Weaknesses of type CWE-287

2,461 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2026-18469HIGHLogin & Register Forms < 4.0.2 - Unauthenticated Account Takeover via Password Reset Code Brute ForceEPSS 0.4%CVE-2026-1743LOWDJI Mavic Mini/Air/Spark/Mini SE Enhanced Wi-Fi Pairing authentication replayEPSS 0.4%CVE-2026-58066CRITICALRocket.Chat's SAML SSO before versions 8.7.0, 8.6.1, 8.5.2, 8.4.5, 8.3.7, 8.2.7, 8.1.7, 8.0.8, and 7.10.14 verified XML signatures but did nEPSS 0.4%CVE-2025-21618HIGHNiceGUI On Air authentication issueEPSS 0.4%CVE-2026-0842MEDIUMFlycatcher Toys smART Sketcher Bluetooth Low Energy missing authenticationEPSS 0.4%CVE-2026-28787HIGHOneUptime has WebAuthn 2FA bypass: server accepts client-supplied challenge instead of server-stored value, allowing credential replayEPSS 0.4%CVE-2026-61630MEDIUMnginx ignition has TOTP Reuse During Validity WindowEPSS 0.4%CVE-2026-34917MEDIUMLow‑privileged session IDs generated for the web admin console could be reused in the XML‑RPC API, whose authentication is normally restrictEPSS 0.4%CVE-2023-35154HIGHKnowage-Server vulnerable to account validation bypassEPSS 0.4%CVE-2024-39830HIGHTiming attack during remote cluster token comparison when shared channels are enabledEPSS 0.4%CVE-2024-0879MEDIUMAuthentication bypass in vector-admin domain restrictionEPSS 0.4%CVE-2024-6078HIGHRockwell Automation Authentication Bypass Vulnerability in DataMosaix™EPSS 0.4%CVE-2023-4985MEDIUMSupcon InPlant SCADA Project.xml improper authenticationEPSS 0.4%CVE-2026-56312MEDIUMCapgo - Account Creation Before CAPTCHA Validation in accept_invitation EndpointEPSS 0.4%CVE-2025-47790MEDIUMNextcloud Server doesn't request second factor after session timeoutEPSS 0.4%CVE-2020-3388HIGHCisco SD-WAN vManage Software Command Injection VulnerabilityEPSS 0.4%CVE-2022-20662MEDIUMCisco Duo for macOS Authentication Bypass VulnerabilityEPSS 0.4%CVE-2026-2812MEDIUMImproper Authentication issue in ArcGIS ServerEPSS 0.4%CVE-2026-53591HIGHFreeScout Vulnerable to Unauthenticated Conversation Thread Injection via HMAC Length Bypass in FetchEmailsEPSS 0.4%CVE-2024-23251MEDIUMAn authentication issue was addressed with improved state management. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadEPSS 0.4%