Weaknesses of type CWE-287

2,453 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2026-61641HIGHWallos: OIDC account takeover via email-based account linking without `email_verified` checkEPSS 0.5%CVE-2026-49191CRITICALExposed Hard-coded M3WebServer Backend API KeyEPSS 0.5%CVE-2026-49197CRITICALPredator Connect W6x: Improper AuthenticationEPSS 0.5%CVE-2026-17175HIGHIBM Db2 Mirror for i is affected by multiple vulnerabilitiesEPSS 0.5%CVE-2024-50640CRITICALjeewx-boot 1.3 has an authentication bypass vulnerability in the preHandle functionEPSS 0.5%CVE-2025-41023MEDIUMAuthentication bypass in AutoGPT de ThesamurEPSS 0.5%CVE-2024-10020HIGHHeateor Social Login WordPress <= 1.1.35 - Authentication Bypass via Disqus OAuth providerEPSS 0.5%CVE-2024-47761HIGHGLPI vulnerable to account takeover via the password reset featureEPSS 0.5%CVE-2026-6456HIGHAccount Switcher <= 1.0.2 - Authenticated (Subscriber+) Authentication Bypass to Privilege EscalationEPSS 0.5%CVE-2026-44986CRITICALPenpot: Pre-authenticated account takeover via team-invitation token + prepare-register-profileEPSS 0.5%CVE-2022-39360MEDIUMMetabase SSO users able to circumvent IdP login by doing password resetEPSS 0.5%CVE-2023-25790MEDIUMWordPress WoodMart theme <= 7.0.4 - Unauth Arbitrary Shortcodes InjectionEPSS 0.5%CVE-2026-4101HIGHSecurity Vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify AccessEPSS 0.5%CVE-2026-42210MEDIUMWebmin 2FA requirement bypassEPSS 0.5%CVE-2023-38735MEDIUMIBM Cognos Dashboards improper authenticationEPSS 0.5%CVE-2023-45669MEDIUMImproper signature counter value handling in webauthn4j-spring-security EPSS 0.5%CVE-2023-25559HIGHSystem account impersonation in DataHubEPSS 0.5%CVE-2023-41089HIGHImproper Authentication in DEXMA DEXGateEPSS 0.5%CVE-2024-23637MEDIUMOctoPrint Unverified Password Change via Access Control SettingsEPSS 0.5%CVE-2026-3739MEDIUMsuitenumerique messages ThreadAccess serializers.py ThreadAccessSerializer improper authenticationEPSS 0.5%