Weaknesses of type CWE-287

2,430 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2022-47003CRITICALA vulnerability in the Remember Me function of Mura CMS before v10.0.580 allows attackers to bypass authentication via a crafted web requestEPSS 3.6%CVE-2021-37624HIGHFreeSWITCH does not authenticate SIP MESSAGE requests, leading to spam and message spoofingEPSS 3.6%CVE-2018-0321—A vulnerability in Cisco Prime Collaboration Provisioning (PCP) could allow an unauthenticated, remote attacker to access the Java Remote MeEPSS 3.6%CVE-2022-0730—Under certain ldap conditions, Cacti authentication can be bypassed with certain credential types.EPSS 3.5%CVE-2021-24148—MStore API < 3.2.0 - Authentication Bypass With Sign In With AppleEPSS 3.4%CVE-2019-16028CRITICALCisco Firepower Management Center Lightweight Directory Access Protocol Authentication Bypass VulnerabilityEPSS 3.4%CVE-2014-0760—Festo CECX-X-(C1/M1) Controller Improper AuthenticationEPSS 3.3%CVE-2017-7562MEDIUMAn authentication bypass flaw was found in the way krb5's certauth interface before 1.16.1 handled the validation of client certificates. A EPSS 3.3%CVE-2025-66039CRITICALFreePBX Endpoint Manager Allows Unauthenticated Logins to Administrator Control Panel via Forged Basic Auth HeaderEPSS 3.3%CVE-2026-12571CRITICALAuthentication Bypass Leading to Account TakeoverEPSS 3.3%CVE-2022-30995CRITICALSensitive information disclosure due to improper authentication. The following products are affected: Acronis Cyber Protect 15 (Windows, LinEPSS 3.3%CVE-2023-0905HIGHSourceCodester Employee Task Management System changePasswordForEmployee.php improper authenticationEPSS 3.2%CVE-2017-12236—A vulnerability in the implementation of the Locator/ID Separation Protocol (LISP) in Cisco IOS XE 3.2 through 16.5 could allow an unauthentEPSS 3.1%CVE-2023-30869CRITICALWordPress Easy Digital Downloads Plugin 3.1-3.1.1.4.1 is vulnerable to Privilege EscalationEPSS 3.1%CVE-2021-34865HIGHThis vulnerability allows network-adjacent attackers to bypass authentication on affected installations of multiple NETGEAR routers. AuthentEPSS 3.1%CVE-2018-14786—Becton, Dickinson and Company (BD) Alaris Plus medical syringe pumps (models Alaris GS, Alaris GH, Alaris CC, and Alaris TIVA) versions 2.3.EPSS 3.1%CVE-2020-3297HIGHCisco Small Business Smart and Managed Switches Session Management VulnerabilityEPSS 3.0%CVE-2021-25036—All In One SEO < 4.1.5.3 - Authenticated Privilege EscalationEPSS 3.0%CVE-2026-8181CRITICALBurst Statistics 3.4.0 - 3.4.1.1 - Authentication Bypass to Admin Account TakeoverEPSS 3.0%CVE-2025-1104MEDIUMD-Link DHP-W310AV authentication spoofingEPSS 3.0%