Multiple methods in the salt master skip minion token validation. Therefore a misbehaving minion can impersonate another
The Nextcloud Approval app allows approval or disapproval of files in the sidebar. Prior to 1.3.1 and 2.5.0, an authenti
A vulnerability was found in i-Drive i11 and i12 up to 20250227. It has been classified as problematic. Affected is an u
PAM-PKCS#11 is a Linux-PAM login module that allows a X.509 certificate based user login. Prior to version 0.6.13, if ce
A flaw in Gliffy results in broken authentication through the reset functionality of the application.
MinIO is a high performance object storage. Starting in RELEASE.2024-06-06T09-36-42Z and prior to RELEASE.2025-02-28T09
Scratch-Coding-Hut.github.io is the website for Coding Hut. The website as of 28 February 2025 contained a sign in with
Ratify is a verification engine as a binary executable and on Kubernetes which enables verification of artifact security
scratch-coding-hut.github.io is the website for Coding Hut. In 1.0-beta3 and earlier, the login link can be used to logi
An authentication bypass vulnerability was found in Videx's CyberAudit-Web. Through the exploitation of a logic flaw, an
passport-wsfed-saml2 provides passport strategy for both WS-fed and SAML2 protocol. A vulnerability present starting in
passport-wsfed-saml2 provides passport strategy for both WS-fed and SAML2 protocol. A vulnerability present starting in
Improper authentication handling was identified in a set of HTTP POST requests affecting the following product families:
auth-js is an isomorphic Javascript library for Supabase Auth. Prior to version 2.70.0, the library functions getUserByI
Improper Authentication vulnerability in WF Steuerungstechnik GmbH airleader MASTER allows Authentication Bypass.This is
Press, a Frappe custom app that runs Frappe Cloud, manages infrastructure, subscription, marketplace, and software-as-a-
An improper access control vulnerability was found in the EZ Sync Manager of ADM, which allows authenticated users to c
A vulnerability in Imprivata Enterprise Access Management (formerly Imprivata OneSign) allows bypassing the login screen
Fedify is a TypeScript library for building federated server apps powered by ActivityPub. In versions below 1.3.20, 1.4.
The Evertz SDVN 3080ipx-10G is a High Bandwidth Ethernet Switching Fabric for Video Application. This device exposes a w
Improper authentication vulnerability in Novakon P series allows unauthenticated attackers to upload and download any ap
Incorrect authentication vulnerability in OpenSIAC, which could allow an attacker to impersonate a person using Cl@ve as
A broken authorization vulnerability in Kiloview NDI N30 allows a remote unauthenticated attacker to deactivate user ver
pwn.college DOJO is an education platform for learning cybersecurity. Prior to commit 467db0b9ea0d9a929dc89b41f6eb59f7cf
Improper Authentication vulnerability in GE Vernova Smallworld on Windows, Linux allows Authentication Abuse.This issue
Milvus is an open-source vector database built for generative AI applications. An unauthenticated attacker can exploit a
Improper Authentication vulnerability in TYPO3 Extension "Modules" codingms/modules.This issue affects Extension "Module
An authentication bypass vulnerability in Google Cloud Dialogflow CX Messenger allowed unauthenticated users to interact
CWE-287: Improper Authentication may allow Authentication Bypass
Adobe Framemaker Publishing Server versions 2020.3, 2022.2 and earlier are affected by an Improper Authentication vulner
A condition exists in FlashArray Purity whereby an attacker can employ a privileged account allowing remote access to th
OpenObserve is a observability platform built specifically for logs, metrics, traces, analytics, designed to work at pet
Improper Authentication vulnerability in EazyPlugins Eazy Plugin Manager allows Accessing Functionality Not Properly Con
Dataiku DSS before 11.4.5 and 12.4.1 has Incorrect Access Control that could lead to a full authentication bypass.
An issue was discovered on GL.iNet devices before version 4.5.0. There is an NGINX authentication bypass via Lua string
The authentication mechanism can be bypassed by overflowing the value of the Cookie "authentication" field, provided the
CrateDB 5.5.1 is contains an authentication bypass vulnerability in the Admin UI component. After configuring password a
Gessler GmbH WEB-MASTER has a restoration account that uses weak hard coded credentials and if exploited could allow an
Lack of authentication in all versions of the fileserver component of Allegro AI’s ClearML platform allows a remote atta
An improper authentication vulnerability has been identified in SonicWall SonicOS SSL-VPN feature, which in specific con
An issue in Daily Habit Tracker v.1.0 allows a remote attacker to manipulate trackers via the home.php, add-tracker.php,
Microsoft Exchange Server Elevation of Privilege Vulnerability
Adobe FrameMaker Publishing Server versions 2022.1 and earlier are affected by an Improper Authentication vulnerability
An improper authentication vulnerability has been reported to affect several QNAP operating system versions. If exploite
An issue was discovered in Newland Nquire 1000 Interactive Kiosk version NQ1000-II_G_V1.00.011, allows remote attackers
An authentication bypass vulnerability exists in Arcserve Unified Data Protection 9.2 and 8.1 in the edge-app-base-webui
OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository
Weak access control in OpenText PVCS Version Manager allows potential bypassing of authentication and download of files.
Weak access control in OpenText PVCS Version Manager allows potential bypassing of authentication and uploading of files
In TeslaMate before 1.27.2, there is unauthorized access to port 4000 for remote viewing and operation of user data. Aft
Frequently Asked Questions
What is CWE-287?
CWE-287 (Improper Authentication) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-287?
There are 5,272 CVE records associated with CWE-287 in our database. Of these, 1116 are critical severity, 1386 are high severity, and 1045 are medium severity.
How can I protect against CWE-287 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-287 using AI-powered security agents.
Detect CWE-287 Vulnerabilities
CyberStrike's AI agents automatically detect improper authentication vulnerabilities across your infrastructure.
Get Started