Weaknesses of type CWE-287

2,446 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2026-86292MEDIUMSourceCodester Simple Traffic Offense System User Creation saveuser.php missing authenticationEPSS 0.7%CVE-2026-86306MEDIUMlight0011 cms Cookie Helper UserModel.class.php improper authenticationEPSS 0.7%CVE-2026-92401MEDIUMChangeWeDer crm improper authenticationEPSS 0.7%CVE-2026-6126MEDIUMzhayujie chatgpt-on-wechat CowAgent Administrative HTTP Endpoint missing authenticationEPSS 0.7%CVE-2022-24901HIGHAuthentication bypass and denial of service (DoS) vulnerabilities in Apple Game Center auth adapter EPSS 0.7%CVE-2026-61435HIGHPraisonAI before 4.6.78 Authentication Bypass via Host Header SpoofingEPSS 0.7%CVE-2022-48364MEDIUMThe undo_mark_statuses_as_sensitive method in app/services/approve_appeal_service.rb in Mastodon 3.5.x before 3.5.3 does not use the server'EPSS 0.7%CVE-2026-50561CRITICALYuxi has a JWT Authentication Bypass Leading to Cross-Instance Administrator Token ReuseEPSS 0.7%CVE-2023-43793HIGHMisskey allows users to bypass authentication of Bull dashboardEPSS 0.7%CVE-2026-37270CRITICALTrueview Security camera T18161- AF v4.9.60.0 contains an authentication bypass vulnerability caused by improper password validation and theEPSS 0.7%CVE-2024-22206CRITICAL@clerk/nextjs auth() and getAuth() methods vulnerable to insecure direct object reference (IDOR)EPSS 0.7%CVE-2023-22497MEDIUMNetdata is vulnerable to improper authenticationEPSS 0.7%CVE-2025-14703MEDIUMShiguangwu sgwbox N3 POST Message fsnotify improper authenticationEPSS 0.7%CVE-2026-40165HIGHauthentik: SAML NameID XML Comment Injection Enables Authentication Bypass via Identifier TruncationEPSS 0.7%CVE-2026-4187MEDIUMTiandy Easy7 Integrated Management Platform Device Identifier UpdateLocalDevInfo.jsp missing authenticationEPSS 0.7%CVE-2026-18610MEDIUMNewType WebEIP EIP_Com_FileList.aspx improper authenticationEPSS 0.7%CVE-2024-47080HIGHmatrix-js-sdk keys sent via `sendSharedHistoryKeys` vulnerable to interception by malicious homeserverEPSS 0.7%CVE-2019-13423—Search Guard Kibana Plugin versions before 5.6.8-7 and before 6.x.y-12 had an issue that an authenticated Kibana user could impersonate as kEPSS 0.7%CVE-2024-11494HIGH**UNSUPPORTED WHEN ASSIGNED** The improper authentication vulnerability in the Zyxel P-6101C ADSL modem firmware version P-6101CSA6AP_201403EPSS 0.7%CVE-2025-60534CRITICALBlue Access Cobalt v02.000.195 suffers from an authentication bypass vulnerability, which allows an attacker to selectively proxy requests iEPSS 0.7%