Weaknesses of type CWE-287

2,456 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2026-27939HIGHStatamic allows Authenticated Control Panel users to escalate privileges via elevated session bypassEPSS 0.5%CVE-2026-44847HIGHMaxKB: Webhook Trigger Authentication BypassEPSS 0.5%CVE-2026-40138CRITICALCritical Pre-Authentication Vulnerability in BeyondTrust Remote Support and Privileged Remote AccessEPSS 0.5%CVE-2024-41800MEDIUMCraft CMS Allows TOTP Token To Stay Valid After UseEPSS 0.5%CVE-2025-0637CRITICALInadequate access control in Beta10EPSS 0.5%CVE-2026-84114MEDIUMCleo Harmony SAML Authentication LocalUserUtil.getNativeUserByAssertions improper authenticationEPSS 0.5%CVE-2023-35901LOWIBM Robotic Process Automation security bypassEPSS 0.5%CVE-2024-11087HIGHminiOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) Pro Addon <= 200.3.9 - Authentication BypassEPSS 0.5%CVE-2026-47718MEDIUMFUXA provides guest and invalid-token access to protected read APIs in secure modeEPSS 0.5%CVE-2025-53845MEDIUMAn improper authentication vulnerability [CWE-287] in Fortinet FortiAnalyzer version 7.6.0 through 7.6.3 and before 7.4.6 allows an unauthenEPSS 0.5%CVE-2024-38810MEDIUMMissing Authorization When Using @AuthorizeReturnObjectEPSS 0.5%CVE-2025-27621HIGHUpTrain has a Constant Default API KeyEPSS 0.5%CVE-2025-59280LOWWindows SMB Client Tampering VulnerabilityEPSS 0.5%CVE-2023-26150MEDIUMVersions of the package asyncua before 0.9.96 are vulnerable to Improper Authentication such that it is possible to access Address Space witEPSS 0.5%CVE-2026-16905MEDIUMIBM Db2 Mirror for i is affected by multiple vulnerabilitiesEPSS 0.5%CVE-2026-73777HIGHAuthorization Bypass Vulnerabilities Leading to Privilege Escalation in AOS-CX API EndpointEPSS 0.5%CVE-2026-68760MEDIUMPotential remember-me authentication bypass in JFrog ArtifactoryEPSS 0.5%CVE-2024-14034CRITICALHirschmann HiEOS Authentication Bypass via HTTP Management ModuleEPSS 0.5%CVE-2026-76684HIGHAuthentication Bypass Vulnerabilities in HPE Networking EdgeConnect SD-WAN Orchestrator APIEPSS 0.5%CVE-2026-79938HIGHDell PowerProtect Cyber Recovery, versions prior to 20.3, contain an Improper Authentication vulnerability. A low privileged attacker with rEPSS 0.5%