Weaknesses of type CWE-287

2,461 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2026-41896HIGHCoolify: Unauthenticated Deployment Trigger via Webhook HMAC Bypass with Null SecretEPSS 0.4%CVE-2026-32246HIGHTinyauth vulnerable to TOTP/2FA bypass via OIDC authorize endpointEPSS 0.4%CVE-2019-13531MEDIUMMedtronic Valleylab FT10 and LS10 Improper AuthenticationEPSS 0.4%CVE-2018-1106—An authentication bypass flaw has been found in PackageKit before 1.1.10 that allows users without administrator privileges to install signeEPSS 0.4%CVE-2026-41720HIGHAuthentication Bypass with Empty Password in Spring LDAPEPSS 0.4%CVE-2026-86248CRITICALApache Tomcat: Fix for CVE-2026-34500 was incomplete. OCSP checks sometimes soft-fail with FFM even when soft-fail is disabledEPSS 0.4%CVE-2026-28606CRITICALIn handleBondStateChanged of AdapterService.java, there is a possible way to skip pairing due to a logic error in the code. This could lead EPSS 0.4%CVE-2025-9063HIGHRockwell Automation PanelView Plus 7 Performance Series B Authentication BypassEPSS 0.4%CVE-2026-49447MEDIUMCosmos-Server's constellation public-devices endpoint accepts arbitrary bearer tokensEPSS 0.4%CVE-2025-51451CRITICALIn TOTOLINK EX1200T firmware 4.1.2cu.5215, an attacker can bypass login by sending a specific request through formLoginAuth.htm.EPSS 0.4%CVE-2026-76688HIGHAuthentication Bypass Vulnerabilities in the Web-Based Management Interface of EdgeConnect SD-WAN OrchestratorEPSS 0.4%CVE-2026-16030HIGHMStore API < 4.21.0 - Unauthenticated Account Takeover via Firebase Phone AuthenticationEPSS 0.4%CVE-2026-97231MEDIUMvolotat Anagnorisis Socket.IO Connect app.py missing authenticationEPSS 0.4%CVE-2026-82183HIGHOAuth Single Sign On 6.25.0 - 7.0.0 - Unauthenticated Account Takeover via Unverified Steam OpenID AssertionEPSS 0.4%CVE-2026-12585HIGHAbandoned Cart Lite for WooCommerce < 6.8.2 - Unauthenticated Account Takeover via Malleable Recovery-Link TokenEPSS 0.4%CVE-2026-14309HIGHChat On Desk < 1.0.9 - Unauthenticated Account Takeover via Password Reset OTP BypassEPSS 0.4%CVE-2026-14300HIGHminiOrange Social Login and Register < 7.8.0 - Unauthenticated Account TakeoverEPSS 0.4%CVE-2026-18468HIGHLogin & Register Forms < 4.0.2 - Unauthenticated Account Takeover via Password Reset Verification State Keyed on a Client-Supplied Address HeaderEPSS 0.4%CVE-2026-18469HIGHLogin & Register Forms < 4.0.2 - Unauthenticated Account Takeover via Password Reset Code Brute ForceEPSS 0.4%CVE-2026-14836HIGHLogin/Signup Popup < 3.2.5 - Unauthenticated Account Takeover via Password Reset Rate Limit BypassEPSS 0.4%