Weaknesses of type CWE-287

2,449 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2026-30967HIGHParse Server OAuth2 authentication adapter account takeover via identity spoofingEPSS 0.6%CVE-2026-19125HIGHEthPress <= 2.3.5 - Unauthenticated Authentication BypassEPSS 0.6%CVE-2026-30949HIGHParse Server is missing audience validation in Keycloak authentication adapterEPSS 0.6%CVE-2025-1475CRITICALWPCOM Member <= 1.7.5 - Authentication Bypass via 'user_phone'EPSS 0.6%CVE-2026-3224CRITICALAuthentication bypass in the Microsoft Entra ID (Azure AD) authentication mode in Devolutions Server 2025.3.15.0 and earlier allows an unautEPSS 0.6%CVE-2026-16198MEDIUMSipeed PicoClaw First Run Setup access_control.go authentication bypassEPSS 0.6%CVE-2022-46875MEDIUMThe executable file warning was not presented when downloading .atloc and .ftploc files, which can run commands on a user's computer. <br>*NEPSS 0.6%CVE-2026-48812HIGHFreeScout Allows Unauthenticated Access to Legacy Attachment FilesEPSS 0.6%CVE-2025-52856CRITICALVioStorEPSS 0.6%CVE-2022-43690MEDIUMConcrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 did not use strict comparison for the legacy_salt so that limitedEPSS 0.6%CVE-2024-47806HIGHJenkins OpenId Connect Authentication Plugin 4.354.v321ce67a_1de8 and earlier does not check the `aud` (Audience) claim of an ID Token, alloEPSS 0.6%CVE-2024-47807HIGHJenkins OpenId Connect Authentication Plugin 4.354.v321ce67a_1de8 and earlier does not check the `iss` (Issuer) claim of an ID Token, allowiEPSS 0.6%CVE-2018-0163—A vulnerability in the 802.1x multiple-authentication (multi-auth) feature of Cisco IOS Software could allow an unauthenticated, adjacent atEPSS 0.6%CVE-2024-9946HIGHSocial Share, Social Login and Social Comments Plugin – Super Socializer <= 7.13.68 - Authentication Bypass via Disqus OAuth providerEPSS 0.6%CVE-2026-85701MEDIUMramon-victor freegpt-webui Authentication Check __init__.py ChatCompletion.create missing authenticationEPSS 0.6%CVE-2026-44472HIGHSaleor: Account pre-hijacking vulnerability due to unverified anonymous order mergeEPSS 0.6%CVE-2026-29145CRITICALApache Tomcat, Apache Tomcat Native: OCSP checks sometimes soft-fail even when soft-fail is disabledEPSS 0.6%CVE-2026-29792CRITICALFeathersjs has an OAuth Callback Account TakeoverEPSS 0.6%CVE-2020-8350HIGHAn authentication bypass vulnerability was reported in Lenovo ThinkPad Stack Wireless Router firmware version 1.1.3.4 that could allow escalEPSS 0.6%CVE-2026-10243MEDIUMcode-projects Smart Parking System Admin Endpoint missing authenticationEPSS 0.6%