Weaknesses of type CWE-287

2,449 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2023-45801HIGHImproper Authentication vulnerability in Nadatel DVR allows Information Elicitation.This issue affects DVR: from 3.0.0 before 9.9.0. EPSS 0.7%CVE-2026-16083MEDIUMSipeed PicoClaw LINE Webhook line.go webhook.ParseRequest authentication replayEPSS 0.7%CVE-2024-28735HIGHUnit4 Financials by Coda versions prior to 2023Q4 suffer from an incorrect access control authorization bypass vulnerability which allows anEPSS 0.7%CVE-2023-1617CRITICALImproper Authentication Mechanism in B&R VC4 VisualizationEPSS 0.7%CVE-2023-4373CRITICAL Inadequate validation of permissions when employing remote tools and macros within Devolutions Remote Desktop Manager versions 2023.2.19 anEPSS 0.7%CVE-2022-38180MEDIUMIn JetBrains Ktor before 2.1.0 the wrong authentication provider could be selected in some casesEPSS 0.7%CVE-2025-63224CRITICALThe Itel DAB Encoder (IDEnc build 25aec8d) is vulnerable to Authentication Bypass due to improper JWT validation across devices. Attackers cEPSS 0.7%CVE-2024-1006HIGHShanxi Diankeyun Technology NODERP Cookie common.php improper authenticationEPSS 0.7%CVE-2023-34246MEDIUMDoorkeeper Improper Authentication vulnerabilityEPSS 0.7%CVE-2025-52572CRITICALHikka vulnerable to RCE through dangling web interfaceEPSS 0.7%CVE-2024-24830CRITICALOpenObserve Privilege Escalation Vulnerability in Users APIEPSS 0.7%CVE-2017-12281—A vulnerability in the implementation of Protected Extensible Authentication Protocol (PEAP) functionality for standalone configurations of EPSS 0.7%CVE-2026-40344HIGHMinIO has an Unauthenticated Object Write via Missing Signature Verification in Unsigned-Trailer UploadsEPSS 0.7%CVE-2022-0910MEDIUMA downgrade from two-factor authentication to one-factor authentication vulnerability in the CGI program of Zyxel USG/ZyWALL series firmwareEPSS 0.7%CVE-2017-20133HIGHItech Job Portal Script admin improper authenticationEPSS 0.7%CVE-2026-7723MEDIUMPrefectHQ prefect WebSocket Endpoint in missing authenticationEPSS 0.7%CVE-2025-32877CRITICALAn issue was discovered on COROS PACE 3 devices through 3.0808.0. It identifies itself as a device without input or output capabilities, whiEPSS 0.7%CVE-2017-7937—An Improper Authentication issue was discovered in Phoenix Contact GmbH mGuard firmware versions 8.3.0 to 8.4.2. An attacker may be able to EPSS 0.7%CVE-2024-10173MEDIUMdidi DDMQ Console Module improper authenticationEPSS 0.7%CVE-2023-33190CRITICALImproperly configured permissions in SealosEPSS 0.7%