Weaknesses of type CWE-287

2,456 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2023-28963MEDIUMJunos OS: User-controlled input vulnerability in J-WebEPSS 0.5%CVE-2024-28006MEDIUMImproper authentication vulnerability in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WEPSS 0.5%CVE-2025-15224LOWlibssh key passphrase bypass without agent setEPSS 0.5%CVE-2024-13528HIGHCustomer Email Verification for WooCommerce <= 2.9.5 - Authentication Bypass via ShortcodeEPSS 0.5%CVE-2026-32730HIGHApostropheCMS MFA/TOTP Bypass via Incorrect MongoDB Query in Bearer Token MiddlewareEPSS 0.5%CVE-2022-44595MEDIUMWordPress WP2FA plugin <= 2.2.0 - Broken Authentication vulnerabilityEPSS 0.5%CVE-2026-33898HIGHLocal Incus UI web server vulnerable to nuthentication bypassEPSS 0.5%CVE-2026-10560HIGHUnauthenticated Access to Private Flow Build Events and Cancellation in Langflow OSSEPSS 0.5%CVE-2019-18252—BIOTRONIK CardioMessenger II, The affected products allow credential reuse for multiple authentication purposes. An attacker with adjacent aEPSS 0.5%CVE-2019-18246—BIOTRONIK CardioMessenger II, The affected products do not properly enforce mutual authentication with the BIOTRONIK Remote Communication inEPSS 0.5%CVE-2026-83269CRITICALVulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versions that are affecteEPSS 0.5%CVE-2026-83232CRITICALVulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Console / Repository Explorer). Supported versiEPSS 0.5%CVE-2026-79576CRITICALAn issue in the Single-Sign On (SSO) component of Digital-Infrastructure v9.6.7 allows attackers to authenticate as any user, including the EPSS 0.5%CVE-2026-83452CRITICALVulnerability in the Oracle Document Management and Collaboration product of Oracle E-Business Suite (component: Internal Operations). SuppEPSS 0.5%CVE-2026-82994CRITICALVulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). SupporEPSS 0.5%CVE-2026-83261CRITICALVulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Core). The supported version that is afEPSS 0.5%CVE-2026-14205CRITICALWP Events Manager < 2.2.5 - Subscriber+ Payment Bypass via 'qty' ParameterEPSS 0.5%CVE-2026-83151CRITICALVulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that EPSS 0.5%CVE-2026-83283CRITICALVulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security). The suppoEPSS 0.5%CVE-2026-70757CRITICALVulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected areEPSS 0.5%