joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standar
Webmin is a web-based system administration tool for Unix-like servers. Prior to version 2.640, for Webmin accounts that
Flask-Security-Too allows users to add security features to their Flask applicationa. Version 5.8.0's OAuth reauthentica
Improper Authentication (CWE-287) in the PAM configuration in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-
The background service of ABP or AES runs as NT AUTHORITY\SYSTEM and implements a file-based inter-process communication
A vulnerability allowing an unauthenticated attacker to read arbitrary files from the host, which can be further leverag
Traefik is an open source HTTP reverse proxy and load balancer. From 3.6.11 until 3.6.25 and 3.7.10, Traefik's BasicAuth
Improper authentication in the Intel(R) TDX module for some Intel(R) platforms within Ring 0: Trust Domain may allow an
Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.36.0, the jwtAuthCheck function in server/auth/
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.30.0, FreeRDP server-side RDSTLS in libfreer
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. When `secureEnabled=true`, FUXA `1.3.0-2773` s
Budibase is an open-source low-code platform. Prior to 3.39.30, the OIDC flow in packages/backend-core/src/middleware/pa
UpTrain is an open-source platform to evaluate and improve generative AI applications. In version 0.7.1 and prior, the U
Joomla! Core - [20260807] - MFA Authentication Bypass in Joomla 4.0.0-5.4.7 and 6.0.0-6.1.2 - Insufficient state checks
Tapo C120 v1 and C200 v5 contain an improper authentication vulnerability within the login authentication verification m
This High severity BASM (Broken Authentication & Session Management) vulnerability known as CVE-2026-21582 was introduce
Improper Authentication vulnerability in team-alembic AshAuthentication allows purpose-limited JWTs to be replayed as fu
Doorkeeper is an OAuth 2 provider for Ruby on Rails. In version 1.9.0, an attacker who knows only a dynamically register
Arc is an open, SQL-native time-series database for telemetry. From 26.02.1 until 26.06.2, Arc Enterprise clustering acc
YesWiki is a wiki system written in PHP. Prior to version 4.5.4, the request to commence a site backup can be performed
On affected versions of the CloudVision Portal, improper access controls could enable a malicious authenticated user to
Authentication bypass by assumed-immutable data in Azure DevOps allows an unauthorized attacker to elevate privileges ov
Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.
Hikka, a Telegram userbot, has vulnerability affects all users on all versions of Hikka. Two scenarios are possible. 1.
A SAML library not dependent on any frameworks that runs in Node. In version 5.0.1, Node-SAML loads the assertion from t
Azure Entra ID Elevation of Privilege Vulnerability
The Itel DAB Gateway (IDGat build c041640a) is vulnerable to Authentication Bypass due to improper JWT validation across
The Itel DAB Encoder (IDEnc build 25aec8d) is vulnerable to Authentication Bypass due to improper JWT validation across
An attacker can bypass authorization checks and force a Step CA ACME or SCEP provisioner to create certificates without
SAP NetWeaver Application Server for ABAP and ABAP Platform allows an authenticated attacker to obtain illegitimate acce
code-projects Simple Car Rental System 1.0 has a permission bypass issue where low privilege users can forge high privil
The PayU CommercePro Plugin plugin for WordPress is vulnerable to privilege escalation in all versions up to, and includ
An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authe
The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPres
It has been found that the Beta10 software does not provide for proper authorisation control in multiple areas of the ap
**UNSUPPORTED WHEN ASSIGNED** Insecure default credentials for the Telnet function in the legacy DSL CPE Zyxel VMG4325-B
An issue in compop.ca ONLINE MALL v.3.5.3 allows a remote attacker to execute arbitrary code via the rid, tid, et, and t
Logsign Unified SecOps Platform Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypas
A vulnerability in the D-Link DIR-859 router with firmware version A3 1.05 and earlier permits unauthorized individuals
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.951 Application 20.0.2368 allows Unauthenticated
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows OAUTH Security
The WPCOM Member plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.7.5
A vulnerability has been identified in SINAMICS S200 (All versions with serial number beginning with SZVS8, SZVS9, SZVS0
DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.6, there is a flaw i
WeGIA is a Web manager for charitable institutions. A security vulnerability was identified in versions prior to 3.2.6,
An attacker with network access, could capture traffic and obtain user cookies, allowing the attacker to steal the activ
Unauthenticated RCE in HPE Insight Cluster Management Utility
This issue was addressed through improved state management. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequo
An issue in Student Study Center Desk Management System v1.0 allows attackers to bypass authentication via a crafted GET
PKCE was implemented in the OAuth implementation in workers-oauth-provider that is part of MCP framework https://github
Frequently Asked Questions
What is CWE-287?
CWE-287 (Improper Authentication) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-287?
There are 5,272 CVE records associated with CWE-287 in our database. Of these, 1116 are critical severity, 1386 are high severity, and 1045 are medium severity.
How can I protect against CWE-287 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-287 using AI-powered security agents.
Detect CWE-287 Vulnerabilities
CyberStrike's AI agents automatically detect improper authentication vulnerabilities across your infrastructure.
Get Started