Weaknesses of type CWE-287

2,451 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2026-15341CRITICALUser Session Synchronizer <= 1.4.0 - Unauthenticated Authentication Bypass to Account Takeover via 'ussync-key', 'ussync-token', and 'ussync-ref' ParametersEPSS 0.6%CVE-2026-7113MEDIUMNousResearch hermes-agent Webhooks Endpoint webhook.py missing authenticationEPSS 0.6%CVE-2024-45369CRITICALmySCADA myPRO Improper AuthenticationEPSS 0.6%CVE-2022-46411HIGHAn issue was discovered in Veritas NetBackup Flex Scale through 3.0 and Access Appliance through 8.0.100. A default password is persisted afEPSS 0.6%CVE-2026-49448CRITICALauthentik: SourceStage bypass via empty POSTEPSS 0.6%CVE-2026-2174MEDIUMcode-projects Contact Management System CRUD Endpoint improper authenticationEPSS 0.6%CVE-2026-54600HIGHWallos: Unauthenticated database replacement via import endpoint on fresh installEPSS 0.6%CVE-2022-40616MEDIUMIBM Maximo Asset Management 7.6.1.1, 7.6.1.2, and 7.6.1.3 could allow a user to bypass authentication and obtain sensitive information or peEPSS 0.6%CVE-2025-11852MEDIUMApeman ID71 ONVIF Service device_service missing authenticationEPSS 0.6%CVE-2026-77194MEDIUMSimple Membership <= 4.8.1 - Unauthenticated Authentication Bypass to Administrator Account Takeover via Multisite Identity BindingEPSS 0.6%CVE-2023-42818MEDIUMSSH public key login without private key challenge if mfa is enabled in jumpserverEPSS 0.6%CVE-2025-15457MEDIUMbg5sbk MiniCMS Trash File Restore post.php improper authenticationEPSS 0.6%CVE-2025-15458MEDIUMbg5sbk MiniCMS Article post-edit.php improper authenticationEPSS 0.6%CVE-2026-65633HIGHPurpose-limited JWT accepted as full bearer authentication in AshAuthenticationEPSS 0.6%CVE-2024-47218CRITICALAn issue was discovered in vesoft NebulaGraph through 3.8.0. It allows bypassing authentication.EPSS 0.6%CVE-2024-37019CRITICALNorthern.tech Mender Enterprise before 3.6.4 and 3.7.x before 3.7.4 has Weak Authentication.EPSS 0.6%CVE-2026-15348MEDIUMPremium Packages <= 7.0.4 - Authentication Bypass to Non-Admin via 'wpdmppdl' ParameterEPSS 0.6%CVE-2022-30124MEDIUMAn improper authentication vulnerability exists in Rocket.Chat Mobile App <4.14.1.22788 that allowed an attacker with physical access to a mEPSS 0.6%CVE-2026-78885MEDIUMliketrek TREK OIDC Service oidcService.ts findOrCreateUser improper authenticationEPSS 0.6%CVE-2026-7112MEDIUMNousResearch hermes-agent API_SERVER_KEY api_server.py _check_auth improper authenticationEPSS 0.6%