Weaknesses of type CWE-287

2,461 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2026-83202CRITICALVulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affEPSS 0.4%CVE-2022-39892LOWImproper access control in Samsung Pass prior to version 4.0.05.1 allows attackers to unauthenticated access via keep open feature.EPSS 0.4%CVE-2026-34834HIGHBulwark Webmail: Authentication Bypass in verifyIdentity() due to missing cookie validationEPSS 0.4%CVE-2026-27134HIGHStrimzi: All CAs from a custom CA chain consisting of multiple CAs are trusted for mTLS user autenticationEPSS 0.4%CVE-2025-55293CRITICALMeshtastic allows crafting of specific NodeInfo packets that overwrite any publicKey saved in the NodeDBEPSS 0.4%CVE-2024-57490HIGHGuangzhou Hongfan Technology Co., LTD. iOffice20 has any user login vulnerability. An attacker can log in to any system account including thEPSS 0.4%CVE-2026-39322CRITICALPolarLearn: Any password authenticates banned accounts and grants API accessEPSS 0.4%CVE-2024-44821MEDIUMZZCMS 2023 contains a vulnerability in the captcha reuse logic located in /inc/function.php. The checkyzm function does not properly refreshEPSS 0.4%CVE-2026-71277CRITICALrust-iot-platform Authentication Bypass via Non-Validated Authorization HeaderEPSS 0.4%CVE-2026-34873CRITICALAn issue was discovered in Mbed TLS 3.5.0 through 4.0.0. Client impersonation can occur while resuming a TLS 1.3 session.EPSS 0.4%CVE-2023-31279HIGHImproper AuthenticationEPSS 0.4%CVE-2026-46485HIGHDash: Users can write to config despire permissions (OIDC tested)EPSS 0.4%CVE-2024-3487LOWBroken Authentication vulnerability in iManagerEPSS 0.4%CVE-2026-10157MEDIUMOpen5GS NGAP PathSwitchRequest Message ngap-handler.c improper authenticationEPSS 0.4%CVE-2026-58075HIGHA vulnerability allowing an unauthenticated attacker to read arbitrary files from the host, which can be further leveraged toescalate privilEPSS 0.4%CVE-2024-37233MEDIUMWordPress Play.ht plugin <= 3.6.4 - Broken Access Control vulnerabilityEPSS 0.4%CVE-2022-46313MEDIUMThe sensor privacy module has an authentication vulnerability. Successful exploitation of this vulnerability may cause unavailability of theEPSS 0.4%CVE-2026-83961HIGHColdFusion | Improper Authentication (CWE-287)EPSS 0.4%CVE-2026-15210CRITICALLogin/Signup with Phone Number, OTP Verification < 1.8.71 - Unauthenticated Account Takeover via OTP Brute ForceEPSS 0.4%CVE-2026-19714CRITICALSimple JWT Login < 3.6.8 - Unauthenticated Account Takeover via Missing Google id_token Audience ValidationEPSS 0.4%