A flaw in Node.js HTTPS Agent connection reuse can cause PFX object-array key collisions, allowing mutual TLS (mTLS) cli
Improper authentication for some Intel(R) PROSet/Wireless WiFi Software within Ring 0: Kernel may allow an information d
EVerest is an EV charging software stack. In versions up to and including 2025.12.1, it is possible to bypass the sequen
Dell OpenManage Network Integration, versions prior to 3.9, contains an Improper Authentication vulnerability. A low pri
NVIDIA Delegated Licensing Service for all appliance platforms contains a vulnerability where an attacker could exploit
Packistry is a self-hosted Composer repository designed to handle PHP package distribution. Prior to version 0.13.0, Rep
FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to
Low‑privileged session IDs generated for the web admin console could be reused in the XML‑RPC API, whose authentication
Vulnerability in the Oracle Transportation Management product of Oracle Supply Chain (component: Authentication). The
Forwarding information received from a host listed as a trusted proxy is not kept separate from Dovecot's own authentica
NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.1
The MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor plugin for WordPress is vulnerable to Sens
A vulnerability was found in HybridAuth up to 3.12.2. This issue affects some unknown processing of the file src/HttpCli
A security flaw has been discovered in kalcaddle kodbox 1.64. Impacted is the function can of the file /workspace/source
A vulnerability has been found in JeecgBoot 3.9.1. This issue affects some unknown processing of the file /openapi/call/
Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: Siebel Server Sync for Exchange).
The MonsterInsights WordPress plugin before 11.1.0 does not correctly validate the signature on one of its unauthentica
A vulnerability was detected in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C and TC3T15C up to 20
A vulnerability was determined in karakeep-app karakeep up to 0.32.0. The impacted element is an unknown function of the
A person with access to a Mac may be able to bypass Login Window. A consistency issue was addressed with improved state
When doing SSH-based transfers using either SCP or SFTP, and asked to do public key authentication, curl would wrongly s
A vulnerability has been found in DJI Mavic Mini, Air, Spark and Mini SE up to 01.00.0500. Affected by this vulnerabilit
Flux notification-controller is the event forwarder and notification dispatcher for the GitOps Toolkit controllers. Prio
A security vulnerability has been detected in Besen BS20 EV Charging Station up to 20260426. This affects an unknown par
The Booking for Appointments and Events Calendar WordPress plugin before 2.4.4 does not restrict which fields can be wr
This issue was addressed with additional restrictions on the lock screen. This issue is fixed in macOS Sequoia 15.7.8, m
A vulnerability in the handling of verify_mode = CERT_REQUIRED in the wolfssl Python package (wolfssl-py) causes client
A Improper Authentication vulnerability in TLP allows local users to arbitrarily control the power profile in use as wel
Authentication bypass in the password recovery feature of the local web interface across multiple VIGI camera models all
Chef InSpec versions up to 5.23 and before 7.0.107 creates named pipes with overly permissive default Windows access con
Orthanc versions before 1.12.10 are affected by an authorisation logic flaw in the application's HTTP Basic Authenticati
OGP-Website installs prior git commit 52f865a4fba763594453068acf8fa9e3fc38d663 are affected by a type juggling flaw whic
An authentication bypass vulnerability has been found in Thesamur's AutoGPT. This vulnerability allows an attacker to by
FreshRSS is a free, self-hostable RSS aggregator. From 57e1a37 - 00f2f04, the lengths of the nonce was changed from 40 c
Oxia is a metadata store and coordination system. Prior to 0.16.2, the OIDC authentication provider unconditionally sets
MISP’s OIDC authentication plugin allowed automatic linking of an OIDC identity to an existing local user account based
Kavita is a cross platform reading server. Prior to 0.9.0.2, an Improper Token validation flaw permits a remote and unau
OpenLearnX is an open-source, decentralized learning and assessment platform. Prior to 2.0.4, a critical authentication
The Mennekes Amtron series (firmware versions ≤ 5.22.3) is vulnerable to an authentication bypass. An unauthenticated re
An Improper Authentication vulnerability in the /api/Cdn/GetFile endpoint of linqi allows unauthenticated, remote attack
On Tapo C520WS v2, restricted accounts (for example, hub users) are intended to execute only a limited set of low‑sensit
The XML‑RPC API addUser method has a validation bypass introduced in the fix for CVE‑2025‑55129. As a result, API users
Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.1, 8.4.4, 8.3.6, 8.2.6,
@acastellon/auth is an authentication control system for microservices. Versions prior to 2.3.0 appear to allow an unaut
HestiaCP panel cronjob feature is affected by a broken access control vulnerability. Low privilege users can modify the
The charging station does not require authentication for Bluetooth commands to perform actions. The functionality expose
LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.4, when LightRAG is deployed with LIGHTRA
Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's SSO discovery and pre-valid
Wekan is open source kanban built with Meteor. Prior to 9.32, the Wekan Accounts.onCreateUser hook in server/models/user
Qinglong is a timed task management platform supporting Python3, JavaScript, Shell, and Typescript. Prior to 2.20.1, the
Frequently Asked Questions
What is CWE-287?
CWE-287 (Improper Authentication) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-287?
There are 5,272 CVE records associated with CWE-287 in our database. Of these, 1116 are critical severity, 1386 are high severity, and 1045 are medium severity.
How can I protect against CWE-287 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-287 using AI-powered security agents.
Detect CWE-287 Vulnerabilities
CyberStrike's AI agents automatically detect improper authentication vulnerabilities across your infrastructure.
Get Started