Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-287

MITRE ↗

Improper Authentication

1,116
CRITICAL
1,386
HIGH
1,045
MEDIUM
94
LOW
3,718 CVEs · Page 16/75
CVE-2026-49852

joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standar

CVE-2026-42210

Webmin is a web-based system administration tool for Unix-like servers. Prior to version 2.640, for Webmin accounts that

CVE-2026-46715

Flask-Security-Too allows users to add security features to their Flask applicationa. Version 5.8.0's OAuth reauthentica

CVE-2026-12504

Improper Authentication (CWE-287) in the PAM configuration in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-

CVE-2026-18759

The background service of ABP or AES runs as NT AUTHORITY\SYSTEM and implements a file-based inter-process communication

CVE-2026-58075

A vulnerability allowing an unauthenticated attacker to read arbitrary files from the host, which can be further leverag

CVE-2026-71326

Traefik is an open source HTTP reverse proxy and load balancer. From 3.6.11 until 3.6.25 and 3.7.10, Traefik's BasicAuth

CVE-2026-20885

Improper authentication in the Intel(R) TDX module for some Intel(R) platforms within Ring 0: Trust Domain may allow an

CVE-2026-73085

Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.36.0, the jwtAuthCheck function in server/auth/

CVE-2026-73241

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.30.0, FreeRDP server-side RDSTLS in libfreer

CVE-2026-47718

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. When `secureEnabled=true`, FUXA `1.3.0-2773` s

CVE-2026-73302

Budibase is an open-source low-code platform. Prior to 3.39.30, the OIDC flow in packages/backend-core/src/middleware/pa

CVE-2025-27621

UpTrain is an open-source platform to evaluate and improve generative AI applications. In version 0.7.1 and prior, the U

CVE-2026-73337

Joomla! Core - [20260807] - MFA Authentication Bypass in Joomla 4.0.0-5.4.7 and 6.0.0-6.1.2 - Insufficient state checks

CVE-2026-15315

Tapo C120 v1 and C200 v5 contain an improper authentication vulnerability within the login authentication verification m

CVE-2026-21582

This High severity BASM (Broken Authentication & Session Management) vulnerability known as CVE-2026-21582 was introduce

CVE-2026-65633

Improper Authentication vulnerability in team-alembic AshAuthentication allows purpose-limited JWTs to be replayed as fu

CVE-2026-44476

Doorkeeper is an OAuth 2 provider for Ruby on Rails. In version 1.9.0, an attacker who knows only a dynamically register

CVE-2026-55678

Arc is an open, SQL-native time-series database for telemetry. From 26.02.1 until 26.06.2, Arc Enterprise clustering acc

10.0
CVE-2025-46348

YesWiki is a wiki system written in PHP. Prior to version 4.5.4, the request to commence a site backup can be performed

10.0
CVE-2024-11186

On affected versions of the CloudVision Portal, improper access controls could enable a malicious authenticated user to

10.0
CVE-2025-29813

Authentication bypass by assumed-immutable data in Azure DevOps allows an unauthorized attacker to elevate privileges ov

10.0
CVE-2025-32975 KEV

Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.

10.0
CVE-2025-52572

Hikka, a Telegram userbot, has vulnerability affects all users on all versions of Hikka. Two scenarios are possible. 1.

10.0
CVE-2025-54419

A SAML library not dependent on any frameworks that runs in Node. In version 5.0.1, Node-SAML loads the assertion from t

10.0
CVE-2025-55241

Azure Entra ID Elevation of Privilege Vulnerability

10.0
CVE-2025-63216

The Itel DAB Gateway (IDGat build c041640a) is vulnerable to Authentication Bypass due to improper JWT validation across

10.0
CVE-2025-63224

The Itel DAB Encoder (IDEnc build 25aec8d) is vulnerable to Authentication Bypass due to improper JWT validation across

10.0
CVE-2025-44005

An attacker can bypass authorization checks and force a Step CA ACME or SCEP provisioner to create certificates without

9.9
CVE-2025-0070

SAP NetWeaver Application Server for ABAP and ABAP Platform allows an authenticated attacker to obtain illegitimate acce

9.9
CVE-2025-60306

code-projects Simple Car Rental System 1.0 has a permission bypass issue where low privilege users can forge high privil

9.8
CVE-2024-12264

The PayU CommercePro Plugin plugin for WordPress is vulnerable to privilege escalation in all versions up to, and includ

9.8
CVE-2024-53704 KEV

An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authe

9.8
CVE-2024-12919

The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPres

9.8
CVE-2025-0637

It has been found that the Beta10 software does not provide for proper authorisation control in multiple areas of the ap

9.8
CVE-2025-0890

**UNSUPPORTED WHEN ASSIGNED** Insecure default credentials for the Telnet function in the legacy DSL CPE Zyxel VMG4325-B

9.8
CVE-2024-48445

An issue in compop.ca ONLINE MALL v.3.5.3 allows a remote attacker to execute arbitrary code via the rid, tid, et, and t

9.8
CVE-2025-1044

Logsign Unified SecOps Platform Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypas

9.8
CVE-2024-57045

A vulnerability in the D-Link DIR-859 router with firmware version A3 1.05 and earlier permits unauthorized individuals

9.8
CVE-2025-27641

Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.951 Application 20.0.2368 allows Unauthenticated

9.8
CVE-2025-27672

Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows OAUTH Security

9.8
CVE-2025-1475

The WPCOM Member plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.7.5

9.8
CVE-2024-56336

A vulnerability has been identified in SINAMICS S200 (All versions with serial number beginning with SZVS8, SZVS9, SZVS0

9.8
CVE-2025-27138

DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.6, there is a flaw i

9.8
CVE-2025-30361

WeGIA is a Web manager for charitable institutions. A security vulnerability was identified in versions prior to 3.2.6,

9.8
CVE-2025-2859

An attacker with network access, could capture traffic and obtain user cookies, allowing the attacker to steal the activ

9.8
CVE-2024-13804

Unauthenticated RCE in HPE Insight Cluster Management Utility

9.8
CVE-2025-30430

This issue was addressed through improved state management. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequo

9.8
CVE-2023-44752

An issue in Student Study Center Desk Management System v1.0 allows attackers to bypass authentication via a crafted GET

9.8
CVE-2025-4144

PKCE was implemented in the OAuth implementation in workers-oauth-provider that is part of MCP framework https://github

Frequently Asked Questions

What is CWE-287?

CWE-287 (Improper Authentication) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-287?

There are 5,272 CVE records associated with CWE-287 in our database. Of these, 1116 are critical severity, 1386 are high severity, and 1045 are medium severity.

How can I protect against CWE-287 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-287 using AI-powered security agents.

Detect CWE-287 Vulnerabilities

CyberStrike's AI agents automatically detect improper authentication vulnerabilities across your infrastructure.

Get Started