Weaknesses of type CWE-287

2,453 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2026-49843MEDIUMFreeSWITCH: Pre-authentication session eviction via attacker-chosen `sessid` in `mod_verto`EPSS 0.5%CVE-2025-61922CRITICALPrestaShop Checkout allows customer account takeover via emailEPSS 0.5%CVE-2022-46773MEDIUMIBM Robotic Process Automation security bypassEPSS 0.5%CVE-2026-16686HIGHVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.5%CVE-2026-7876CRITICALAuthentication bypass vulnerability found in Aspera High-Speed Transfer Server for Cloud Pak for IntegrationEPSS 0.5%CVE-2025-22375CRITICALAuthentication Bypass in CyberAudit-WebEPSS 0.5%CVE-2018-25236CRITICALHirschmann HiOS HiSecOS Authentication Bypass via HTTP ManagementEPSS 0.5%CVE-2025-56333CRITICALAn issue in Fossorial fosrl/pangolin v.1.6.2 and before allows a remote attacker to escalate privileges via the 2FA componentEPSS 0.5%CVE-2024-44202MEDIUMAn authentication issue was addressed with improved state management. This issue is fixed in Safari 18, iOS 18 and iPadOS 18. Private BrowsiEPSS 0.5%CVE-2026-62669HIGHGrav Login Plugin: 2FA Bypass via 'login.regenerate2FASecret' - Secret Rotation During Pending ChallengeEPSS 0.5%CVE-2026-56675HIGH9router: Reverse proxy locality collapse allows unauthenticated access to 9router /v1 APIsEPSS 0.5%CVE-2026-55727HIGHA flaw in the authentication mechanism for video stream requests in Genetec Security Center 5.14.0.0 prior to build 5.14.178.18 may allow anEPSS 0.5%CVE-2025-3222CRITICALSmallworld SWMFS Improper AuthenticationEPSS 0.5%CVE-2024-37367HIGHRockwell Automation FactoryTalk® View SE v12 Information Leakage Vulnerability via Authentication RestrictionEPSS 0.5%CVE-2024-37368HIGHRockwell Automation FactoryTalk® View SE v11 Information Leakage Vulnerability via Authentication RestrictionEPSS 0.5%CVE-2026-18031CRITICALTabaPay Gateway <= 1.4.0 - Unauthenticated Account Takeover via Payment CallbackEPSS 0.5%CVE-2026-16299CRITICALSingle Sign On For TNG < 2.2.0 - Unauthenticated Arbitrary Password ResetEPSS 0.5%CVE-2026-14182CRITICALCustomer Email Verification for WooCommerce < 3.2.6 - Unauthenticated Account Takeover via Type-Juggling Authentication BypassEPSS 0.5%CVE-2026-59500CRITICALPriority - CWE-287: Improper AuthenticationEPSS 0.5%CVE-2026-14919CRITICALShopMonitor.io < 1.2.0 - Unauthenticated Administrator Account Takeover via Password-Reset Email RerouteEPSS 0.5%