Weaknesses of type CWE-287

2,456 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2026-14205CRITICALWP Events Manager < 2.2.5 - Subscriber+ Payment Bypass via 'qty' ParameterEPSS 0.5%CVE-2026-83261CRITICALVulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Core). The supported version that is afEPSS 0.5%CVE-2026-83269CRITICALVulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versions that are affecteEPSS 0.5%CVE-2026-83355CRITICALVulnerability in the Oracle Enterprise Manager for Fusion Middleware product of Oracle Enterprise Manager (component: Metrics). Supported vEPSS 0.5%CVE-2026-70757CRITICALVulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected areEPSS 0.5%CVE-2026-70756CRITICALVulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected areEPSS 0.5%CVE-2026-83020CRITICALVulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). SupporEPSS 0.5%CVE-2026-82994CRITICALVulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). SupporEPSS 0.5%CVE-2026-83021CRITICALVulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). Supported versions that are affEPSS 0.5%CVE-2026-15611CRITICALUnverified email-based SSO account linkingEPSS 0.5%CVE-2026-34121HIGHAuthentication Bypass in DS Configuration Service via HTTP Request Parsing Differential of TP-Link Tapo C520WSEPSS 0.5%CVE-2026-5076CRITICALARMember Premium <= 7.3.1 - Insecure Password Reset Mechanism to Unauthenticated Privilege EscalationEPSS 0.5%CVE-2026-52893CRITICALWekan: OIDC Account Takeover via Unconditional Email-Based Account Merge in onCreateUser hookEPSS 0.5%CVE-2025-43936HIGHDell ObjectScale, versions prior to ObjectScale 4.4.0.0, contains an Improper Authentication vulnerability. An unauthenticated attacker withEPSS 0.5%CVE-2025-15586CRITICALOGP-Website installs prior git commit 52f865a4fba763594453068acf8fa9e3fc38d663 are affected by a type juggling flaw which if exploited can rEPSS 0.5%CVE-2024-21654MEDIUMrubygems.org MFA Bypass through password reset function could allow account takeover EPSS 0.5%CVE-2026-22752CRITICALSpring Security Authorization Server Dynamic Client Registration endpoints perform insufficient validation of client metadataEPSS 0.5%CVE-2026-55075HIGHCoder vulnerable to OIDC account takeover via email-based user matching and email_verified bypassEPSS 0.5%CVE-2026-34531MEDIUMFlask-HTTPAuth invokes token verification callback when missing or empty token was given by clientEPSS 0.5%CVE-2024-4129HIGHAuthentication bypass in Snow License ManagerEPSS 0.5%