Improper authentication in Microsoft Defender for Identity allows an unauthorized attacker to perform spoofing over an a
An issue was discovered in Infoblox NETMRI before 7.6.1. Authentication Bypass via a Hardcoded credential can occur.
Netwrix Directory Manager (formerly Imanami GroupID) v.11.0.0.0 and before, as well as after v.11.1.25134.03 lacks Authe
If you enable Basic Authentication in Pekko Management using the Java DSL, the authenticator may not be properly applied
Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a networ
Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.12.0 and prior to
Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a networ
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. Prior to versio
Flask-AppBuilder is an application development framework. Prior to version 4.8.1, when Flask-AppBuilder is configured to
An improper authentication vulnerability [CWE-287] in Fortinet FortiAnalyzer version 7.6.0 through 7.6.3 and before 7.4.
There is an improper authentication vulnerability in some Hikvision DVR products. Due to the improper implementation of
An issue was discovered in Zeroheight (SaaS) prior to 2025-06-13. A legacy user creation API pathway allowed accounts to
A logic issue was addressed with improved state management. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7
Nextcloud Server is a self hosted personal cloud system. Nextcloud Server prior to 29.0.15, 30.0.9, and 31.0.3 and Nextc
The salt.auth.pki module does not properly authenticate callers. The "password" field contains a public certificate whic
Bypass vulnerability in the network search instruction authentication module Impact: Successful exploitation of this vul
A vulnerability was identified in huggingface LeRobot up to 0.3.3. Affected by this vulnerability is an unknown function
A security flaw has been discovered in JeecgBoot up to 3.9.0. The affected element is an unknown function of the file je
A weakness has been identified in joey-zhou xiaozhi-esp32-server-java up to 3.0.0. This impacts the function tryAuthenti
A vulnerability exists in ChurchCRM 5.13.0 and prior that allows an attacker to hijack a user's session by exploiting a
An Improper Access Control vulnerability in the Stylus Tools component of Google ChromeOS version 16238.64.0 on the gara
An issue in the web socket handshake process of SteVe v3.7.1 allows attackers to bypass authentication and execute arbit
Froxlor is open-source server administration software. A vulnerability in versions prior to 2.2.6 allows users (such as
An improper authentication vulnerability exists in WSO2 Identity Server 7.0.0 due to an implementation flaw that allows
An issue was discovered in the COROS application through 3.8.12 for Android. Bluetooth pairing and bonding is neither in
Insufficient validation of the screen lock mechanism in Trust Wallet v8.45 allows physically proximate attackers to bypa
An issue in RTSPtoWeb v.2.4.3 allows a remote attacker to obtain sensitive information and executearbitrary code via the
A vulnerability classified as critical was found in Beijing Yunfan Internet Technology Yunfan Learning Examination Syste
In WhatsUp Gold versions released before 2024.0.3, a database manipulation vulnerability allows an unauthenticated a
A vulnerability was found in WCMS up to 8.3.11. It has been declared as critical. Affected by this vulnerability is the
A vulnerability, which was classified as critical, has been found in xxyopen/201206030 novel-plus up to 5.1.3. Affected
Dell Secure Connect Gateway (SCG) 5.0 Appliance - SRS, version(s) 5.26, Enables Live-Restore setting which enhances secu
Improper Authentication vulnerability in Drupal Login Disable allows Exploiting Incorrectly Configured Access Control Se
A flaw was found in Keycloak. When an Active Directory user resets their password, the system updates it without perform
Improper password reset in PAM Module in Devolutions Server 2024.3.10.0 and earlier allows an authenticated user to reus
While processing the authentication message in UE, improper authentication may lead to information disclosure.
A flaw was found in Keycloak. The org.keycloak.authorization package may be vulnerable to circumventing required actions
Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. Himmelblau versions 0.9.0 through 0.9.1
Improper Authentication (CWE-287) in the LDAP authentication engine in AxxonSoft Axxon One (C-Werk) 2.0.2 and earlier on
A serious authentication flaw allowed attackers with valid credentials to bypass multi-factor authentication under certa
An issue was discovered in allauth-django before 65.13.0. Both Okta and NetIQ were using preferred_username as the ident
HCL MyXalytics is affected by broken authentication. It allows attackers to compromise keys, passwords, and session tok
Matrix Media Repo (MMR) is a highly configurable multi-homeserver media repository for Matrix. MMR before version 1.3.5
In Apache Cassandra it is possible for a local attacker without access to the Apache Cassandra process or configuration
A vulnerability was found in otale Tale Blog 2.0.5. It has been classified as problematic. This affects an unknown part
A vulnerability, which was classified as critical, has been found in IROAD Dash Cam X5 and Dash Cam X6 up to 20250308. A
A vulnerability has been found in qinguoyi TinyWebServer up to 1.0 and classified as critical. This vulnerability affect
Spring Cloud Config Server may not use Vault token sent by clients using a X-CONFIG-TOKEN header when making requests to
BEC Technologies Multiple Routers Authentication Bypass Vulnerability. This vulnerability allows remote attackers to byp
A vulnerability was found in 20120630 Novel-Plus up to 0e156c04b4b7ce0563bef6c97af4476fcda8f160. It has been rated as cr
Frequently Asked Questions
What is CWE-287?
CWE-287 (Improper Authentication) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-287?
There are 5,272 CVE records associated with CWE-287 in our database. Of these, 1116 are critical severity, 1386 are high severity, and 1045 are medium severity.
How can I protect against CWE-287 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-287 using AI-powered security agents.
Detect CWE-287 Vulnerabilities
CyberStrike's AI agents automatically detect improper authentication vulnerabilities across your infrastructure.
Get Started