Weaknesses of type CWE-287

2,446 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2026-47159MEDIUMVaultwarden: Authentication Flow Information Disclosure in SSO Discovery Allows Organization Enumeration and Pre-Validation Token ExposureEPSS 0.7%CVE-2026-55678MEDIUMArc: Unauthenticated cluster node admission when `cluster.shared_secret` is unsetEPSS 0.7%CVE-2023-32347HIGH Teltonika’s Remote Management System versions prior to 4.10.0 use device serial numbers and MAC addresses to identify devices from the userEPSS 0.7%CVE-2025-6528MEDIUM70mai M300 RTSP Live Video Stream Endpoint 12 improper authenticationEPSS 0.7%CVE-2026-55445CRITICALQinglong: Incomplete fix for CVE-2026-3965: Improper AuthenticationEPSS 0.7%CVE-2026-5270CRITICALAuthentication Bypass in Navigator and Blue Planet ProductsEPSS 0.7%CVE-2022-39254HIGHWhen matrix-nio receives forwarded room keys, the receiver doesn't check if it requested the key from the forwarderEPSS 0.7%CVE-2026-61740CRITICALLightRAG: Authentication bypass: hardcoded DEFAULT_TOKEN_SECRET and public /auth-status defeat LIGHTRAG_API_KEY protectionEPSS 0.7%CVE-2020-7293CRITICALWeb Gateway (MWG) - Privilege Escalation vulnerabilityEPSS 0.7%CVE-2022-23554MEDIUMAuthentication bypass in AlpineEPSS 0.7%CVE-2023-35940HIGHGLPI vulnerable to unauthenticated access to Dashboard dataEPSS 0.7%CVE-2026-65375HIGHThe issue was addressed with improved authentication. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.6. An EPSS 0.7%CVE-2026-6635MEDIUMrowboatlabs rowboat tools_webhook app.py tool_call improper authenticationEPSS 0.7%CVE-2026-85702MEDIUMramon-victor freegpt-webui Backend Conversation API backend.py _conversation missing authenticationEPSS 0.7%CVE-2026-41076HIGHRT: LDAP authentication bypass via empty passwordEPSS 0.7%CVE-2026-28215CRITICALhoppscotch Vulnerable to Unauthenticated Onboarding Config TakeoverEPSS 0.7%CVE-2023-51472CRITICALWordPress Checkout Mestres WP plugin <= 7.1.9.7 - Unauthenticated Account Takeover vulnerabilityEPSS 0.7%CVE-2024-41196CRITICALAn issue in Ocuco Innovation - REPORTSERVER.EXE v2.10.24.13 allows attackers to bypass authentication and escalate privileges to AdministratEPSS 0.7%CVE-2022-42951HIGHAn issue was discovered in Couchbase Server 6.5.x and 6.6.x before 6.6.6, 7.x before 7.0.5, and 7.1.x before 7.1.2. During the start-up of aEPSS 0.7%CVE-2025-37184CRITICALUnauthenticated Bypass Allows Multi-Factor Authentication CircumventionEPSS 0.7%