Weaknesses of type CWE-287

2,461 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2026-100606CRITICALFlowise through 3.1.4 Authentication Bypass via SSO Email MatchEPSS 0.4%CVE-2024-23251MEDIUMAn authentication issue was addressed with improved state management. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadEPSS 0.4%CVE-2026-18052HIGHManageWP Worker < 4.9.37 - Unauthenticated Authentication Bypass via Unsigned Auto-Login ParametersEPSS 0.4%CVE-2026-33042MEDIUMParse Server affected by empty authData bypassing credential requirement on signupEPSS 0.4%CVE-2026-33473MEDIUMVikunja has TOTP Reuse During Validity WindowEPSS 0.4%CVE-2023-51511MEDIUMWordPress Booster Elite for WooCommerce plugin < 7.1.3 - Authenticated Production Creation/Modification VulnerabilityEPSS 0.4%CVE-2024-5201HIGHDimensions RM - Privilege EscalationEPSS 0.4%CVE-2025-6524LOW70mai 1S Video Services improper authenticationEPSS 0.4%CVE-2024-30939MEDIUMAn issue discovered in Yealink VP59 Teams Editions with firmware version 91.15.0.118 allows a physically proximate attacker to gain control EPSS 0.4%CVE-2022-29083MEDIUMPrior Dell BIOS versions contain an Improper Authentication vulnerability. An unauthenticated attacker with physical access to the system coEPSS 0.4%CVE-2024-45051HIGHBypass of email address validation via encoded email addresses in DiscourseEPSS 0.4%CVE-2024-2244MEDIUMREST service authentication anomaly with “valid username/no password” credential combination for batch job processing resulting in successfuEPSS 0.4%CVE-2026-16972MEDIUMVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.4%CVE-2026-46355HIGHBigBlueButton: Unauthenticated Session Hijack via Exposed /bigbluebutton/api/handleJoinExistingUserEPSS 0.4%CVE-2026-26128HIGHWindows SMB Server Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2026-48780HIGHForem vulnerable to bypass of email address domain restrictionsEPSS 0.4%CVE-2022-3156HIGHRockwell Automation Studio 5000 Logix Emulate Vulnerable to a Remote Code Execution VulnerabilityEPSS 0.4%CVE-2026-58253HIGHNATS Server: Route API Auth BypassEPSS 0.4%CVE-2025-46607MEDIUMDell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 8.4 through 8.5 contain an improper authEPSS 0.4%CVE-2022-43528MEDIUMUnder certain configurations, an attacker can login to Aruba EdgeConnect Enterprise Orchestrator without supplying a multi-factor authenticaEPSS 0.4%