Weaknesses of type CWE-287

2,456 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2026-49186HIGHLack of MQTT Broker Topic Access Control ListsEPSS 0.5%CVE-2025-62376CRITICALpwn.college DOJO vulnerable to improper authentication in workspace endpoint allowing unauthorized Windows VM accessEPSS 0.5%CVE-2023-38691MEDIUMmatrix-appservice-bridge doesn't verify the sub parameter of an openId token exhange, allowing unauthorized access to provisioning APIsEPSS 0.5%CVE-2024-9927HIGHWooCommerce Order Proposal <= 2.0.5 - Authenticated (Shop Manager+) Privilege Escalation via Order ProposalEPSS 0.5%CVE-2026-10845HIGHIBM WebSphere Application Server is affected by an authentication bypass vulnerabilityEPSS 0.5%CVE-2025-14097HIGHRemote Code Execution Vulnerability in Radiometer ProductsEPSS 0.5%CVE-2026-73085MEDIUMAudiobookshelf: Refresh Token Accepted on Resource EndpointsEPSS 0.5%CVE-2026-55377HIGHLogto: Account Center MFA management step-up bypass via WebAuthn registration verificationEPSS 0.5%CVE-2020-7295LOWWeb Gateway (MWG) - Privilege Escalation vulnerabilityEPSS 0.5%CVE-2024-47078HIGHMeshtastic firmware Authentication/Authorization Bypass via MQTTEPSS 0.5%CVE-2026-73337HIGHJoomla! Core - [20260807] - MFA Authentication Bypass in Joomla 4.0.0-5.4.7 and 6.0.0-6.1.2EPSS 0.5%CVE-2026-46488CRITICALmotionEye: Authentication possible via password hashEPSS 0.5%CVE-2026-83327CRITICALVulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Personalization). Supported versions thatEPSS 0.5%CVE-2025-62349HIGHSalt Master authentication protocol downgrade may enable minion impersonationEPSS 0.5%CVE-2026-48114CRITICALMetacat has an unauthenticated SQL injection vulnerabilityEPSS 0.5%CVE-2026-21582HIGHThis High severity BASM (Broken Authentication & Session Management) vulnerability known as CVE-2026-21582 was introduced in version 7.2.1 oEPSS 0.5%CVE-2023-23761HIGHImproper authentication vulnerability in GitHub Enterprise Server leading to modification of secret gistsEPSS 0.5%CVE-2021-25910HIGHZIV AUTOMATION 4CCT vulnerable to improper authenticationEPSS 0.5%CVE-2026-44847HIGHMaxKB: Webhook Trigger Authentication BypassEPSS 0.5%CVE-2025-5870MEDIUMTRENDnet TV-IP121W Web Interface setup.cgi improper authenticationEPSS 0.5%