Weaknesses of type CWE-287

2,452 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2026-60367CRITICALVulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). SupporEPSS 0.5%CVE-2023-44039CRITICALIn VeridiumID before 3.5.0, the WebAuthn API allows an internal unauthenticated attacker (who can pass enrollment verifications and is allowEPSS 0.5%CVE-2025-9965CRITICALUDP Service Weak AuthenticationEPSS 0.5%CVE-2025-9100MEDIUMzhenfeng13 My-Blog Frontend Blog Article Comment comment authentication replayEPSS 0.5%CVE-2023-37268MEDIUMUser login confusion with SSO in warpgateEPSS 0.5%CVE-2025-11661MEDIUMProjectsAndPrograms School Management System missing authenticationEPSS 0.5%CVE-2024-21543MEDIUMVersions of the package djoser before 2.3.0 are vulnerable to Authentication Bypass when the authenticate() function fails. This is because EPSS 0.5%CVE-2026-2065MEDIUMFlycatcher Toys smART Pixelator Bluetooth Low Energy missing authenticationEPSS 0.5%CVE-2023-23857CRITICALImproper Access Control in SAP NetWeaver AS for JavaEPSS 0.5%CVE-2022-26508MEDIUMImproper authentication in the Intel(R) SDP Tool before version 3.0.0 may allow an unauthenticated user to potentially enable information diEPSS 0.5%CVE-2023-47222CRITICALMedia Streaming add-onEPSS 0.5%CVE-2024-45823CRITICALFactoryTalk® Batch View™ Authentication Bypass Vulnerability via shared secretsEPSS 0.5%CVE-2024-23647MEDIUMPKCE downgrade attack in AuthentikEPSS 0.5%CVE-2024-41199HIGHAn issue in Ocuco Innovation - JOBMANAGER.EXE v2.10.24.16 allows attackers to bypass authentication and escalate privileges to AdministratorEPSS 0.5%CVE-2026-50623MEDIUMApache CXF: Authentication Bypass in OAuth2 TokenIntrospectionServiceEPSS 0.5%CVE-2026-18786HIGHCheckView < 2.3.2 - Administrator Account Creation via REST API Authentication BypassEPSS 0.5%CVE-2026-2991HIGHKiviCare – Clinic & Patient Management System (EHR) <= 4.1.2 - Unauthenticated Authentication Bypass via Social Login TokenEPSS 0.5%CVE-2024-41798CRITICALA vulnerability has been identified in SENTRON 7KM PAC3200 (All versions). Affected devices only provide a 4-digit PIN to protect from adminEPSS 0.5%CVE-2026-50365HIGHRemote Access Management service/API (RPC server) Elevation of Privilege VulnerabilityEPSS 0.5%CVE-2026-56080MEDIUMCap-go - Authentication Logic Flaw in Enforce Password PolicyEPSS 0.5%