Weaknesses of type CWE-287

2,461 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2026-11703MEDIUMMissing SNI/ALPN binding on stateful (session-ID) TLS session resumptionEPSS 0.4%CVE-2025-45583CRITICALIncorrect access control in the FTP protocol of Audi UTR 2.0 Universal Traffic Recorder 2.0 allows attackers to authenticate into the servicEPSS 0.4%CVE-2025-25504MEDIUMAn issue in the /usr/local/bin/jncs.sh script of Gefen WebFWC (In AV over IP products) v1.85h, v1.86v, and v1.70 allows attackers with netwoEPSS 0.4%CVE-2022-32935MEDIUMA lock screen issue was addressed with improved state management. This issue is fixed in iOS 15.7.1 and iPadOS 15.7.1, iOS 16.1 and iPadOS 1EPSS 0.4%CVE-2026-12493HIGHClover Payment Gateway by Zaytech for WooCommerce < 1.3.6 - Unauthenticated Payment Bypass via check_orderEPSS 0.4%CVE-2026-14830HIGHFlxWoo < 3.1.1 - Unauthenticated Payment BypassEPSS 0.4%CVE-2023-25556HIGH A CWE-287: Improper Authentication vulnerability exists that could allow a device to be compromised when a key of less than seven digits isEPSS 0.4%CVE-2025-46573HIGHpassport-wsfed-saml2 Has SAML Authentication Bypass via Attribute SmugglingEPSS 0.4%CVE-2025-31122CRITICALscratch-coding-hut.github.io Login Links Generation vulnerabilityEPSS 0.4%CVE-2022-25667HIGHInformation disclosure in kernel due to improper handling of ICMP requests in Snapdragon Wired Infrastructure and NetworkingEPSS 0.4%CVE-2026-75907HIGHCVE-2026-75907EPSS 0.4%CVE-2024-42164MEDIUMDisabling MFA without AuthenticationEPSS 0.4%CVE-2026-61067HIGHVulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that EPSS 0.4%CVE-2023-39531MEDIUMSentry vulnerable to incorrect credential validation on OAuth token requestsEPSS 0.4%CVE-2026-84458CRITICALZammad: Account takeover via unverified email matching during SSO auto-linkEPSS 0.4%CVE-2025-41064CRITICALIncorrect authentication in GTT´s group OpenSIACEPSS 0.4%CVE-2025-31478HIGHZulip Authentication Backend Configuration BypassEPSS 0.4%CVE-2025-46641MEDIUMDell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 8.4 through 8.5 contain an improper authEPSS 0.4%CVE-2025-10293HIGHKeyy Two Factor Authentication (like Clef) <= 1.2.3 - Authenticated (Subscriber+) Privilege Escalation via Account TakeoverEPSS 0.4%CVE-2026-10611HIGHOTP bypass via plugin-based LDAP authentication in MISP when LDAP mixed authentication is enabledEPSS 0.4%