Weaknesses of type CWE-287

2,453 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2026-83061CRITICALVulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Supported versions that arEPSS 0.5%CVE-2026-83042CRITICALVulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are afEPSS 0.5%CVE-2026-83099CRITICALVulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). Supported versions that aEPSS 0.5%CVE-2026-83339CRITICALVulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versionsEPSS 0.5%CVE-2026-73947CRITICALVulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that EPSS 0.5%CVE-2026-83066CRITICALVulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Supported versions that arEPSS 0.5%CVE-2026-46890CRITICALVulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Marketing). Supported versions that are affected are EPSS 0.5%CVE-2026-1740MEDIUMEFM ipTIME A8004T Hidden Hiddenloginsetup timepro.cgi httpcon_check_session_url improper authenticationEPSS 0.5%CVE-2025-67158HIGHAn authentication bypass in the /cgi-bin/jvsweb.cgi endpoint of Revotech I6032W-FHW v1.0.0014 - 20210517 allows attackers to access sensitivEPSS 0.5%CVE-2026-19607MEDIUMKeycloak-services: keycloak-services: broker-originated username collision causes account lockoutEPSS 0.5%CVE-2026-93532MEDIUMgedelumbung HospitalManagement Password Change password.php simpan improper authenticationEPSS 0.5%CVE-2026-78863MEDIUMliketrek TREK Pre-2FA mfa_token authService.ts loginUser improper authenticationEPSS 0.5%CVE-2026-18216MEDIUMBackup Migration < 2.1.7 - Admin+ Privilege Escalation via Post-Restore Auto-LoginEPSS 0.5%CVE-2026-5557MEDIUMbadlogic pi-mono pi-mom Slack Bot slack.ts authentication bypassEPSS 0.5%CVE-2026-16076MEDIUMAstrBotDevs AstrBot API open_api.py OpenApiRoute.chat_send authentication spoofingEPSS 0.5%CVE-2025-14002HIGHWPCOM Member <= 1.7.16 - Authentication Bypass via Weak OTPEPSS 0.5%CVE-2024-55954HIGHOpenObserve Improper Authorization Allows Admin User to Remove Root UserEPSS 0.5%CVE-2024-45750HIGHAn issue in TheGreenBow Windows Standard VPN Client 6.87.108 (and older), Windows Enterprise VPN Client 6.87.109 (and older), Windows EnterpEPSS 0.5%CVE-2019-3825MEDIUMA vulnerability was discovered in gdm before 3.31.4. When timed login is enabled in configuration, an attacker could bypass the lock screen EPSS 0.5%CVE-2026-57216MEDIUMRabbitMQ: AMQP 1.0, AMQP 0-9-1, Stream Protocol loopback enforcement can lead to remote guest sessions due to listener-address loopback checksEPSS 0.5%