Weaknesses of type CWE-287

2,450 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2022-4041MEDIUMPrivilege Escalation Vulnerability in Hitachi Storage Plug-in for VMware vCenterEPSS 0.6%CVE-2020-22657CRITICALIn Ruckus R310 10.5.1.0.199, Ruckus R500 10.5.1.0.199, Ruckus R600 10.5.1.0.199, Ruckus T300 10.5.1.0.199, Ruckus T301n 10.5.1.0.199, RuckusEPSS 0.6%CVE-2026-88007CRITICALTraefik HTTP/3 Backend NTLM Connection ReuseEPSS 0.6%CVE-2026-31387MEDIUMApache OFBiz: Cookie Manipulation Allows Authenticated JWT Forgery and Account ImpersonationEPSS 0.6%CVE-2022-29237MEDIUMLimited Authentication Bypass for Media Files in OpencastEPSS 0.6%CVE-2024-24771HIGHOpen Forms potential multi-factor authentication bypassEPSS 0.6%CVE-2026-16857HIGHVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.6%CVE-2026-87016HIGHOpen WebUI: Sign-in as another user via wildcard characters in the OAuth subject claim on SQLiteEPSS 0.6%CVE-2026-53761HIGHFrappe CRM: Authentication Bypass via Logged Invitation Keys in crm/apiEPSS 0.6%CVE-2025-22228HIGHCVE-2025-22228: Spring Security BCryptPasswordEncoder does not enforce maximum password lengthEPSS 0.6%CVE-2024-0002CRITICALA condition exists in FlashArray Purity whereby an attacker can employ a privileged account allowing remote access to the array.EPSS 0.6%CVE-2026-41145HIGHMinIO has an Unauthenticated Object Write via Query-String Credential Signature Bypass in Unsigned-Trailer UploadsEPSS 0.6%CVE-2025-60772CRITICALImproper authentication in the web-based management interface of NETLINK HG322G V1.0.00-231017, allows a remote unauthenticated attacker to EPSS 0.6%CVE-2026-68569HIGHApache Tomcat: Principal lookup can fail open in some casesEPSS 0.6%CVE-2024-2450HIGHMattermost versions 8.1.x before 8.1.10, 9.2.x before 9.2.6, 9.3.x before 9.3.2, and 9.4.x before 9.4.3 fail to correctly verify account ownEPSS 0.6%CVE-2026-10697HIGHMFA Bypass in MOVEit TransferEPSS 0.6%CVE-2026-25804HIGHAntrea has invalid enforcement order for network policy rules caused by integer overflowEPSS 0.6%CVE-2024-37893MEDIUMMFA bypass in oauth flow in Firefly IIIEPSS 0.6%CVE-2019-1758MEDIUMCisco IOS Software Catalyst 6500 Series 802.1x Authentication Bypass VulnerabilityEPSS 0.6%CVE-2025-5149MEDIUMWCMS Login getallcon getMemberByUid improper authenticationEPSS 0.6%