Weaknesses of type CWE-287

2,449 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2026-52830CRITICALfast-mcp-telegram: Bearer token path traversal bypasses reserved Telegram session protectionEPSS 0.6%CVE-2026-40964HIGHAuthentication Bypass in cf-auth-proxy in Cloud Foundry Foundation all installations allows an unauthenticated remote attacker to gain read EPSS 0.6%CVE-2026-35903CRITICALMERCURY MIPC252W IP camera 1.0.5 Build 230306 Rel.79931n contains an improper authentication vulnerability in the RTSP service. After succesEPSS 0.6%CVE-2026-97879MEDIUMzhistaredu StarTraining api-docs Endpoint SecurityConfig.java missing authenticationEPSS 0.6%CVE-2023-43805HIGHNexkey allows users to bypass authentication of Bull dashboardEPSS 0.6%CVE-2026-75878CRITICALIBM Sterling File Gateway is Vulnerable to Authentication BypassEPSS 0.6%CVE-2025-47889CRITICALIn Jenkins WSO2 Oauth Plugin 1.0 and earlier, authentication claims are accepted without validation by the "WSO2 Oauth" security realm, alloEPSS 0.6%CVE-2022-1349—WPQA < 5.2 - Subscriber+ Arbitrary Profile Picture Deletion via IDOREPSS 0.6%CVE-2026-75325CRITICALDWSurvey v6.14.0 is is vulnerable to authentication bypass via the '/api/dwsurvey/none/' and '/api/dwsurvey/up/**' parameters.EPSS 0.6%CVE-2024-53990CRITICALAsyncHttpClient (AHC) library's `CookieStore` replaces explicitly defined `Cookie`sEPSS 0.6%CVE-2022-31164HIGHTovy before v0.7.51 vulnerable to users logging in as and impersonating other usersEPSS 0.6%CVE-2026-37271CRITICALFire-Boltt Smartwatch FB BGS001 Firmware: MOY-JS14-2.0.4 is vulnerable to Improper Authentication, The device accepts GATT Write Request comEPSS 0.6%CVE-2026-6274CRITICALAuthentication Bypass in DTS Electronics' Redline WR3200EPSS 0.6%CVE-2026-57148CRITICALpraisonai-platform 0.1.4 still boots on the hardcoded JWT secret dev-secret-change-me (default-open production guard)EPSS 0.6%CVE-2026-90961CRITICALMISP LdapAuth and LinOTPAuth Authentication Bypass via Empty or Non-String CredentialsEPSS 0.6%CVE-2026-33175HIGHOAuthenticator: Authentication Bypass in Auth0OAuthenticator via Unverified Email ClaimsEPSS 0.6%CVE-2026-66014HIGHPotential authentication bypass leading to privilege escalation in ArtifactoryEPSS 0.6%CVE-2024-3701CRITICALImproper Authentication in com.transsion.kolun.aiserviceEPSS 0.6%CVE-2023-46717MEDIUMAn improper authentication vulnerability [CWE-287] in FortiOS versions 7.4.1 and below, versions 7.2.6 and below, and versions 7.0.12 and beEPSS 0.6%CVE-2026-80218HIGHSign-in token minted for one resource accepted by another in AshAuthenticationEPSS 0.6%