Weaknesses of type CWE-287

2,452 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2025-11529MEDIUMChurchCRM API Endpoint AuthMiddleware.php AuthMiddleware missing authenticationEPSS 0.5%CVE-2025-30116HIGHAn issue was discovered on the Forvia Hella HELLA Driving Recorder DR 820. Remotely Dumping of Video Footage and the Live Video Stream can oEPSS 0.5%CVE-2024-56336CRITICALA vulnerability has been identified in SINAMICS S200 (All versions with serial number beginning with SZVS8, SZVS9, SZVS0 or SZVSN and the FSEPSS 0.5%CVE-2026-64665HIGHStatamic: Account takeover via OAuth email matching without email-verification checkEPSS 0.5%CVE-2023-4242MEDIUMFULL - Customer <= 2.2.3 - Authenticated(Subscriber+) Information Disclosure via Health CheckEPSS 0.5%CVE-2024-10114HIGHSocial Login - WordPress / WooCommerce Plugin <= 2.7.7 - Authentication Bypass via WordPress.com OAuth providerEPSS 0.5%CVE-2026-73054HIGHSiYuan before v3.7.4 Authentication Bypass via WebSocketEPSS 0.5%CVE-2022-46172MEDIUMauthentik allows existing authenticated users to create arbitrary accountsEPSS 0.5%CVE-2026-82107CRITICALDataStage on Cloud Pak for Data has several vulnerabilities due to open source softwareEPSS 0.5%CVE-2026-31377HIGHApache Doris: Improper Authentication Allows Unauthorized Access to FE Meta ServiceEPSS 0.5%CVE-2024-52518MEDIUMNextcloud Server is missing password confirmation when changing external storage optionsEPSS 0.5%CVE-2026-9371MEDIUMItzCrazyKns Vane API route.ts missing authenticationEPSS 0.5%CVE-2025-47275CRITICALBrute Force Authentication Tags of CookieStore Sessions in Auth0-PHP SDKEPSS 0.5%CVE-2021-4197—An unprivileged write to the file handler flaw in the Linux kernel's control groups and namespaces subsystem was found in the way users haveEPSS 0.5%CVE-2022-36071HIGHRecovery codes abuse in SFTPGoEPSS 0.5%CVE-2026-4349MEDIUMDuende IdentityServer4 Token Renewal Endpoint authorize improper authenticationEPSS 0.5%CVE-2026-58423HIGHLFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositoriesEPSS 0.5%CVE-2026-22236CRITICALImproper Authentication Vulnerability in BLUVOYIXEPSS 0.5%CVE-2026-2249CRITICALUnauthenticated Remote Command Execution via Web Console in METIS DFSEPSS 0.5%CVE-2026-2248CRITICALUnauthenticated Remote Root Shell Access via Web Console in METIS WICEPSS 0.5%