Weaknesses of type CWE-287

2,461 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2026-44961NONEThe XML‑RPC API addUser method has a validation bypass introduced in the fix for CVE‑2025‑55129. As a result, API users could create usernamEPSS 0.4%CVE-2026-13690HIGHUsersWP < 1.2.67 - Two-Factor Authentication BypassEPSS 0.4%CVE-2026-10281MEDIUMEnderfga claw-orchestrator API Endpoint embedded-server.ts EmbeddedServer missing authenticationEPSS 0.4%CVE-2026-4583LOWShenzhen HCC Technology MPOS M6 PLUS Bluetooth authentication replayEPSS 0.4%CVE-2021-22943—A vulnerability found in UniFi Protect application V1.18.1 and earlier permits a malicious actor who has already gained access to a network EPSS 0.4%CVE-2026-2756LOWOmniPEMF NeoRhythm BLE missing authenticationEPSS 0.4%CVE-2026-75807HIGHSAML Single Sign On <= 5.4.6 - Unauthenticated Authentication Bypass via X.509 Certificate PoisoningEPSS 0.4%CVE-2024-35670MEDIUMWordPress Integrate Google Drive plugin <= 1.3.93 - Broken Access Control vulnerabilityEPSS 0.4%CVE-2025-27086HIGHA vulnerability in the HPE Performance Cluster Manager (HPCM) GUI could allow an attacker to bypass authentication.EPSS 0.4%CVE-2025-5597CRITICALWF Steuerungstechnik GmbH - airleader MASTER - Authentication BypassEPSS 0.4%CVE-2022-39018HIGHBroken access controls on PDFtron data in M-Files HubshareEPSS 0.4%CVE-2026-85716LOWAsyncHttpClient: SCRAM and Digest mutual-authentication responses are not verifiedEPSS 0.4%CVE-2026-10167MEDIUMOUSL-GROUP-BrinaryBrains School Student Management System MY_Controller Login.php sign_auth_cookie improper authenticationEPSS 0.4%CVE-2026-14596HIGHDynamicKit for Elementor < 1.0.3 - Unauthenticated Account Takeover via Password Reset Link Host InjectionEPSS 0.4%CVE-2026-28428MEDIUMTalishar: Authentication Bypass via Empty authKey Parameter Allows Unauthenticated Game ActionsEPSS 0.4%CVE-2026-40946CRITICALOxia: OIDC token audience validation bypass via SkipClientIDCheckEPSS 0.4%CVE-2026-77826HIGHRegistrationMagic 5.0.1.8 - 6.0.9.8 - Unauthenticated Authentication Bypass via Missing Facebook Token Audience ValidationEPSS 0.4%CVE-2025-30214HIGHFrappe vulnerable to information disclosure leading to account takeoverEPSS 0.4%CVE-2026-55689MEDIUMOpenFGA: OIDC audience validation skipped when --authn-oidc-audience is unsetEPSS 0.4%CVE-2025-14738MEDIUMConfiguration Disclosure Vulnerability in TP-Link WA850REEPSS 0.4%