Weaknesses of type CWE-287

2,450 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2024-11209MEDIUMApereo CAS 2FA login improper authenticationEPSS 0.6%CVE-2023-25913HIGHAuthentication Bypass in Danfoss AK-SM800AEPSS 0.6%CVE-2022-4441HIGHPrivilege Escalation Vulnerability in Hitachi Storage Plug-in for VMware vCenterEPSS 0.6%CVE-2026-92578CRITICALWWBN AVideo through 29.0 Authentication Bypass via Stored Password HashEPSS 0.6%CVE-2026-16867HIGHIBM i is Affected By Multiple Vulnerabilities in NetServerEPSS 0.6%CVE-2023-30967CRITICALGotham Orbital Simulator path traversalEPSS 0.6%CVE-2022-39252HIGHWhen matrix-rust-sdk recieves forwarded room keys, the reciever doesn't check if it requested the key from the forwarderEPSS 0.6%CVE-2023-44397HIGHCloudExplorer Lite permission bypass vulnerabilityEPSS 0.6%CVE-2026-29093HIGHWWBN AVideo: Unauthenticated PHP session store exposed to host network via published memcached portEPSS 0.6%CVE-2024-7763CRITICALWhatsUp Gold getReport Missing Authentication Authentication Bypass VulnerabilityEPSS 0.6%CVE-2026-5795HIGHIn Eclipse Jetty, the class JASPIAuthenticator initiates the authentication checks, which set two ThreadLocal variable. Upon returning froEPSS 0.6%CVE-2026-82466CRITICALRodauth before 2.46.0 Authentication Bypass via webauthn_loginEPSS 0.6%CVE-2022-29893HIGHImproper authentication in firmware for Intel(R) AMT before versions 11.8.93, 11.22.93, 11.12.93, 12.0.92, 14.1.67, 15.0.42, 16.1.25 may allEPSS 0.6%CVE-2023-4816MEDIUMA vulnerability exists in the Equipment Tag Out authentication, when configured with Single Sign-On (SSO) with password validation in T214. EPSS 0.6%CVE-2026-54089CRITICALFile Browser: Authentication Bypass via Proxy Auth Header ForgeryEPSS 0.6%CVE-2025-54888HIGH@fedify/fedify: Improper Authentication and Incorrect AuthorizationEPSS 0.6%CVE-2026-47865CRITICALVMware Avi Load Balancer Authentication Bypass VulnerabilityEPSS 0.6%CVE-2026-51584CRITICALAn issue in usememos v0.27.1 allows a remote attacker to achieve account takeover via the ssoCredentials branch of the SignIn handler in serEPSS 0.6%CVE-2026-55076HIGHCoder's OIDC email_verified type coercion bypass enables account takeover via unverified email linkingEPSS 0.6%CVE-2026-66908HIGHApache Camel: Camel-platform-http-main: when JWT authentication was configured with a keystore but no issuer or audience, the iss and aud claims were never validated, so any unexpired token signed by a trusted key was acceptedEPSS 0.6%