Weaknesses of type CWE-287

2,461 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2026-34736MEDIUMOpen edX Platform: Account Activation Bypass via activation_key Exposure in REST APIEPSS 0.4%CVE-2026-10611HIGHOTP bypass via plugin-based LDAP authentication in MISP when LDAP mixed authentication is enabledEPSS 0.4%CVE-2023-44096— Vulnerability of brute-force attacks on the device authentication module.Successful exploitation of this vulnerability may affect service cEPSS 0.4%CVE-2026-60615HIGHVulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Security). The supported version tEPSS 0.4%CVE-2026-44460HIGHFileRise: TOTP Bypass via Setup Endpoint Disclosing Existing SecretEPSS 0.4%CVE-2026-54320HIGHDaytona: Cross-tenant organization takeover via invitation acceptance with an unverified emailEPSS 0.4%CVE-2025-14716MEDIUMUnauthorized access to informationEPSS 0.4%CVE-2026-58029MEDIUMFull Account Takeover from BotPasswords and OAuth via action=changeauthenticationdataEPSS 0.4%CVE-2025-69273HIGHSpectrum broken authenticationEPSS 0.4%CVE-2025-1231MEDIUMImproper password reset in PAM Module in Devolutions Server 2024.3.10.0 and earlier allows an authenticated user to reuse the oracle user paEPSS 0.4%CVE-2022-40966HIGHAuthentication bypass vulnerability in multiple Buffalo network devices allows a network-adjacent attacker to bypass authentication and acceEPSS 0.4%CVE-2025-66174MEDIUMThere is an improper authentication vulnerability in some Hikvision DVR products. Due to the improper implementation of authentication for tEPSS 0.4%CVE-2025-24949MEDIUMIn JotUrl 2.0, is possible to bypass security requirements during the password change process.EPSS 0.3%CVE-2024-57491HIGHAuthentication Bypass vulnerability in jobx up to v1.0.1-RELEASE allows an attacker can exploit this vulnerability to access sensitive API wEPSS 0.3%CVE-2026-72917MEDIUMAnythingLLM: Password recovery accepts one recovery code twice after whitespace normalizationEPSS 0.3%CVE-2026-30851HIGHCaddy forward_auth copy_headers Does Not Strip Client-Supplied Headers, Allowing Identity Injection and Privilege EscalationEPSS 0.3%CVE-2023-0228HIGHImproper authentication vulnerability in S+ OperationsEPSS 0.3%CVE-2025-14908MEDIUMJeecgBoot Multi-Tenant Management SysTenantController.java improper authenticationEPSS 0.3%CVE-2023-0863HIGHAuthentication to access the AC wallbox via its Bluetooth Low Energy (BLE) channel can be bypassed, EPSS 0.3%CVE-2025-11192HIGHFabric Engine (VOSS) AutoSense Authentication BypassEPSS 0.3%