Weaknesses of type CWE-287

2,449 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2023-51405HIGHWordPress BookingPress plugin <= 1.0.74 - Booking Price Manipulation vulnerabilityEPSS 0.7%CVE-2023-51482CRITICALWordPress Eazy Plugin Manager plugin <= 4.1.2 - Auth. Arbitrary Options Update lead to RCE vulnerabilityEPSS 0.7%CVE-2026-0953CRITICALTutor LMS Pro <= 3.9.5 - Authentication Bypass via Social LoginEPSS 0.7%CVE-2026-74894CRITICALopenssl_encrypt before 1.4.0 Authentication Bypass via Bearer TokenEPSS 0.7%CVE-2026-90620MEDIUM0x4m4 HexStrike AI API Command Endpoint hexstrike_server.py missing authenticationEPSS 0.7%CVE-2026-5000MEDIUMPromtEngineer localGPT API Endpoint server.py LocalGPTHandler missing authenticationEPSS 0.7%CVE-2026-6577MEDIUMliangliangyy DjangoBlog logtracks Endpoint views.py missing authenticationEPSS 0.7%CVE-2026-90504MEDIUMvvbbnn00 WARP-Clash-API authorized missing authenticationEPSS 0.7%CVE-2026-5632MEDIUMassafelovic gpt-researcher HTTP REST API Endpoint missing authenticationEPSS 0.7%CVE-2026-4562MEDIUMMacCMS Timming API Endpoint Timming.php weak authenticationEPSS 0.7%CVE-2026-15491MEDIUMRafyMrX TOKO-ONLINE-ROTI missing authenticationEPSS 0.7%CVE-2026-5320MEDIUMvanna-ai vanna Chat API Endpoint v2 missing authenticationEPSS 0.7%CVE-2026-7679MEDIUMYunaiV yudao-cloud OAuth2TokenServiceImpl.java getAccessToken improper authenticationEPSS 0.7%CVE-2026-95271MEDIUMdgtlmoon changedetection.io Authentication Hook flask_app.py check_authentication improper authenticationEPSS 0.7%CVE-2026-7710MEDIUMYunaiV yudao-cloud Ruoyi-Vue-Pro JwtAuthenticationTokenFilter.java doFilterInternal improper authenticationEPSS 0.7%CVE-2026-6569MEDIUMkodcloud KodExplorer fileGet Endpoint share.class.php improper authenticationEPSS 0.7%CVE-2026-7022MEDIUMSmythOS sre HTTP Header AgentRuntime.class.ts AgentRuntime improper authenticationEPSS 0.7%CVE-2026-82919MEDIUMcu silicon edit Endpoint views.py create_app missing authenticationEPSS 0.7%CVE-2026-18810MEDIUMH3C NX15 networkSetup missing authenticationEPSS 0.7%CVE-2026-6582MEDIUMTransformerOptimus SuperAGI Vector Database Management Endpoint vector_dbs.py get_vector_db_details missing authenticationEPSS 0.7%