Weaknesses of type CWE-287

2,456 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2024-13804CRITICALUnauthenticated RCE in HPE Insight Cluster Management UtilityEPSS 0.5%CVE-2025-2388MEDIUMKeytop 路内停车收费系统 API getParks improper authenticationEPSS 0.5%CVE-2026-41571CRITICALNote Mark: OIDC-registered users authenticated by submitting password "null"EPSS 0.5%CVE-2025-3062MEDIUMDrupal Admin LTE theme - Critical - Unsupported - SA-CONTRIB-2025-010EPSS 0.5%CVE-2025-3061MEDIUMMaterial Admin - Critical - Unsupported - SA-CONTRIB-2025-006EPSS 0.5%CVE-2026-72922HIGHAutoGPT: Webhook provider path confusion bypasses generic webhook secret verificationEPSS 0.5%CVE-2023-21027HIGHIn multiple functions of PasspointXmlUtils.java, there is a possible authentication misconfiguration due to a logic error in the code. This EPSS 0.5%CVE-2026-92914HIGHAVideo LoginControl PGP Second Factor Authentication BypassEPSS 0.5%CVE-2025-61665HIGHWeGIA: Broken Access Control in `get_relatorios_socios.php` EndpointEPSS 0.5%CVE-2024-1609HIGHOPPO Store APP has a WebView component privilege escalation vulnerability.EPSS 0.5%CVE-2026-48528CRITICALMetacat has an unauthenticated SQL injection vulnerabilityEPSS 0.5%CVE-2026-86723HIGHAVideo LoginControl PGP Authentication Bypass via verifyChallengeEPSS 0.5%CVE-2023-42662CRITICALJFrog Artifactory Improper SSO Mechanism may lead to Exposure of Access TokensEPSS 0.5%CVE-2026-86722HIGHAVideo Authentication Bypass via SQL Cache InvalidationEPSS 0.5%CVE-2022-24885LOWImproper Authentication in Nextcloud Android FilesEPSS 0.5%CVE-2026-32305HIGHTraefik mTLS bypass via fragmented ClientHello SNI extraction failureEPSS 0.5%CVE-2024-25618MEDIUMExternal OpenID Connect Account Takeover by E-Mail Change in mastodonEPSS 0.5%CVE-2026-50191HIGH4gaBoards: Pre-Account Takeover via SSO Email LinkageEPSS 0.5%CVE-2025-5871MEDIUMPapendorf SOL Connect Center Web Interface missing authenticationEPSS 0.5%CVE-2025-27403HIGHRatify Azure authentication providers can leak authentication tokens to non-Azure container registriesEPSS 0.5%