Weaknesses of type CWE-287

2,450 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2025-45777CRITICALAn issue in the OTP mechanism of Chavara Family Welfare Centre Chavara Matrimony Site v2.0 allows attackers to bypass authentication via supEPSS 0.7%CVE-2023-51477CRITICALWordPress BuddyBoss Theme theme <= 2.4.60 - Unauth. Arbitrary WordPress Settings Change vulnerabilityEPSS 0.7%CVE-2022-32928MEDIUMA logic issue was addressed with improved restrictions. This issue is fixed in iOS 16, macOS Ventura 13, watchOS 9. A user in a privileged nEPSS 0.7%CVE-2024-1147CRITICALWeak Access Control - Arbitrary file downloadEPSS 0.7%CVE-2024-1148CRITICALWeak Access Control - Arbitrary file uploadEPSS 0.7%CVE-2023-51484CRITICALWordPress Login as User or Customer plugin <= 3.8 - Unauthenticated Account Takeover vulnerabilityEPSS 0.7%CVE-2023-51478CRITICALWordPress Build App Online plugin <= 1.0.19 - Unauthenticated Account Takeover vulnerabilityEPSS 0.7%CVE-2026-15542MEDIUMwill-moss Isaiah Websocket Connection Authentication main.go improper authenticationEPSS 0.7%CVE-2025-7875MEDIUMMetasoft 美特软件 MetaCRM debug.jsp improper authenticationEPSS 0.7%CVE-2026-90524MEDIUMjaychouchannel Tourism-Management-System Update Endpoint missing authenticationEPSS 0.7%CVE-2026-5616MEDIUMJeecgBoot AI Chat JeecgBizToolsProvider.java missing authenticationEPSS 0.7%CVE-2026-7630MEDIUMinnocommerce InnoShop Installation Endpoint InstallServiceProvider.php boot improper authenticationEPSS 0.7%CVE-2024-25699HIGHPortal for ArcGIS has an invalid authentication vulnerabilityEPSS 0.7%CVE-2026-90601MEDIUMgetzep graphiti REST API main.py improper authenticationEPSS 0.7%CVE-2023-3337HIGHPuneethReddyHC Online Shopping System Advanced Admin Registration reg.php improper authenticationEPSS 0.7%CVE-2026-81202MEDIUMitsourcecode Payroll System CRUD Operation ajax.php delete missing authenticationEPSS 0.7%CVE-2026-84423MEDIUMCasdoor upload-resource API resource.go missing authenticationEPSS 0.7%CVE-2026-5676MEDIUMTotolink A8000R cstecgi.cgi setLanguageCfg missing authenticationEPSS 0.7%CVE-2026-85595CRITICALTraefik before v2.11.55 and v3.0.0 through v3.7.10 Authentication Bypass via digestAuthEPSS 0.7%CVE-2024-10097HIGHLoginizer Security and Loginizer <= 1.9.2 - Authentication Bypass via WordPress.com OAuth providerEPSS 0.7%