Weaknesses of type CWE-287

2,461 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2026-8185MEDIUMUGREEN CM933 Administrative missing authenticationEPSS 0.4%CVE-2024-37313HIGHNextcloud server allows the by-pass the second factorEPSS 0.4%CVE-2026-28471MEDIUMOpenClaw 2026.1.14-1 < 2026.2.2 - Allowlist Bypass via displayName and Cross-Homeserver localpart Matching in Matrix PluginEPSS 0.4%CVE-2026-11618MEDIUMDTStack Taier Source Connection Test Endpoint LoginInterceptor.java preHandle improper authenticationEPSS 0.4%CVE-2025-68640MEDIUMThe Apple Find My backend service through 2025-12-17 allows an attacker in possession of a valid PET (Private Endpoint Token) to enumerate dEPSS 0.4%CVE-2026-10617MEDIUMnextlevelbuilder GoClaw Webhook Verification auth.go resolveAuth missing authenticationEPSS 0.4%CVE-2026-56737HIGHphpMyFAQ's two-factor authentication login bypasses the password factorEPSS 0.4%CVE-2025-62717LOWEmlog Pro session verification code error due to clearing logic errorEPSS 0.4%CVE-2025-70841CRITICALDokans Multi-Tenancy Based eCommerce Platform SaaS 3.9.2 allows unauthenticated remote attackers to obtain sensitive application configuratiEPSS 0.4%CVE-2025-14942CRITICALAuthentication BypassEPSS 0.4%CVE-2025-30168MEDIUMParse Server has an OAuth login vulnerabilityEPSS 0.4%CVE-2026-12341HIGHSailPoint IdentityIQ Improper Bearer Token Validation VulnerabilityEPSS 0.4%CVE-2025-30733MEDIUMVulnerability in the RDBMS Listener component of Oracle Database Server. Supported versions that are affected are 19.3-19.26, 21.3-21.17 anEPSS 0.4%CVE-2026-12196HIGHHestiaCP Admin TakeoverEPSS 0.4%CVE-2026-19806HIGHSupport Genix <= 1.4.52 - Authenticated (Subscriber+) Authentication Bypass to Administrator Account Takeover via 'p' Parameter Forged Guest TokenEPSS 0.4%CVE-2026-53958HIGH4gaBoards: SSO Pre-Account Takeover / Hijacking via Mass AssignmentEPSS 0.4%CVE-2026-40910MEDIUMfrp: Authentication bypass in frp HTTP vhost routing when routeByHTTPUser is used for access controlEPSS 0.4%CVE-2022-41738HIGHIBM Spectrum Scale security bypassEPSS 0.4%CVE-2023-52540HIGHVulnerability of improper authentication in the Iaware module. Impact: Successful exploitation of this vulnerability will affect availabilitEPSS 0.4%CVE-2026-39976HIGHLaravel Passport's TokenGuard Authenticates Unrelated User for Client Credentials TokensEPSS 0.4%