Weaknesses of type CWE-287

2,452 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2023-48865MEDIUMAn issue discovered in Reportico Till 8.1.0 allows attackers to obtain sensitive information via execute_mode parameter of the URL.EPSS 0.6%CVE-2026-24898CRITICALOpenEMR has an Unauthenticated MedEx Token DisclosureEPSS 0.6%CVE-2022-37774MEDIUMThere is a broken access control vulnerability in the Maarch RM 2.8.3 solution. When accessing some specific document (pdf, email) from an aEPSS 0.6%CVE-2026-4592MEDIUMkalcaddle kodbox Password Login index.class.php tfaVerify improper authenticationEPSS 0.6%CVE-2026-14627MEDIUMNousResearch hermes-agent Discord Platform Integration discord.py DiscordAdapter._is_allowed_user improper authenticationEPSS 0.6%CVE-2026-45156HIGHNextcloud: Authentication Bypass in ID4me handling via Missing JWT Signature Verification in User OIDCEPSS 0.6%CVE-2026-47426HIGHOpenAM OAuth Client Impersonation via JWKS Resolver CacheEPSS 0.6%CVE-2025-30361CRITICALWeGIA Vulnerable to Broken Authentication - Old Password ValidationEPSS 0.6%CVE-2026-90474HIGHMCPHub before 1.0.32 OAuth 2.0 Authentication BypassEPSS 0.6%CVE-2026-89136HIGHClient accepts unsolicited RawPublicKey server certificate typeEPSS 0.6%CVE-2026-77567HIGHFilament: App-based MFA can be bypassed when recovery codes are enabledEPSS 0.6%CVE-2025-5985MEDIUMcode-projects School Fees Payment System improper authenticationEPSS 0.6%CVE-2026-16261HIGHHuge IT Login <= 1.0.4 - Unauthenticated Account TakeoverEPSS 0.6%CVE-2022-44610MEDIUMImproper authentication in the Intel(R) DCM software before version 5.1 may allow an authenticated user to potentially enable escalation of EPSS 0.6%CVE-2022-3674HIGHSourceCodester Sanitization Management System missing authenticationEPSS 0.5%CVE-2024-36402MEDIUMUnauthenticated writes to the media repository allow planting of problematic content in Matrix Media RepoEPSS 0.5%CVE-2024-43240CRITICALWordPress Indeed Ultimate Membership Pro plugin <= 12.7 - Unauthenticated Privilege Escalation vulnerabilityEPSS 0.5%CVE-2025-63210CRITICALThe Newtec Celox UHD (models: CELOXA504, CELOXA820) running firmware version celox-21.6.13 is vulnerable to an authentication bypass. An attEPSS 0.5%CVE-2020-16222—Philips Patient Monitoring Devices Improper AuthenticationEPSS 0.5%CVE-2023-36724MEDIUMWindows Power Management Service Information Disclosure VulnerabilityEPSS 0.5%