Weaknesses of type CWE-287

2,450 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2025-55171HIGHWeGIA Anonymous Attacker can Delete Arbitrary Image file at endpoint `/html/personalizacao_remover.php`EPSS 0.6%CVE-2026-41428CRITICALBudibase: Authentication Bypass via Unanchored Regex in Public Endpoint Matcher — Unauthenticated Access to Protected EndpointsEPSS 0.6%CVE-2026-19749MEDIUMTenda CH7 RTSP/ONVIF missing authenticationEPSS 0.6%CVE-2026-97878MEDIUMzhistaredu StarTraining Druid Console index.html anonymous missing authenticationEPSS 0.6%CVE-2026-77001CRITICALSocial Login & Sharing buttons with Analytics By SoClever <= 1.2.0 - Unauthenticated Authentication BypassEPSS 0.6%CVE-2026-53483CRITICALDell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1EPSS 0.6%CVE-2026-17101HIGHIBM i is Affected By Multiple Vulnerabilities in Navigator for iEPSS 0.6%CVE-2026-86709CRITICALThe Pressengine <= 1.0 - Unauthenticated Authentication BypassEPSS 0.6%CVE-2026-75800CRITICALFrontegg SAML SSO <= 1.0.1 - Unauthenticated Account Takeover via Unverified SAMLResponseEPSS 0.6%CVE-2024-22442CRITICALThe vulnerability could be remotely exploited to bypass authentication.EPSS 0.6%CVE-2023-1065MEDIUMThis vulnerability in the Snyk Kubernetes Monitor can result in irrelevant data being posted to a Snyk Organization, which could in turn obfEPSS 0.6%CVE-2024-6576HIGHMOVEit Transfer Privilege Escalation VulnerabilityEPSS 0.6%CVE-2024-2873CRITICALUser authentication bypass in wolfSSH serverEPSS 0.6%CVE-2026-46579HIGHOpenshift/router: openshift/router: mtls client certificate spoofing via unstripped x-ssl-client headers on http frontendEPSS 0.6%CVE-2025-27672CRITICALVasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows OAUTH Security Bypass OVE-20230524-EPSS 0.6%CVE-2024-11322HIGHCyberPower PowerPanel Business Unauthenticated Restart DoSEPSS 0.6%CVE-2022-46400MEDIUMThe Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) allows attackers to bypass passkey enEPSS 0.6%CVE-2024-51996HIGHSymphony has an Authentication Bypass via RememberMeEPSS 0.6%CVE-2023-1477HIGHImproper Authentication vulnerability in HYPR Keycloak Authenticator Extension allows Authentication Abuse.This issue affects HYPR Keycloak EPSS 0.6%CVE-2026-55652CRITICALWekan: Header-login IP allowlist bypass via X-Forwarded-For spoofing in Wekan allows unauthenticated full account takeover (incl. admin)EPSS 0.6%