Weaknesses of type CWE-287

2,451 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2026-48087CRITICALOpenReception: WebAuthn passkey injection allows account takeoverEPSS 0.6%CVE-2026-59954HIGHApollo ConfigService access key authentication bypass via appId parsing and non-canonical matchingEPSS 0.6%CVE-2022-0985—Insufficient capability checks could allow users with the moodle/site:uploadusers capability to delete users, without having the necessary mEPSS 0.6%CVE-2025-68717CRITICALKAYSUS KS-WR3600 routers with firmware 1.0.5.9.1 allow authentication bypass during session validation. If any user is logged in, endpoints EPSS 0.6%CVE-2024-7050HIGHImproper Authentication vulnerability in OpenText OpenText Directory Services may allow Multi-factor Authentication Bypass in particular sceEPSS 0.6%CVE-2026-4831MEDIUMkalcaddle kodbox Password-protected Share auth.class.php can improper authenticationEPSS 0.6%CVE-2026-4664MEDIUMCustomer Reviews for WooCommerce <= 5.103.0 - Unauthenticated Authentication Bypass to Arbitrary Review Submission via 'key' ParameterEPSS 0.6%CVE-2022-27839LOWImproper authentication vulnerability in SecretMode in Samsung Internet prior to version 16.2.1 allows attackers to access bookmark tab withEPSS 0.6%CVE-2025-49851HIGHImproper Authentication in ControlID iDSecure On-premisesEPSS 0.6%CVE-2026-70482HIGHOpen WebUI: Account takeover via OAuth token exchange accepting tokens issued to any clientEPSS 0.6%CVE-2024-27253CRITICALIBM Engineering Requirements Management DOORS Next is impacted by vulnerability in Reviews delete requestEPSS 0.6%CVE-2024-47070CRITICALauthentik vulnerable to password authentication bypass via X-Forwarded-For HTTP headerEPSS 0.6%CVE-2026-46389CRITICALUDS Identity Config has a client authentication bypass in `ClientIdAndKubernetesSecretAuthenticator`EPSS 0.6%CVE-2026-12597HIGHLoginPress Pro <= 6.2.3 - Unauthenticated Authentication Bypass via Unverified OAuth Email via GitHub OAuth CallbackEPSS 0.6%CVE-2024-41198CRITICALAn issue in Ocuco Innovation - REPORTS.EXE v2.10.24.13 allows attackers to bypass authentication and escalate privileges to Administrator viEPSS 0.6%CVE-2024-41197CRITICALAn issue in Ocuco Innovation - INVCLIENT.EXE v2.10.24.5 allows attackers to bypass authentication and escalate privileges to Administrator vEPSS 0.6%CVE-2024-41195CRITICALAn issue in Ocuco Innovation - INNOVASERVICEINTF.EXE v2.10.24.17 allows attackers to bypass authentication and escalate privileges to AdminiEPSS 0.6%CVE-2025-7114MEDIUMSimStudioAI sim Session route.ts POST missing authenticationEPSS 0.6%CVE-2023-6155MEDIUMQuiz Maker < 6.4.9.5 - Unauthenticated Email Address DisclosureEPSS 0.6%CVE-2022-38982CRITICALThe fingerprint module has service logic errors.Successful exploitation of this vulnerability will cause the phone lock to be cracked.EPSS 0.6%