Weaknesses of type CWE-287

2,430 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2021-1571HIGHCisco Small Business 220 Series Smart Switches VulnerabilitiesEPSS 9.7%CVE-2025-9533MEDIUMTOTOLINK T10 formLoginAuth.htm improper authenticationEPSS 9.4%CVE-2021-1543HIGHCisco Small Business 220 Series Smart Switches VulnerabilitiesEPSS 9.3%CVE-2012-6440MEDIUMRockwell Automation ControlLogix PLC Improper Input ValidationEPSS 9.3%CVE-2016-2125MEDIUMIt was found that Samba before versions 4.5.3, 4.4.8, 4.3.13 always requested forwardable tickets when using Kerberos authentication. A servEPSS 9.2%CVE-2025-44005CRITICALAn attacker can bypass authorization checks and force a Step CA ACME or SCEP provisioner to create certificates without completing certain pEPSS 9.1%CVE-2021-1541HIGHCisco Small Business 220 Series Smart Switches VulnerabilitiesEPSS 8.8%CVE-2018-10682CRITICALAn issue was discovered in WildFly 10.1.2.Final. It is possible for an attacker to access the administration panel on TCP port 9990 without EPSS 8.3%CVE-2021-39165HIGHUnauthenticated SQL InjectionEPSS 8.2%CVE-2025-59934CRITICALFormbricks missing JWT signature verificationEPSS 8.1%CVE-2012-6437CRITICALRockwell Automation ControlLogix PLC Improper AuthenticationEPSS 7.8%CVE-2018-14826—Entes EMG12 versions 2.57 and prior The application uses a web interface where it is possible for an attacker to bypass authentication with EPSS 7.7%CVE-2025-53786HIGHMicrosoft Exchange Server Hybrid Deployment Elevation of Privilege VulnerabilityEPSS 7.7%CVE-2026-82329CRITICALPotential authentication bypass leading to administrative access in ArtifactoryEPSS 7.7%KEVCVE-2021-24527—Profile Builder < 3.4.9 - Admin Access via Password ResetEPSS 7.6%CVE-2018-7532—Unauthentication vulnerabilities have been identified in Geutebruck G-Cam/EFD-2250 Version 1.12.0.4 and Topline TopFD-2125 Version 3.15.1 IPEPSS 7.6%CVE-2024-5805CRITICALMOVEit Gateway Authentication Bypass VulnerabilityEPSS 7.6%CVE-2025-4755MEDIUMD-Link DI-7003GV2 netconfig.asp sub_497DE4 improper authenticationEPSS 7.3%CVE-2025-46631MEDIUMImproper access controls in the web management portal of the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated remote attacker to enable tEPSS 7.2%CVE-2021-42949CRITICALThe component controlla_login function in HotelDruid Hotel Management Software v3.0.3 generates a predictable session token, allowing attackEPSS 7.1%