Weaknesses of type CWE-287

2,453 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2026-2248CRITICALUnauthenticated Remote Root Shell Access via Web Console in METIS WICEPSS 0.5%CVE-2025-32879HIGHAn issue was discovered on COROS PACE 3 devices through 3.0808.0. It starts advertising if no device is connected via Bluetooth. This allowsEPSS 0.5%CVE-2024-9947HIGHProfilePress - Pro <= 4.11.1 - Authentication Bypass via WordPress.com OAuth providerEPSS 0.5%CVE-2026-56793HIGHDell OpenManage Server Administrator, versions prior to 11.1.0.2, contains an Improper Authentication vulnerability. An unauthenticated attaEPSS 0.5%CVE-2022-23540MEDIUMjsonwebtoken vulnerable to signature validation bypass due to insecure default algorithm in jwt.verify()EPSS 0.5%CVE-2026-9373MEDIUMJeecgBoot OpenAPI Endpoint call improper authenticationEPSS 0.5%CVE-2026-14291HIGHSecurity Ninja (Premium) < 5.290 - Two-Factor Authentication Bypass via secnin_skip_2faEPSS 0.5%CVE-2025-6979HIGHCaptive Portal can allow authentication bypassEPSS 0.5%CVE-2025-6172CRITICALPermission vulnerability in the mobile application (com.afmobi.boomplayer) may lead to the risk of unauthorized operation.EPSS 0.5%CVE-2024-57432HIGHmacrozheng mall-tiny 1.0.1 suffers from Insecure Permissions. The application's JWT signing keys are hardcoded and do not change. User inforEPSS 0.5%CVE-2025-8838MEDIUMWinterChenS my-site Backend admin preHandle improper authenticationEPSS 0.5%CVE-2026-36727CRITICALAn insecure authentication vulnerability in the /api/social-sign-in endpoint of bookcars v8.3 allows attackers to bypass authentication via EPSS 0.5%CVE-2026-44196CRITICALPingvin Share X: TOTP Authentication Bypass via Password-only LoginEPSS 0.5%CVE-2025-8348MEDIUMKehua Charging Pile Cloud Platform home improper authenticationEPSS 0.5%CVE-2026-32815MEDIUMSiYuan: Cross-Origin WebSocket Hijacking via Authentication Bypass — Unauthenticated Information DisclosureEPSS 0.5%CVE-2025-56752CRITICALA vulnerability in the Ruijie RG-ES series switch firmware ESW_1.0(1)B1P39 enables remote attackers to fully bypass authentication mechanismEPSS 0.5%CVE-2020-5224MEDIUMSession key exposure through session list in Django User SessionsEPSS 0.5%CVE-2024-11671MEDIUMImproper authentication in SQL data source MFA validation in Devolutions Remote Desktop Manager 2024.3.17 and earlier on Windows allows an aEPSS 0.5%CVE-2026-49872MEDIUMApache APISIX: Improper authentication in cas-auth pluginEPSS 0.5%CVE-2025-9994CRITICALAmp’ed RF BT-AP 111 Bluetooth access point's HTTP admin interface does not require authenticationEPSS 0.5%