Weaknesses of type CWE-287

2,450 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2022-39801HIGHSAP GRC Access control Emergency Access Management allows an authenticated attacker to access a Firefighter session even after it is closed EPSS 0.7%CVE-2020-36832CRITICALIndeed Membership Pro 7.3 - 8.6 - Authentication BypassEPSS 0.7%CVE-2024-10097HIGHLoginizer Security and Loginizer <= 1.9.2 - Authentication Bypass via WordPress.com OAuth providerEPSS 0.7%CVE-2024-27767CRITICALUnitronics Unistream Unilogic – Versions prior to 1.35.227 CWE-287: Improper AuthenticationEPSS 0.7%CVE-2026-86669MEDIUMaircheng-org iWebShop-5 systemseller.php login improper authenticationEPSS 0.7%CVE-2023-51442HIGHAuthentication bypass vulnerability in navidrome's subsonic endpointEPSS 0.7%CVE-2026-14622MEDIUMjairiidriss restaurant-website-php-mysql AJAX Endpoint ajax_files missing authenticationEPSS 0.7%CVE-2026-62896CRITICALMicrosoft Teams Elevation of Privilege VulnerabilityEPSS 0.7%CVE-2026-8621HIGHCrabbox < v0.12.0 Authentication Bypass via Header SpoofingEPSS 0.7%CVE-2026-30863CRITICALParse Server: JWT audience validation bypass in Google, Apple, and Facebook authentication adaptersEPSS 0.7%CVE-2023-23460CRITICALPriority Web – Authentication bypass EPSS 0.7%CVE-2022-2757CRITICAL Due to the lack of adequately implemented access-control rules, all versions Kingspan TMS300 CS are vulnerable to an attacker viewing andEPSS 0.7%CVE-2026-8321MEDIUMinkeep agents runAuth Middleware runAuth.ts createDevContext authentication bypassEPSS 0.7%CVE-2026-6126MEDIUMzhayujie chatgpt-on-wechat CowAgent Administrative HTTP Endpoint missing authenticationEPSS 0.7%CVE-2026-82758MEDIUMash_authentication_oauth2_server treats an empty resolved secret as valid, opening the gated Dynamic Client Registration endpointEPSS 0.7%CVE-2026-15557MEDIUMwaooAI waoowaoo Internal Task Header api-auth.ts requireProjectAuthLight improper authenticationEPSS 0.7%CVE-2026-47156CRITICALMantisBT: SOAP API Authentication Bypass with Privilege Escalation to AdministratorEPSS 0.7%CVE-2026-16210MEDIUMnewpanjing simpleui AjaxAdmin AJAX Endpoint admin.py self.get_action missing authenticationEPSS 0.7%CVE-2026-92401MEDIUMChangeWeDer crm improper authenticationEPSS 0.7%CVE-2026-90840MEDIUMPHPGurukul Blood Donor Management System Admin Controllers Dashboard.php __construct improper authenticationEPSS 0.7%