Weaknesses of type CWE-287

2,451 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2026-89093MEDIUMBetter Messages <= 2.15.33 - Unauthenticated Information Exposure Spoofing via 'X-Real-IP' Header via /guests/registerEPSS 0.6%CVE-2026-44476MEDIUMDoorkeeper OpenID Connect: Dynamic Client Registration feature creates public clients with client_secretEPSS 0.6%CVE-2025-11287MEDIUMsamanhappy MCPHub sseService.ts handleSseConnectionfunction improper authenticationEPSS 0.6%CVE-2023-28962MEDIUMJunos OS: Unauthenticated access vulnerability in J-WebEPSS 0.6%CVE-2023-3127HIGHImproper Authentication in iSTAREPSS 0.6%CVE-2024-10327HIGHA vulnerability in Okta Verify for iOS versions 9.25.1 (beta) and 9.27.0 (including beta) allows push notification responses through the iOSEPSS 0.6%CVE-2025-52395CRITICALAn issue in Roadcute API v.1 allows a remote attacker to execute arbitrary code via the application exposing a password reset API endpoint tEPSS 0.6%CVE-2026-18922CRITICAL389-ds-base: 389-ds-base: sasl plain authentication allows privilege escalation to directory manager via stale identity in cyrus sasl auxiliary propertyEPSS 0.6%CVE-2021-25368LOWHijacking vulnerability in Samsung Cloud prior to version 4.7.0.3 allows attackers to intercept when the provider is executed.EPSS 0.6%CVE-2023-51471HIGHWordPress Checkout Mestres WP plugin <= 7.1.9.7 - Unauthenticated Arbitrary Options Update vulnerabilityEPSS 0.6%CVE-2024-12919CRITICALPaid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction <= 2.13.7 - Authentication Bypass via pms_payment_idEPSS 0.6%CVE-2023-48703HIGHSAML authentication bypass vulnerability in RobotsAndPencils/go-samlEPSS 0.6%CVE-2026-33432HIGHRoxy-WI has Pre-Authentication LDAP Injection that Leads to Authentication BypassEPSS 0.6%CVE-2026-12595HIGHLoginPress Pro <= 6.2.3 - Unauthenticated Authentication Bypass via Unverified OAuth Email via Discord OAuth CallbackEPSS 0.6%CVE-2026-12598HIGHLoginPress Pro <= 6.2.3 - Unauthenticated Authentication Bypass via Unverified OAuth Email in Spotify OAuth CallbackEPSS 0.6%CVE-2025-6533MEDIUMxxyopen/201206030 novel-plus CATCHA LoginController.java ajaxLogin authentication replayEPSS 0.6%CVE-2025-49812HIGHApache HTTP Server: mod_ssl TLS upgrade attackEPSS 0.6%CVE-2026-20317CRITICALCisco Secure Workload Software Security Hardening Release August 2026 - Improper Authentication VulnerabilitiesEPSS 0.6%CVE-2026-72533HIGHPortainer Portainer CE - Authentication BypassEPSS 0.6%CVE-2026-33409HIGHParse Server: Auth provider validation bypass on login via partial authDataEPSS 0.6%