Weaknesses of type CWE-287

2,451 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2024-12287CRITICALBiagiotti Membership <= 1.0.2 - Authentication Bypass via biagiotti_membership_check_facebook_userEPSS 0.6%CVE-2026-16015MEDIUMpoco-ai poco-claw executor_manager API tasks.py create_task missing authenticationEPSS 0.6%CVE-2026-42560CRITICALauth: Patreon provider assigns the same local user ID to every authenticated Patreon account, enabling cross‑user impersonationEPSS 0.6%CVE-2026-75774MEDIUMkarakeep-app karakeep OAuth Sign-In auth.ts improper authenticationEPSS 0.6%CVE-2023-37226CRITICALLoftware Spectrum before 4.6 HF14 has Missing Authentication for a Critical Function.EPSS 0.6%CVE-2024-56329HIGHAccount Takeover Vulnerability in Social Account Linking in joelbutcher/socialstreamEPSS 0.6%CVE-2018-8862—In ATI Systems Emergency Mass Notification Systems (HPSS16, HPSS32, MHPSS, and ALERT4000) devices, an improper authentication vulnerability EPSS 0.6%CVE-2026-41070CRITICALopenvpn-auth-oauth2 returns FUNC_SUCCESS on client-deny, allowing unauthenticated VPN accessEPSS 0.6%CVE-2026-93960MEDIUMPixelfed OAuth Scope ApiV1Controller.php instancePeers missing authenticationEPSS 0.6%CVE-2026-27197CRITICALSentry: Improper Authentication on SAML SSO process allows user identity linkingEPSS 0.6%CVE-2024-45106HIGHApache Ozone: Improper authentication when generating S3 secretsEPSS 0.6%CVE-2025-27138HIGHDataEase has an improper authentication vulnerabilityEPSS 0.6%CVE-2026-52827HIGHKimai: Two-factor authentication bypass on the Kimai APIEPSS 0.6%CVE-2026-0589MEDIUMcode-projects Online Product Reservation System Administration Backend improper authenticationEPSS 0.6%CVE-2026-59955HIGHApollo ConfigService access key authentication bypass via raw config file appId parsingEPSS 0.6%CVE-2026-48087CRITICALOpenReception: WebAuthn passkey injection allows account takeoverEPSS 0.6%CVE-2026-82906MEDIUMsdcb chats Signed File Download Endpoint FileController.cs DownloadPublic missing authenticationEPSS 0.6%CVE-2023-48312CRITICALAuthentication bypass using an empty token in capsule-proxyEPSS 0.6%CVE-2026-33716CRITICALAVideo Allows Unauthenticated Live Stream Control via Token Verification URL Override in control.json.phpEPSS 0.6%CVE-2026-59954HIGHApollo ConfigService access key authentication bypass via appId parsing and non-canonical matchingEPSS 0.6%