Weaknesses of type CWE-287

2,449 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2026-90620MEDIUM0x4m4 HexStrike AI API Command Endpoint hexstrike_server.py missing authenticationEPSS 0.7%CVE-2026-8216MEDIUMIndustrial Application Software IAS Canias ERP Java RMI Session Management iasServerRemoteInterface.doAction improper authenticationEPSS 0.7%CVE-2024-50645CRITICALMallChat v1.0-SNAPSHOT has an authentication bypass vulnerability. An attacker can exploit this vulnerability to access API without any tokeEPSS 0.7%CVE-2023-46249CRITICALauthentik potential installation takeover when default admin user is deletedEPSS 0.7%CVE-2026-86214MEDIUMMstfakts College-Management-System login.php improper authenticationEPSS 0.7%CVE-2026-6129MEDIUMzhayujie chatgpt-on-wechat CowAgent Agent Mode Service missing authenticationEPSS 0.7%CVE-2026-93559MEDIUMForget-C Jellyfish AI Short Drama Studio FastAPI dependencies.py missing authenticationEPSS 0.7%CVE-2026-5320MEDIUMvanna-ai vanna Chat API Endpoint v2 missing authenticationEPSS 0.7%CVE-2026-7022MEDIUMSmythOS sre HTTP Header AgentRuntime.class.ts AgentRuntime improper authenticationEPSS 0.7%CVE-2025-46348CRITICALYesWiki Vulnerable to Unauthenticated Site Backup Creation and DownloadEPSS 0.7%CVE-2023-30845HIGHESPv2 vulnerable to JWT authentication bypass via `X-HTTP-Method-Override` headerEPSS 0.7%CVE-2026-88895HIGHCyberPanel before 3.0.5 Authentication Bypass via APIEPSS 0.7%CVE-2022-31122CRITICALWire-server vulnerable to Token Recipient Confusion resulting in account impersonation, deletion or malicious account creationEPSS 0.7%CVE-2021-26074MEDIUMBroken Authentication in Atlassian Connect Spring Boot (ACSB) from version 1.1.0 before version 2.1.3: Atlassian Connect Spring Boot is a JaEPSS 0.7%CVE-2020-1778MEDIUMBypassing user account validationEPSS 0.7%CVE-2024-28007CRITICALImproper authentication vulnerability in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WEPSS 0.7%CVE-2024-28009CRITICALImproper authentication vulnerability in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WEPSS 0.7%CVE-2026-54176MEDIUMbackpack/crud: MyAccountController allows changing the login email without a current-password checkEPSS 0.7%CVE-2023-31123CRITICALeffectindex/tripreporter vulnerable to improper password verification on POST `/api/v1/account/login`EPSS 0.6%CVE-2026-41276HIGHFlowise: AccountService resetPassword Authentication Bypass VulnerabilityEPSS 0.6%