Weaknesses of type CWE-287

2,446 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2025-66022CRITICALFACTION Unauthenticated Custom Extension Upload leads to RCEEPSS 0.7%CVE-2026-8737MEDIUMSanluan PublicCMS Trade Address Query TradeAddressListDirective.java execute missing authenticationEPSS 0.7%CVE-2026-8244MEDIUMIndustrial Application Software IAS Canias ERP Login RMI improper authenticationEPSS 0.7%CVE-2026-94151MEDIUMOmega Solution HRM OS Role Permission API permission missing authenticationEPSS 0.7%CVE-2026-8214MEDIUMIndustrial Application Software IAS Canias ERP RMI doAction improper authenticationEPSS 0.7%CVE-2026-8031MEDIUMPicoTronica e-Clinic Healthcare System ECHS API Endpoint patient-records missing authenticationEPSS 0.7%CVE-2025-7897MEDIUMharry0703 MoneyPrinterTurbo API Endpoint base.py verify_token missing authenticationEPSS 0.7%CVE-2023-25597MEDIUMA vulnerability in the web conferencing component of Mitel MiCollab through 9.6.2.9 could allow an unauthenticated attacker to download a shEPSS 0.7%CVE-2022-36296MEDIUMWordPress ActiveDEMAND plugin <= 0.2.27 - Broken Authentication vulnerabilityEPSS 0.7%CVE-2023-44752CRITICALAn issue in Student Study Center Desk Management System v1.0 allows attackers to bypass authentication via a crafted GET request to /php-sscEPSS 0.7%CVE-2026-86117CRITICALCoolify through 4.3.17 OAuth Account Takeover via Unverified Email MatchingEPSS 0.7%CVE-2025-60424HIGHA lack of rate limiting in the OTP verification component of Nagios Fusion v2024R1.2 and v2024R2 allows attackers to bypass authentication vEPSS 0.7%CVE-2026-8994HIGHLogin with NEAR <= 0.3.3 - Authentication Bypass via 'account' ParameterEPSS 0.7%CVE-2022-2664HIGHPrivate Cloud Management Platform POST Request global_config_query improper authenticationEPSS 0.7%CVE-2026-19342MEDIUMcode-projects Task Management System Login index.php improper authenticationEPSS 0.7%CVE-2026-28408CRITICALWeGIA lacks authentication verification in adicionar_tipo_docs_atendido.phpEPSS 0.7%CVE-2022-47408CRITICALAn issue was discovered in the fp_newsletter (aka Newsletter subscriber management) extension before 1.1.1, 1.2.0, 2.x before 2.1.2, 2.2.1 tEPSS 0.7%CVE-2026-69854CRITICALSpring Cloud Azure Elevation of Privilege VulnerabilityEPSS 0.7%CVE-2026-50559HIGHAuthentication/Authorization Bypass via Advanced Path Normalization VulnerabilitiesEPSS 0.7%CVE-2026-47159MEDIUMVaultwarden: Authentication Flow Information Disclosure in SSO Discovery Allows Organization Enumeration and Pre-Validation Token ExposureEPSS 0.7%