Weaknesses of type CWE-287

2,456 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2026-79787CRITICALAlluxio through 2.9.5 S3 REST Proxy Authentication Bypass via Unverified Request SignatureEPSS 0.5%CVE-2026-32879MEDIUMNew API has passkey-based secure step-up verification bypass for root-only channel secret disclosureEPSS 0.5%CVE-2026-44707MEDIUMChatwoot: Pre-Account Takeover via OAuth on Unconfirmed AccountsEPSS 0.5%CVE-2026-13597CRITICALQRcode Login for WeChat <= 1.3 - Unauthenticated Account TakeoverEPSS 0.5%CVE-2025-62169HIGHOctoPrint-SpoolManager Plugin APIs do not enforce authenticationEPSS 0.5%CVE-2026-93964MEDIUMNginxProxyManager nginx-proxy-manager Validate Route certificate.js internalCertificate.validate missing authenticationEPSS 0.5%CVE-2025-8546MEDIUMatjiu pybbs Verification Code login CaptchaEPSS 0.5%CVE-2026-56345CRITICALAVideo - Arbitrary User Session Hijacking via Meet Plugin uploadRecordedVideo EndpointEPSS 0.5%CVE-2021-45035MEDIUMVelneo vClient Improper authenticationEPSS 0.5%CVE-2025-5437MEDIUMMultilaser Sirius RE016 Password Change cstecgi.cgi improper authenticationEPSS 0.5%CVE-2022-35629—Velociraptor Client ID SpoofingEPSS 0.5%CVE-2025-10423MEDIUMnewbee-mall kaptcha mallKaptcha CaptchaEPSS 0.5%CVE-2021-45917HIGHSUN & MOON RISE CO., LTD. Shockwall - Improper AuthenticationEPSS 0.5%CVE-2023-47189MEDIUMWordPress Defender Security plugin <= 4.2.0 - Masked Login Area View Bypass vulnerabilityEPSS 0.5%CVE-2025-71279CRITICALXenForo Passkey Security BypassEPSS 0.5%CVE-2017-20235CRITICALProSoft Technology ICX35-HWC Authentication BypassEPSS 0.5%CVE-2025-12810MEDIUMFailure in Password Rotation and Check-in Mechanism in Secret Server Allows Reuse of CredentialsEPSS 0.5%CVE-2026-49202HIGHUnverified Meeting Recording Endpoints & Permissive CORSEPSS 0.4%CVE-2025-64175HIGHGogs Vulnerable to 2FA Bypass via Recovery CodeEPSS 0.4%CVE-2024-7870MEDIUMPixelYourSite – Your smart PIXEL (TAG) & API Manager <= 9.7.1 and PixelYourSite PRO <= 10.4.2 - Unauthenticated Information Exposure and Log DeletionEPSS 0.4%