Weaknesses of type CWE-287

2,451 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2025-5149MEDIUMWCMS Login getallcon getMemberByUid improper authenticationEPSS 0.6%CVE-2025-30215CRITICALNATS-Server Fails to Authorize Certain Jetstream Admin APIsEPSS 0.6%CVE-2024-45404HIGHOpenCTI's lack of Rate Limit lead to OTP brute forcingEPSS 0.6%CVE-2025-0604MEDIUMKeycloak-ldap-federation: authentication bypass due to missing ldap bind after password reset in keycloakEPSS 0.6%CVE-2020-8236—A wrong configuration in Nextcloud Server 19.0.1 incorrectly made the user feel the passwordless WebAuthn is also a two factor verification EPSS 0.6%CVE-2024-25652HIGHIn Delinea PAM Secret Server 11.4, it is possible for a user assigned "Administer Reports" permission and/or with access to Report functionaEPSS 0.6%CVE-2021-25505LOWImproper authentication in Samsung Pass prior to 3.0.02.4 allows to use app without authentication when lockscreen is unlocked.EPSS 0.6%CVE-2026-73501CRITICALkin-openapi: ValidationHandler.Load() Fail-Open Authentication Bypass via NoopAuthenticationFunc DefaultEPSS 0.6%CVE-2025-15097MEDIUMAlteryx Server status improper authenticationEPSS 0.6%CVE-2026-48039CRITICALMeta Ads MCP: Unauthenticated HTTP MCP Tool Execution Leaks Operator Meta Access TokenEPSS 0.6%CVE-2024-23813HIGHA vulnerability has been identified in Polarion ALM (All versions < V2404.0). The REST API endpoints of doorsconnector of the affected produEPSS 0.6%CVE-2026-63472CRITICALVendure: External-authentication account takeover: external login linked to a pre-existing account by email without verificationEPSS 0.6%CVE-2022-24740MEDIUMImproper Authentication in VoltoEPSS 0.6%CVE-2024-44127MEDIUMThis issue was addressed through improved state management. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18. Private BEPSS 0.6%CVE-2023-39345HIGHUnauthorized Access to Private Fields in User Registration API in strapiEPSS 0.6%CVE-2025-27414MEDIUMMinIO SFTP authentication bypass due to improperly trusted SSH keyEPSS 0.6%CVE-2026-13543MEDIUMDocumenso Google OAuth Login handle-oauth-callback-url.ts improper authenticationEPSS 0.6%CVE-2026-19974MEDIUMtreefrogframework treefrog-framework Session Cookie tsessioncookiestore.cpp strncmp improper authenticationEPSS 0.6%CVE-2026-24241MEDIUMNVIDIA Delegated Licensing Service for all appliance platforms contains a vulnerability where an attacker could exploit an improper authentiEPSS 0.6%CVE-2024-48859MEDIUMQTS, QuTS heroEPSS 0.6%