Weaknesses of type CWE-287

2,461 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2026-60678HIGHVulnerability in the Oracle General Ledger product of Oracle E-Business Suite (component: Internal Operations). Supported versions that areEPSS 0.4%CVE-2026-60654HIGHVulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions tEPSS 0.4%CVE-2020-7297MEDIUMWeb Gateway (MWG) - Privilege Escalation vulnerabilityEPSS 0.4%CVE-2026-46903HIGHVulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Business Logic Infrastructure Security). SuppoEPSS 0.4%CVE-2026-61098HIGHVulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versionsEPSS 0.4%CVE-2026-61121HIGHVulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll). Supported versions that are affected are EPSS 0.4%CVE-2026-60568CRITICALVulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are afEPSS 0.4%CVE-2026-60924HIGHVulnerability in the Oracle Public Sector Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported versions tEPSS 0.4%CVE-2026-47037HIGHVulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). The supported version tEPSS 0.4%CVE-2026-46929HIGHVulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Cost Planning). Supported versions that are affeEPSS 0.4%CVE-2021-44458HIGHLack of websocket authentication in Lens causes remote code execution when visiting a malicious websiteEPSS 0.4%CVE-2025-12998HIGHBroken Authentication in extension “Modules” (modules)EPSS 0.4%CVE-2025-57278HIGHThe LB-Link BL-CPE300M AX300 4G LTE Router firmware version BL-R8800_B10_ALK_SL_V01.01.02P42U14_06 does not implement proper session handlinEPSS 0.4%CVE-2026-32253CRITICALSunshine: Authentication bypass via improper client certificate validationEPSS 0.4%CVE-2023-28540CRITICALImproper Authentication in Data ModemEPSS 0.4%CVE-2026-18816LOWBaserow 2FA Verify Endpoint views.py verify improper authenticationEPSS 0.4%CVE-2026-67327HIGHbetter-auth before 1.6.22 Account Takeover via Magic-Link Email-OTPEPSS 0.4%CVE-2024-50641HIGHAn authentication bypass vulnerability in PandoraNext-TokensTool v0.6.8 and before. An attacker can exploit this vulnerability to access APIEPSS 0.4%CVE-2026-48526HIGHPyJWT: Public-key JWK accepted as HMAC secret enables forged HS256 tokens when mixed families are allowedEPSS 0.4%CVE-2026-73302CRITICALBudibase: OIDC SSO account takeover: incoming identity linked by email without checking email_verifiedEPSS 0.4%