Weaknesses of type CWE-287

2,461 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2026-44478HIGHhoppscotch: Unauthenticated Onboarding Config Disclosure via Empty Recovery TokenEPSS 0.4%CVE-2026-84606HIGHA privacy issue was addressed with improved handling of identifiers. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, visiEPSS 0.4%CVE-2024-23767HIGHAn issue was discovered on HMS Anybus X-Gateway AB7832-F firmware version 3. The HICP protocol allows unauthenticated changes to a device's EPSS 0.4%CVE-2026-55666CRITICALRocket.Chat: Email Parameter Fallback Leads To Account Takeover Within Apple OAuthEPSS 0.4%CVE-2026-15206HIGHSMS Alert Order Notifications – WooCommerce < 3.9.8 - Unauthenticated Account Takeover via Unbound OTP Verification in Signup-with-MobileEPSS 0.4%CVE-2026-32072MEDIUMActive Directory Spoofing VulnerabilityEPSS 0.4%CVE-2023-48747MEDIUMWordPress Booster for WooCommerce plugin <= 7.1.2 - Authenticated Production Creation/Modification VulnerabilityEPSS 0.4%CVE-2026-10777MEDIUMealpha072 Student-Management-System Administrative Backend config.php improper authenticationEPSS 0.4%CVE-2025-46572CRITICALpassport-wsfed-saml2 Has SAML Authentication Bypass via Signature WrappingEPSS 0.4%CVE-2026-15089CRITICALCommerce guest registration - Critical - Unsupported - SA-CONTRIB-2026-079EPSS 0.4%CVE-2026-4476MEDIUMYi Technology YI Home Camera CGI Endpoint ipc missing authenticationEPSS 0.4%CVE-2026-18215MEDIUMKeycloak-services: keycloak-services: microsoft external access-token exchange bypasses configured tenantEPSS 0.4%CVE-2026-45567HIGHRoxy-WI: Authentication bypass via 'api' substring in URL + unauthenticated /api/gptEPSS 0.4%CVE-2023-21455MEDIUMImproper authorization implementation in Exynos baseband prior to SMR Mar-2023 Release 1 allows incorrect handling of unencrypted message.EPSS 0.4%CVE-2025-31271HIGHThis issue was addressed through improved state management. This issue is fixed in macOS Tahoe 26. Incoming FaceTime calls can appear or be EPSS 0.4%CVE-2018-16877HIGHA flaw was found in the way pacemaker's client-server authentication was implemented in versions up to and including 2.0.0. A local attackerEPSS 0.4%CVE-2025-58065MEDIUMFlask App Builder has an Authentication Bypass vulnerability when using non AUTH_DB methodsEPSS 0.4%CVE-2023-38367MEDIUMIBM Cloud Pak for Automation authentication bypassEPSS 0.4%CVE-2026-8185MEDIUMUGREEN CM933 Administrative missing authenticationEPSS 0.4%CVE-2026-56223CRITICALCapgo - Account Takeover via Cross-Domain SSO Email Assertion in provision-userEPSS 0.4%