Weaknesses of type CWE-287

2,461 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2023-52540HIGHVulnerability of improper authentication in the Iaware module. Impact: Successful exploitation of this vulnerability will affect availabilitEPSS 0.4%CVE-2018-10597—IntelliVue Patient Monitors MP Series (including MP2/X2/MP30/MP50/MP70/NP90/MX700/800) Rev B-M, IntelliVue Patient Monitors MX (MX400-550) REPSS 0.4%CVE-2026-8293HIGHReally Simple Security < 9.5.10.1 - Authentication Bypass via Two-Factor OTP SkipEPSS 0.4%CVE-2022-39019MEDIUMBroken access controls on PDFtron WebviewerUI in M-Files HubshareEPSS 0.4%CVE-2024-42172MEDIUMHCL MyXalytics is affected by broken authenticationEPSS 0.4%CVE-2026-62547HIGHVulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer). Supported versions that EPSS 0.4%CVE-2026-61163HIGHVulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). TheEPSS 0.4%CVE-2026-61137HIGHVulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version EPSS 0.4%CVE-2026-4582LOWShenzhen HCC Technology MPOS M6 PLUS Bluetooth missing authenticationEPSS 0.4%CVE-2026-60416HIGHVulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that EPSS 0.4%CVE-2026-60558HIGHVulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are aEPSS 0.4%CVE-2026-61225HIGHVulnerability in the Oracle Communications Converged Application Server product of Oracle Communications (component: Core). Supported versiEPSS 0.4%CVE-2026-61074HIGHVulnerability in the PeopleSoft Enterprise FIN Common Objects Brazil product of Oracle PeopleSoft (component: eProcurement). The supportedEPSS 0.4%CVE-2026-33746CRITICALConvoy: JWT Signature Verification Bypass Allows Authentication as Arbitrary UsersEPSS 0.4%CVE-2026-59224HIGHOpen WebUI: Terminal proxy forwards a spoofable, integrity-unbound user identity to the upstream (X-User-Id header and ws_terminal session_id query injection)EPSS 0.4%CVE-2025-60306CRITICALcode-projects Simple Car Rental System 1.0 has a permission bypass issue where low privilege users can forge high privilege sessions and perEPSS 0.4%CVE-2026-25937MEDIUMGLPI has a MFA bypassEPSS 0.4%CVE-2022-25685HIGHDenial of service in Modem module due to improper authorization while error handling in Snapdragon Auto, Snapdragon Compute, Snapdragon ConsEPSS 0.4%CVE-2026-41896HIGHCoolify: Unauthenticated Deployment Trigger via Webhook HMAC Bypass with Null SecretEPSS 0.4%CVE-2025-54452HIGHImproper Authentication vulnerability in Samsung Electronics MagicINFO 9 Server allows Authentication Bypass.This issue affects MagicINFO 9 EPSS 0.4%