Weaknesses of type CWE-287

2,461 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2026-9398LOWBesen BS20 EV Charging Station BLE/WiFi authentication replayEPSS 0.4%CVE-2026-15210CRITICALLogin/Signup with Phone Number, OTP Verification < 1.8.71 - Unauthenticated Account Takeover via OTP Brute ForceEPSS 0.4%CVE-2026-16055HIGHContest Gallery < 30.0.7 - Unauthenticated Login-Protection and 2FA Bypass via post_cg_loginEPSS 0.4%CVE-2026-34727HIGHVikunja ahs a TOTP Two-Factor Authentication Bypass via OIDC Login PathEPSS 0.4%CVE-2026-49194CRITICALSCREEN_CLICK Authentication BypassEPSS 0.4%CVE-2022-48294HIGHThe IHwAttestationService interface has a defect in authentication. Successful exploitation of this vulnerability may affect data confidentiEPSS 0.4%CVE-2026-19971MEDIUMLB-Link WR1210M Backup Endpoint backup.cgi main missing authenticationEPSS 0.4%CVE-2020-8097HIGHImproper authentication vulnerability in Bitdefender Endpoint Security Tools and Endpoint Security SDK (VA-8646)EPSS 0.4%CVE-2026-1305MEDIUMJapanized for WooCommerce <= 2.8.4 - Missing Authorization to Unauthenticated Paidy Order ManipulationEPSS 0.4%CVE-2026-93984MEDIUMOpenPanel API Authentication Bypass via Unverified Client SecretEPSS 0.4%CVE-2026-12877CRITICALSoftware Issue Manager < 5.1.0 - Unauthenticated SQL Injection via Search ParameterEPSS 0.4%CVE-2025-67822CRITICALA vulnerability in the Provisioning Manager component of Mitel MiVoice MX-ONE 7.3 (7.3.0.0.50) through 7.8 SP1 (7.8.1.0.14) could allow an uEPSS 0.4%CVE-2025-46630MEDIUMImproper access controls in the web management portal of the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated remote attacker to enable 'EPSS 0.4%CVE-2026-60327HIGHVulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that EPSS 0.4%CVE-2026-57134HIGHPraisonAI MCPSecurity Basic/OAuth authentication policies accept invalid credentials without validationEPSS 0.4%CVE-2025-53889MEDIUMDirectus missing permission checks for manual trigger FlowsEPSS 0.4%CVE-2026-11345MEDIUMImproper Authentication Bypass in linqi CDN File AccessEPSS 0.4%CVE-2026-18074HIGHIBM Financial Transaction Manager (FTM) is Impacted by Multiple VulnerabilitiesEPSS 0.4%CVE-2025-70833CRITICALAn Authentication Bypass vulnerability in Smanga 3.2.7 allows an unauthenticated attacker to reset the password of any user (including the aEPSS 0.4%CVE-2022-47976HIGHThe DMSDP module of the distributed hardware has a vulnerability that may cause imposter control connections.Successful exploitation of thisEPSS 0.4%