Weaknesses of type CWE-287

2,461 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2022-35646MEDIUMIBM Security Verify Governance, Identity Manager security bypassEPSS 0.4%CVE-2026-0405MEDIUMAuthentication Bypass in NETGEAR Orbi DevicesEPSS 0.4%CVE-2026-55235MEDIUMlanggraph-api: Relative webhook targets in LangGraph Server can reach in-process routes without authenticationEPSS 0.4%CVE-2026-45363CRITICAL`jwt` (Ruby gem) - empty-key HMAC bypassEPSS 0.4%CVE-2017-14018—An improper authentication issue was discovered in Johnson & Johnson Ethicon Endo-Surgery Generator Gen11, all versions released before NoveEPSS 0.4%CVE-2026-78425HIGHSAML Audience Confusion Allows Cross-SP AuthenticationEPSS 0.4%CVE-2025-54419CRITICALNode-SAML Contains SAML Signature Verification VulnerabilityEPSS 0.4%CVE-2026-44547CRITICALChurchCRM: Incomplete fix for CVE-2026-40582: public API login still bypasses 2FA and account lockout in ChurchCRM 7.2.2EPSS 0.4%CVE-2026-80192HIGHbetter-auth SSO before 1.6.27 Domain Ownership Authentication BypassEPSS 0.4%CVE-2026-48897HIGHJoomla! Core - [20260512] - MFA Authentication BypassEPSS 0.4%CVE-2024-6107CRITICALDue to insufficient verification, an attacker could use a malicious client to bypass authentication checks and run RPC commands in a region.EPSS 0.4%CVE-2026-48896HIGHJoomla! Core - [20260511] - MFA Authentication BypassEPSS 0.4%CVE-2026-16269MEDIUMNewsletters < 4.16 - Unauthenticated API Authentication Bypass via Type JugglingEPSS 0.4%CVE-2026-45283MEDIUMNextcloud: Files Lock app allows users to lock and unlock files of other usersEPSS 0.4%CVE-2026-46705MEDIUMrussh server userauth state is not reset when authentication principal changesEPSS 0.4%CVE-2024-5174MEDIUMBroken Authentication in GliffyEPSS 0.4%CVE-2025-69822HIGHAn issue in Atomberg Atomberg Erica Smart Fan Firmware Version: V1.0.36 allows an attacker to obtain sensitive information and escalate privEPSS 0.4%CVE-2025-69197MEDIUMPterodactyl TOTPs can be reused during validity windowEPSS 0.4%CVE-2023-33054CRITICALImproper Authentication in GPS HLOS DriverEPSS 0.4%CVE-2026-16257HIGHArvow AI SEO Writer < 1.5.4 - Unauthenticated Arbitrary Post Creation via Webhook Secret Type-JugglingEPSS 0.4%