Keycloak provides a way to let users log in using Microsoft accounts while restricting access to a specific organization
A security flaw has been discovered in GL.iNet GL-RM1, GL-RM10, GL-RM10RC and GL-RM1PE 1.8.1. Affected by this issue is
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 8.4 through 8.5 cont
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 8.4 through 8.5 cont
A flaw has been found in bg5sbk MiniCMS up to 1.8. Impacted is the function delete_page of the file /minicms/mc-admin/pa
Pterodactyl is a free, open-source game server management panel. Versions 1.11.11 and below allow TOTP to be used multip
Improper Authentication vulnerability in Delinea Inc. Secret Server On-Prem (RPC Password Rotation modules).This issue a
A lack of session validation in the web API component of Shenzhen Zhibotong Electronics ZBT WE2001 23.09.27 allows remot
FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to versions 1.1.3-stable and 1.2.6-beta, when
Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, several webhook en
Improper authentication in Smart Switch prior to version 3.7.69.15 allows adjacent attackers to trigger a denial of serv
GLPI is a free Asset and IT management software package. Starting in version 11.0.0 and prior to version 11.0.6, a malic
Improper Authentication vulnerability in Secomea GateManager (webserver modules) allows Authentication Bypass.This issue
pyLoad is a free and open-source download manager written in Python. Prior to version 0.5.0b3.dev97, a Host Header Spoof
NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. The nats-server provides
Fleet is open source device management software. Prior to 4.81.0, Fleet contained an issue in the user invitation flow w
Flask-HTTPAuth provides Basic, Digest and Token HTTP authentication for Flask routes. Prior to version 4.8.1, in a situa
CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled and FFM is used in Ap
A weakness has been identified in liangliangyy DjangoBlog up to 2.1.0.0. This impacts an unknown function of the file bl
A weakness has been identified in serge-chat serge up to 1.4TB. The impacted element is the function download_model/dele
frp is a fast reverse proxy. From 0.43.0 to 0.68.0, frp contains an authentication bypass in the HTTP vhost routing path
Improper Handling of TLS Client Authentication Failure Leading to Anonymous Principal Assignment in Apache Storm Versio
A flaw has been found in crocodilestick Calibre-Web-Automated up to 4.0.6. Affected by this issue is some unknown functi
TypeBot is a chatbot builder tool. In versions 3.16.0 and prior, the WhatsApp Cloud API webhook endpoint (POST /v1/works
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supp
A flaw was found in KubeVirt's virt-handler domain notify server. The gRPC handlers for HandleDomainEvent and HandleK8SE
TLS 1.3 post-handshake authentication (PHA) issue where a server could accept a client's Finished message without the cl
Improper Authentication vulnerability in Apache Tomcat allowed a replay attack against the EncryptionInterceptor in the
Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Api/ApiC
A weakness has been identified in zhayujie chatgpt-on-wechat CowAgent 2.1.0. This issue affects the function verify_serv
A vulnerability has been found in mettle sendportal up to 3.0.1. This issue affects the function sendgrid/postmark/posta
Capgo before 12.128.2 contains an improper validation vulnerability in the accept_invitation endpoint that creates user
Improper authentication in Windows Admin Center allows an authorized attacker to disclose information over a network.
The User Frontend: AI Powered Frontend Post Submission, User Directory, User Profile, Membership & User Registration Wor
An authentication bypass vulnerability in Koollab LMS allowed an unauthenticated attacker to take over any account, incl
The Authora : Easy login with mobile number WordPress plugin before 1.7.7 does not keep its one-time login code confiden
An improper authentication vulnerability in the "social_login.cgi" CGI program in Zyxel WAX650S firmware versions throug
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information and perform unauthorized oper
The Backup Migration WordPress plugin before 2.1.7 does not properly restrict a post-restore automatic login mechanism,
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to obtain sensitive information due to impro
A flaw has been found in Faveo Helpdesk up to 2.0.3. This impacts the function FormController::post_ticket_reply of the
The Booking for Appointments and Events Calendar WordPress plugin before 2.4.7 does not require authentication before p
A vulnerability was found in Linux Foundation Magma 1.9.0. The affected element is an unknown function of the file tasks
A vulnerability was detected in Beetel 777VR1 up to 01.00.09/01.00.09_55. Impacted is an unknown function of the compone
Natro Macro is an open-source Bee Swarm Simulator macro written in AutoHotkey. Prior to version 1.1.0, anyone with Disco
NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. The nats-server offers a
A flaw has been found in Flycatcher Toys smART Sketcher up to 2.0. This affects an unknown part of the component Bluetoo
A security flaw has been discovered in Flycatcher Toys smART Pixelator 2.0. Affected by this issue is some unknown funct
A security flaw has been discovered in suitenumerique messages 0.2.0. This issue affects the function ThreadAccessSerial
A vulnerability was found in Yi Technology YI Home Camera 2 2.1.1_20171024151200. The impacted element is an unknown fun
Frequently Asked Questions
What is CWE-287?
CWE-287 (Improper Authentication) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-287?
There are 5,272 CVE records associated with CWE-287 in our database. Of these, 1116 are critical severity, 1386 are high severity, and 1045 are medium severity.
How can I protect against CWE-287 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-287 using AI-powered security agents.
Detect CWE-287 Vulnerabilities
CyberStrike's AI agents automatically detect improper authentication vulnerabilities across your infrastructure.
Get Started