Weaknesses of type CWE-287

2,461 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2026-9830HIGHBookingPress Pro < 5.7.3 - Unauthenticated Customer PII Disclosure and Booking Tampering via Permission Callback BugEPSS 0.4%CVE-2026-41671MEDIUMAdmidio: OIDC Token Introspection Endpoint Returns Active for All Tokens Without ValidationEPSS 0.4%CVE-2026-16036HIGHminiOrange 2FA < 6.2.7 - 2FA Bypass via Password-Only Second-Factor RebindingEPSS 0.4%CVE-2026-17000HIGHVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.4%CVE-2026-87176CRITICALVulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is EPSS 0.4%CVE-2026-83201CRITICALVulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affEPSS 0.4%CVE-2025-27422HIGHFACTION Allows Authentication Bypass via User CreationEPSS 0.4%CVE-2022-39892LOWImproper access control in Samsung Pass prior to version 4.0.05.1 allows attackers to unauthenticated access via keep open feature.EPSS 0.4%CVE-2026-87217CRITICALVulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is EPSS 0.4%CVE-2026-83202CRITICALVulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affEPSS 0.4%CVE-2026-73944CRITICALVulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that EPSS 0.4%CVE-2026-73952CRITICALVulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Portlet Services). Supported versions that areEPSS 0.4%CVE-2026-83154CRITICALVulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: Open UI). Supported versions that are affected are 17.0-2EPSS 0.4%CVE-2026-83104CRITICALVulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). Supported versions that aEPSS 0.4%CVE-2026-87129CRITICALVulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supportEPSS 0.4%CVE-2026-87173CRITICALVulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is EPSS 0.4%CVE-2026-60326CRITICALVulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that EPSS 0.4%CVE-2026-87170CRITICALVulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is EPSS 0.4%CVE-2026-87128CRITICALVulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supportEPSS 0.4%CVE-2026-0629HIGHAuthentication Bypass in Password Recovery Feature via Local Web App on Multiple VIGI CamerasEPSS 0.4%