Weaknesses of type CWE-287

2,430 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2021-4073CRITICALRegistrationMagic <= 5.0.1.7 Authentication BypassEPSS 7.0%CVE-2025-63207CRITICALThe R.V.R Elettronica TEX product (firmware TEXL-000400, Web GUI TLAN-000400) is vulnerable to broken access control due to improper authentEPSS 7.0%CVE-2026-41276HIGHFlowise: AccountService resetPassword Authentication Bypass VulnerabilityEPSS 6.9%CVE-2023-37266CRITICALWeak json web token (JWT) secrets in CasaOSEPSS 6.8%CVE-2017-12337—A vulnerability in the upgrade mechanism of Cisco collaboration products based on the Cisco Voice Operating System software platform could aEPSS 6.4%CVE-2020-12145MEDIUMSilver Peak Unity OrchestratorTM authentication can be subverted through manipulation of HTTP headers.EPSS 6.0%CVE-2022-39290HIGHCSRF key bypass using HTTP methods in zoneminderEPSS 6.0%CVE-2021-21513HIGHDell EMC OpenManage Server Administrator (OMSA) version 9.5 Microsoft Windows installations with Distributed Web Server (DWS) enabled configEPSS 5.9%CVE-2022-0715HIGHA CWE-287: Improper Authentication vulnerability exists that could cause an attacker to arbitrarily change the behavior of the UPS when a keEPSS 5.8%CVE-2025-10365CRITICALAuthentication Bypass in Evertz SDVNEPSS 5.6%CVE-2022-0492HIGHA vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certaEPSS 5.5%KEVCVE-2017-6747—A vulnerability in the authentication module of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypaEPSS 5.5%CVE-2021-34993CRITICALThis vulnerability allows remote attackers to bypass authentication on affected installations of Commvault CommCell 11.22.22. AuthenticationEPSS 5.4%CVE-2019-1917CRITICALCisco Vision Dynamic Signage Director REST API Authentication Bypass VulnerabilityEPSS 5.3%CVE-2019-12643CRITICALCisco REST API Container for IOS XE Software Authentication Bypass VulnerabilityEPSS 5.3%CVE-2017-12229—A vulnerability in the REST API of the web-based user interface (web UI) of Cisco IOS XE 3.1 through 16.5 could allow an unauthenticated, reEPSS 5.2%CVE-2017-16748—An attacker can log into the local Niagara platform (Niagara AX Framework Versions 3.8 and prior or Niagara 4 Framework Versions 4.4 and priEPSS 5.1%CVE-2018-0238—A vulnerability in the role-based resource checking functionality of the Cisco Unified Computing System (UCS) Director could allow an authenEPSS 5.1%CVE-2018-10611—Java remote method invocation (RMI) input port in GE MDS PulseNET and MDS PulseNET Enterprise version 3.2.1 and prior may be exploited to alEPSS 5.0%CVE-2012-5864—Sinapsi eSolar Improper AuthenticationEPSS 4.9%