An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a re
Improper Authentication vulnerability in Repute Infosystems BookingPress allows Accessing Functionality Not Properly Con
Improper Authentication vulnerability in Mestres do WP Checkout Mestres WP allows Accessing Functionality Not Properly C
Bludit uses predictable methods in combination with the MD5 hashing algorithm to generate sensitive tokens such as the A
Servision - CWE-287: Improper Authentication
Discourse is an open source platform for community discussion. A maliciously crafted email address could allow an attack
Unit4 Financials by Coda versions prior to 2023Q4 suffer from an incorrect access control authorization bypass vulnerabi
Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Authentication vulne
Mattermost versions 9.8.x <= 9.8.0, 9.7.x <= 9.7.4, 9.6.x <= 9.6.2 and 9.5.x <= 9.5.5, when shared channels are enabled,
cgi-bin/fdmcgiwebv2.cgi on Swissphone DiCal-RED 4009 devices allows an unauthenticated attacker to gain access to device
In Eclipse Dataspace Components, from version 0.5.0 and before version 0.9.0, the ConsumerPullTransferTokenValidationApi
CVE-2024-45823 IMPACT An authentication bypass vulnerability exists in the affected product. The vulnerability exists
Meshtastic is an open source, off-grid, decentralized, mesh network. Meshtastic uses MQTT to communicate over an interne
The goTenna Pro App does not authenticate public keys which allows an unauthenticated attacker to manipulate messages.
Jenkins OpenId Connect Authentication Plugin 4.354.v321ce67a_1de8 and earlier does not check the `aud` (Audience) claim
Jenkins OpenId Connect Authentication Plugin 4.354.v321ce67a_1de8 and earlier does not check the `iss` (Issuer) claim of
Lif Authentication Server is a server used by Lif to do various tasks regarding Lif accounts. This vulnerability has to
The ProfilePress Pro plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 4
A vulnerability in Okta Verify for iOS versions 9.25.1 (beta) and 9.27.0 (including beta) allows push notification respo
The Loginizer Security and Loginizer plugins for WordPress are vulnerable to authentication bypass in all versions up to
The WooCommerce - Social Login plugin for WordPress is vulnerable to authentication bypass in all versions up to, and in
The Heateor Social Login WordPress plugin for WordPress is vulnerable to authentication bypass in all versions up to, an
The Social Share, Social Login and Social Comments Plugin – Super Socializer plugin for WordPress is vulnerable to authe
Trustee is a set of tools and components for attesting confidential guests and providing secrets to them. The ART (**Att
The web application uses a weak authentication mechanism to verify that a request is coming from an authenticated and au
Improper authentication of an HTTP endpoint in the S3 Gateway of Apache Ozone 1.4.0 allows any authenticated Kerberos us
The Registration Forms – User Registration Forms, Invitation-Based Registrations, Front-end User Profile, Login Form &
OpenCTI is an open-source cyber threat intelligence platform. In versions below 6.2.18, because the function to limit th
The OAuth Single Sign On – SSO (OAuth Client) plugin for WordPress is vulnerable to authentication bypass in all version
The AirVantage platform is vulnerable to an unauthorized attacker registering previously unregistered devices on the Ai
Improper authentication vulnerability in onCharacteristicReadRequest in Auto Hotspot prior to SMR Feb-2024 Release 1 all
Improper authentication vulnerability in onCharacteristicWriteRequest in Auto Hotspot prior to SMR Feb-2024 Release 1 al
Extreme Networks EXOS before v.22.7 and before v.30.2 was discovered to contain an issue in its Web GUI which fails to r
The vulnerability allows a remote attacker to access sensitive data inside exported packages or obtain up to Remote Code
A vulnerability was reported in Lenovo PC Manager prior to version 2.8.90.11211 that could allow a local attacker to esc
A vulnerability was reported in Lenovo PC Manager prior to version 2.8.90.11211 that could allow a local attacker to esc
A vulnerability that allows a user who has been assigned a low-privileged role within Veeam Backup & Replication to alte
Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability
Open Forms allows users create and publish smart forms. Versions prior to 2.2.9, 2.3.7, 2.4.5, and 2.5.2 contain a non-e
In Delinea PAM Secret Server 11.4, it is possible for a user assigned "Administer Reports" permission and/or with access
The SolarWinds Access Rights Manager was susceptible to a Directory Traversal and Information Disclosure Vulnerability.
vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. In affected ve
Lack of authentication in NPM's package @evershop/evershop before version 1.0.0-rc.8, allows remote attackers to obtain
Authorization vulnerability in the BootLoader module. Successful exploitation of this vulnerability may affect service i
HPE OneView may allow clusterService Authentication Bypass resulting in denial of service.
An authentication bypass vulnerability was found in overt-engine. This flaw allows the creation of users in the system w
IBM Storage Scale Container Native Storage Access 5.1.2.1 -through 5.1.7.0 could allow an attacker to initiate connectio
The Access Point functionality in eapol_auth_key_handle in eapol.c in iNet wireless daemon (IWD) before 2.14 allows atta
RobotsAndPencils go-saml, a SAML client library written in Go, contains an authentication bypass vulnerability in all kn
An improper authentication vulnerability [CWE-287] in FortiOS versions 7.4.1 and below, versions 7.2.6 and below, and ve
Frequently Asked Questions
What is CWE-287?
CWE-287 (Improper Authentication) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-287?
There are 5,272 CVE records associated with CWE-287 in our database. Of these, 1116 are critical severity, 1386 are high severity, and 1045 are medium severity.
How can I protect against CWE-287 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-287 using AI-powered security agents.
Detect CWE-287 Vulnerabilities
CyberStrike's AI agents automatically detect improper authentication vulnerabilities across your infrastructure.
Get Started