Weaknesses of type CWE-287

2,457 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2025-64175HIGHGogs Vulnerable to 2FA Bypass via Recovery CodeEPSS 0.4%CVE-2026-21633HIGHA malicious actor with access to the adjacent network could obtain unauthorized access to a UniFi Protect Camera by exploiting a discovery pEPSS 0.4%CVE-2026-56219HIGHCapgo - Unauthenticated RBAC Bindings and Email Disclosure via get_org_user_access_rbac NULL-auth BypassEPSS 0.4%CVE-2023-46630HIGHWordPress Admin and Site Enhancements (ASE) plugin <= 5.7.1 - Password Protected View Bypass Vulnerability vulnerabilityEPSS 0.4%CVE-2026-13447CRITICALMStore API <= 4.20.0 - Unauthenticated Authentication Bypass via 'id_token' Parameter JWT ForgeryEPSS 0.4%CVE-2026-41081MEDIUMApache Storm Client: Anonymous principal assigned on TLS client certificate verification failureEPSS 0.4%CVE-2026-33665HIGHn8n: LDAP Email-Based Account Linking Allows Privilege Escalation and Account TakeoverEPSS 0.4%CVE-2026-40177CRITICALPassword bypass when 2FA is activatedEPSS 0.4%CVE-2021-41503HIGHDCS-5000L v1.05 and DCS-932L v2.17 and older are affecged by Incorrect Acess Control. The use of the basic authentication for the devices coEPSS 0.4%CVE-2026-45754MEDIUMSymfony: Mailjet Mailer Webhook Parser Never Verifies the Configured Secret — Unauthenticated Webhook Event InjectionEPSS 0.4%CVE-2026-52845HIGHCaddy: FastCGI header normalization bypass in `forward_auth copy_headers`EPSS 0.4%CVE-2025-15456MEDIUMbg5sbk MiniCMS Publish page-edit.php improper authenticationEPSS 0.4%CVE-2023-47256MEDIUMConnectWise ScreenConnect through 23.8.4 allows local users to connect to arbitrary relay servers via implicit trust of proxy settingsEPSS 0.4%CVE-2026-12359HIGHSecurity vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify AccessEPSS 0.4%CVE-2024-5012HIGHWhatsUp Gold Missing Authentication GetWindowsCredential Information Disclosure VulnerabilityEPSS 0.4%CVE-2023-50127MEDIUMHozard alarm system (Alarmsysteem) v1.0 is vulnerable to Improper Authentication. Commands sent via the SMS functionality are accepted from EPSS 0.4%CVE-2025-37106HIGHAn authentication bypass and disclosure of information vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.18.EPSS 0.4%CVE-2025-30114CRITICALAn issue was discovered on the Forvia Hella HELLA Driving Recorder DR 820. Bypassing of Device Pairing can occur. The pairing mechanism reliEPSS 0.4%CVE-2025-3910MEDIUMOrg.keycloak.authentication: two factor authentication bypassEPSS 0.4%CVE-2022-3119HIGHOAuth client Single Sign On for WordPress < 3.0.4 - Unauthenticated Settings Update to Authentication BypassEPSS 0.4%