Weaknesses of type CWE-287

2,453 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2026-12492CRITICALHappy Coders OTP Login for WooCommerce < 2.8 - Unauthenticated Account Takeover via hcotp_auto_login_userEPSS 0.5%CVE-2026-100746MEDIUMcoollabsio Coolify GitHub App Setup redirect missing authenticationEPSS 0.5%CVE-2026-86707CRITICALPrivate Feed Key <= 0.1 - Unauthenticated Authentication Bypass via 'feedkey' ParameterEPSS 0.5%CVE-2024-37367HIGHRockwell Automation FactoryTalk® View SE v12 Information Leakage Vulnerability via Authentication RestrictionEPSS 0.5%CVE-2026-14182CRITICALCustomer Email Verification for WooCommerce < 3.2.6 - Unauthenticated Account Takeover via Type-Juggling Authentication BypassEPSS 0.5%CVE-2026-86710CRITICALLogin with QR <= 1.0.0 - Unauthenticated Authentication Bypass via 'autologin_code' ParameterEPSS 0.5%CVE-2024-37368HIGHRockwell Automation FactoryTalk® View SE v11 Information Leakage Vulnerability via Authentication RestrictionEPSS 0.5%CVE-2026-16299CRITICALSingle Sign On For TNG < 2.2.0 - Unauthenticated Arbitrary Password ResetEPSS 0.5%CVE-2026-7664CRITICALUnauthenticated Flow Execution via Webhook Endpoint in Langflow OSSEPSS 0.5%CVE-2025-12374CRITICALEmail Verification, Email OTP, Block Spam Email, Passwordless login, Hide Login, Magic Login – User Verification <= 2.0.44 - Authentication Bypass to Account TakeoverEPSS 0.5%CVE-2023-22663MEDIUMImproper authentication for some Intel Unison software may allow an authenticated user to potentially enable escalation of privilege via netEPSS 0.5%CVE-2026-95676HIGHAuthPoint Gateway Improper Authentication in LDAP Sync Allows First-Factor Authentication BypassEPSS 0.5%CVE-2023-46172MEDIUMIBM DS8900F security bypassEPSS 0.5%CVE-2026-10288MEDIUMcode-projects Hotel and Tourism Reservation System Admin Login login.php password_verify improper authenticationEPSS 0.5%CVE-2026-33117CRITICALAzure SDK for Java Security Feature Bypass VulnerabilityEPSS 0.5%CVE-2026-17197HIGHIBM i is Affected By Multiple Vulnerabilities in Host ServersEPSS 0.5%CVE-2022-34331MEDIUMIBM Power FW security bypassEPSS 0.5%CVE-2026-86721HIGHAVideo through c3edcc274c Authorization Bypass via Session CookieEPSS 0.5%CVE-2024-35184MEDIUMpaperless-ngx's remote user auth via header works even when disabling it for APIEPSS 0.5%CVE-2024-22441CRITICALHPE Cray Parallel Application Launch Service (PALS) is subject to an authentication bypass.EPSS 0.5%