Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-287

MITRE ↗

Improper Authentication

1,116
CRITICAL
1,386
HIGH
1,045
MEDIUM
94
LOW
3,718 CVEs · Page 3/75
9.8
CVE-2026-61154

Vulnerability in the Oracle Commerce Guided Search Platform Services product of Oracle Commerce (component: Forge). Th

9.8
CVE-2026-61178

Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: In

9.8
CVE-2026-61183

Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Re

9.8
CVE-2026-61233

Vulnerability in the PeopleSoft Enterprise FIN Common Objects Brazil product of Oracle PeopleSoft (component: Integratio

9.8
CVE-2026-16232 KEV

An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote at

9.8
CVE-2026-60367

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Third

9.8
CVE-2026-15981

The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, a

9.8
CVE-2026-58066

Rocket.Chat's SAML SSO before versions 8.7.0, 8.6.1, 8.5.2, 8.4.5, 8.3.7, 8.2.7, 8.1.7, 8.0.8, and 7.10.14 verified XML

9.8
CVE-2026-28323

SolarWinds Web Help Desk is found to be affected by a SAML authentication bypass vulnerability. This requires the SAML 2

9.8
CVE-2026-14919

The ShopMonitor.io WordPress plugin before 1.2.0 does not properly restrict its email-rerouting test mode, gating it be

9.8
CVE-2026-63456

Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated

9.8
CVE-2026-9192

An authentication bypass vulnerability in the ODBC App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allo

9.8
CVE-2026-48087

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to ver

9.8
CVE-2026-65400 KEV

An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS

9.8
CVE-2026-14205

The WP Events Manager WordPress plugin before 2.2.5 does not validate the requested quantity when registering for a paid

9.8
CVE-2026-15038

The InfiniteWP Client WordPress plugin before 1.13.6 does not properly verify the site-connection state and the authenti

9.8
CVE-2026-16299

The Single Sign On For TNG WordPress plugin before 2.2.0 does not properly validate a password reset request, allowing u

9.8
CVE-2026-40920

Privilege Escalation via URL Parameter is reported in Apache Ranger versions <= 2.8.0. Users are recommended to upgrade

9.8
CVE-2026-51584

An issue in usememos v0.27.1 allows a remote attacker to achieve account takeover via the ssoCredentials branch of the S

9.8
CVE-2026-12571

An authentication bypass in ManageEngine DDI Central's password-reset workflow allows account takeover.

9.8
CVE-2026-26035

An Improper Authentication vulnerability [CWE-287] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.

9.8
CVE-2026-14182

The Customer Email Verification for WooCommerce WordPress plugin before 3.2.6 does not correctly validate the email-veri

9.8
CVE-2026-48528

Metacat is data repository software that helps researchers preserve, share, and discover data. Metacat versions 2.0.0 th

9.8
CVE-2026-17182

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to bypass authentication and obtain or alter sensit

9.8
CVE-2026-15303

The 6Storage Rentals plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.27.

9.8
CVE-2026-15341

The User Session Synchronizer plugin for WordPress is vulnerable to Authentication Bypass leading to Account Takeover in

9.8
CVE-2026-19924

A security vulnerability has been detected in Tenda AC10 16.03.10.09_multi_TDE01. This vulnerability affects the functio

9.8
CVE-2026-74894

openssl_encrypt before 1.4.0 contains an authentication bypass vulnerability in the verify_api_token function that accep

9.8
CVE-2026-70905

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Agent infrastructure). Suppo

9.8
CVE-2026-18031

The TabaPay Gateway WordPress plugin through 1.4.0 does not validate the payment callback before establishing a session

9.8
CVE-2026-16656

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to gain root privileges due to improper auth

9.8
CVE-2026-17142

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary commands due to imprope

9.8
CVE-2026-77000

The WP Social Media Login WordPress plugin through 1.0.6 does not verify that a social login was actually completed with

9.8
CVE-2026-77001

The Social Login & Sharing buttons with Analytics By SoClever WordPress plugin through 1.2.0 does not perform any authen

9.8
CVE-2026-77002

The SmilePass Selfie Login WordPress plugin through 1.0.2 does not perform any server-side verification of the identity

9.8
CVE-2026-78168

A security vulnerability has been detected in EFM ipTIME T24000M up to 14.20.0. This affects the function httpcon_check_

9.8
CVE-2026-79787

Alluxio's S3 REST proxy fails to verify AWS Signature Version 4 signatures in its default configuration, allowing unauth

9.8
CVE-2026-75325

DWSurvey v6.14.0 is is vulnerable to authentication bypass via the '/api/dwsurvey/none/' and '/api/dwsurvey/up/**' param

9.8
CVE-2026-37006

A vulnerability in the WebSocket endpoint of gpt-researcher v0.14.7 and before allows an unauthenticated remote attacker

9.8
CVE-2026-82329

JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated at

9.6
CVE-2026-1568

Rapid7 InsightVM versions before 8.34.0 contain a signature verification issue on the Assertion Consumer Service (ACS) c

9.6
CVE-2026-44547

ChurchCRM is an open-source church management system. From 7.2.0 to 7.2.2, The fix for CVE-2026-4058 is incomplete. The

9.6
CVE-2026-59151

Prowler is a cloud security platform. Prior to 5.30.3, Prowler's SAML authentication flow trusted the email domain asser

9.6
CVE-2026-22752

Authentication bypass by primary weakness vulnerability in Spring Security Spring Authorization Server. This issue affe

9.6
CVE-2026-62896

Improper authentication in Microsoft Teams allows an authorized attacker to elevate privileges over a network.

9.4
CVE-2026-21891

ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In versions up to and inc

9.4
CVE-2025-68717

KAYSUS KS-WR3600 routers with firmware 1.0.5.9.1 allow authentication bypass during session validation. If any user is l

9.4
CVE-2025-67822

A vulnerability in the Provisioning Manager component of Mitel MiVoice MX-ONE 7.3 (7.3.0.0.50) through 7.8 SP1 (7.8.1.0.

9.4
CVE-2025-70833

An Authentication Bypass vulnerability in Smanga 3.2.7 allows an unauthenticated attacker to reset the password of any u

9.4
CVE-2026-33716

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the standalone live stream control e

Frequently Asked Questions

What is CWE-287?

CWE-287 (Improper Authentication) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-287?

There are 5,272 CVE records associated with CWE-287 in our database. Of these, 1116 are critical severity, 1386 are high severity, and 1045 are medium severity.

How can I protect against CWE-287 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-287 using AI-powered security agents.

Detect CWE-287 Vulnerabilities

CyberStrike's AI agents automatically detect improper authentication vulnerabilities across your infrastructure.

Get Started