 0.7%CVE-2023-44252HIGH** UNSUPPORTED WHEN ASSIGNED **An improper authentication vulnerability [CWE-287] in Fortinet FortiWAN version 5.2.0 through 5.2.1 and versiEPSS 0.7%CVE-2026-6588MEDIUMserge-chat serge Model API Endpoint model.py delete_model missing authenticationEPSS 0.7%CVE-2026-6579MEDIUMliangliangyy DjangoBlog Clean Endpoint views.py missing authenticationEPSS 0.7%CVE-2022-23654HIGHImproper write access check in Requarks/wikiEPSS 0.7%CVE-2026-78434MEDIUMFaveo Helpdesk post-ticket-reply Endpoint FormController.php post_ticket_reply missing authenticationEPSS 0.7%CVE-2026-16656CRITICALVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.7%