Weaknesses of type CWE-287

2,459 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2021-4314MEDIUMIt is possible to manipulate the JWT token without the knowledge of the JWT secret and authenticate without valid JWT token as any user. ThiEPSS 0.4%CVE-2025-10288MEDIUMroncoo roncoo-pay list improper authenticationEPSS 0.4%CVE-2026-80097HIGHMicrosoft Authenticator Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2025-50901CRITICALJeeWMS 771e4f5d0c01ffdeae1671be4cf102b73a3fe644 (2025-05-19) contains incorrect authentication bypass vulnerability, which can lead to arbitEPSS 0.4%CVE-2026-49443HIGHauthentik: `UserSourceConnection.user` and `GroupSourceConnection.group` are changeable through the APIEPSS 0.4%CVE-2025-7115MEDIUMrowboatlabs rowboat Session route.ts PUT missing authenticationEPSS 0.4%CVE-2026-12183CRITICALNefteprodukttekhnika BUK TS-G Gas Station Automation System Authentication Bypass via ajax-login.php Accepting Arbitrary CredentialsEPSS 0.4%CVE-2022-46829HIGHIn JetBrains JetBrains Gateway before 2022.3 a client could connect without a valid token if the host consented.EPSS 0.4%CVE-2026-21508HIGHWindows Storage Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2021-25424—Improper authentication vulnerability in Tizen bluetooth-frwk prior to Firmware update JUN-2021 Release allows bluetooth attacker to take ovEPSS 0.4%CVE-2022-22237MEDIUMJunos OS: Peers not configured for TCP-AO can establish a BGP or LDP session even if authentication is configured locallyEPSS 0.4%CVE-2026-17075MEDIUMIBM i is Affected By Multiple Vulnerabilities in Digital Certificate ManagerEPSS 0.4%CVE-2024-34093MEDIUMAn issue was discovered in Archer Platform 6 before 2024.03. There is an X-Forwarded-For Header Bypass vulnerability. An unauthenticated attEPSS 0.4%CVE-2026-26077MEDIUMDiscourse doesn't ensure webhooks require a tokenEPSS 0.4%CVE-2026-55955MEDIUMApache Tomcat: EncryptInterceptor not protected against replay attacksEPSS 0.4%CVE-2024-44843MEDIUMAn issue in the web socket handshake process of SteVe v3.7.1 allows attackers to bypass authentication and execute arbitrary coammands via sEPSS 0.4%CVE-2025-6926HIGHSecurity Authentication Bypass in CentralAuthEPSS 0.4%CVE-2025-37107HIGHAn authentication bypass vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.18.EPSS 0.4%CVE-2020-3216MEDIUMCisco IOS XE SD-WAN Software Authentication Bypass VulnerabilityEPSS 0.4%CVE-2026-33124HIGHFrigate has insecure password change functionalityEPSS 0.4%