Weaknesses of type CWE-287

2,453 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2024-34399CRITICAL**UNSUPPORTED WHEN ASSIGNED** An issue was discovered in BMC Remedy Mid Tier 7.6.04. An unauthenticated remote attacker is able to access anEPSS 0.5%CVE-2025-64055CRITICALAn issue was discovered in Fanvil x210 V2 2.12.20 allowing unauthenticated attackers on the local network to access administrative functionsEPSS 0.5%CVE-2026-61436HIGHPraisonAI before 4.6.78 Missing Webhook Signature VerificationEPSS 0.5%CVE-2026-54547HIGHMeta Ads MCP: X-Pipeboard-Token Header Auth Bypass Reuses Operator Meta TokenEPSS 0.5%CVE-2025-49591HIGHCryptPad 2FA Bypass VulnerabilityEPSS 0.5%CVE-2026-50338HIGHAzure Spring Apps Elevation of Privilege VulnerabilityEPSS 0.5%CVE-2026-56237CRITICALCapgo - Unauthenticated API Key Generation via Client-Side Parameter ManipulationEPSS 0.5%CVE-2024-10620MEDIUMknightliao Disconf Configuration Center list improper authenticationEPSS 0.5%CVE-2023-1980MEDIUMTwo factor authentication bypass on login in Devolutions Remote Desktop Manager 2022.3.35 and earlier allow user to cancel the two factorEPSS 0.5%CVE-2026-15372HIGHWP 2FA < 4.1.0 - Two-Factor Authentication Bypass via Passkeys ProviderEPSS 0.5%CVE-2024-38523HIGHHush Line OTP issueEPSS 0.5%CVE-2021-32738MEDIUMUtils.readChallengeTx does not verify the server account signatureEPSS 0.5%CVE-2024-11917HIGHJobSearch WP Job Board <= 2.9.2 - Authentication Bypass via Social LoginsEPSS 0.5%CVE-2024-36444HIGHcgi-bin/fdmcgiwebv2.cgi on Swissphone DiCal-RED 4009 devices allows an unauthenticated attacker to gain access to device logs.EPSS 0.5%CVE-2026-14557CRITICALSoftMarket <= 1.0.0 - Unauthenticated Account Takeover via Email Verification BypassEPSS 0.5%CVE-2024-11293HIGHRegistration Forms – User Registration Forms, Invitation-Based Registrations, Front-end User Profile, Login Form & Content Restriction Social Sites Login <= 1.7.9 - Authentication Bypass via WordPress.com OAuth providerEPSS 0.5%CVE-2025-15581MEDIUMOrthanc versions before 1.12.10 are affected by an authorisation logic flaw in the application's HTTP Basic Authentication implementation. EPSS 0.5%CVE-2024-41929HIGHImproper authentication vulnerability in multiple digital video recorders provided by TAKENAKA ENGINEERING CO., LTD. allows a remote authentEPSS 0.5%CVE-2022-39231LOWParse Server subject to Improper Authentication allowing Auth adapter app ID validation to be circumventedEPSS 0.5%CVE-2025-23116CRITICALAn Authentication Bypass vulnerability on UniFi Protect Application with Auto-Adopt Bridge Devices enabled could allow a malicious actor witEPSS 0.5%