Weaknesses of type CWE-287

2,456 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2025-27403HIGHRatify Azure authentication providers can leak authentication tokens to non-Azure container registriesEPSS 0.5%CVE-2023-5328MEDIUMSATO CL4NX-J Plus Cookie improper authenticationEPSS 0.5%CVE-2025-9803CRITICALImproper Authentication in lunary-ai/lunaryEPSS 0.5%CVE-2025-13427MEDIUMAuthentication Bypass in Dialogflow CX MessengerEPSS 0.5%CVE-2024-45346HIGHGetApps application has code execution vulnerabilityEPSS 0.5%CVE-2026-73655HIGHTrigger.dev: Account Takeover via Cross-Provider OAuth Email Matching in Google LoginEPSS 0.5%CVE-2026-73771HIGHImproper Authentication Handling in AOS-CX Management Interface and APIEPSS 0.5%CVE-2025-5872MEDIUMeGauge EG3000 Energy Monitor Setting missing authenticationEPSS 0.5%CVE-2025-5876MEDIUMLucky LM-520-SC/LM-520-FSC/LM-520-FSC-SAM missing authenticationEPSS 0.5%CVE-2026-84831HIGHMandatory MFA bypass before enrollmentEPSS 0.5%CVE-2025-27416MEDIUMAsking For Scratch Username And PasswordEPSS 0.5%CVE-2023-39303MEDIUMQTS, QuTS hero, QuTScloudEPSS 0.5%CVE-2026-21854CRITICALTarkov Data Manager Authentication Bypass vulnerabilityEPSS 0.5%CVE-2026-76338HIGHImproper Authentication through REST API Distributed Search Token Requests in Splunk EnterpriseEPSS 0.5%CVE-2026-13600HIGHAutoNetTV Relay < 3.0.14 - Unauthenticated Privilege Escalation via Scheduled Sync CronEPSS 0.5%CVE-2026-12255HIGHMainWP Child < 6.1.2 - Unauthenticated Administrator Authentication Bypass via Passwordless Site RegistrationEPSS 0.5%CVE-2026-76793HIGHFirebase Authentication < 1.7.1 - Unauthenticated Account Takeover via Firebase Email ClaimEPSS 0.5%CVE-2026-73241HIGHFreeRDP: RDSTLS server authentication bypass: a credential-less Capabilities PDU is accepted at the auth step (fail-open `resultCode`)EPSS 0.5%CVE-2024-49376HIGHAutolab Has Misconfigured Reset Password PermissionsEPSS 0.5%CVE-2026-10845HIGHIBM WebSphere Application Server is affected by an authentication bypass vulnerabilityEPSS 0.5%