A flaw was found in Keycloaks OpenID Connect user authentication, which may incorrectly authenticate requests. An authen
In Bluetooth, there is a possible way for a paired Bluetooth device to access a long term identifier for an Android devi
Under certain configurations, an attacker can login to Aruba EdgeConnect Enterprise Orchestrator without supplying a mul
Mattermost fails to invalidate previously generated password reset tokens when a new reset token was created.
Warpgate is a smart SSH, HTTPS and MySQL bastion host for Linux that doesn't need special client apps. The SSH key verif
WebAuthn4J Spring Security provides Web Authentication specification support for Spring applications. Affected versions
OpenSearch is an open source distributed and RESTful search engine. OpenSearch uses JWTs to store role claims obtained f
A flaw was found in shadow-utils. When asking for a new password, shadow-utils asks the password twice. If the password
There is a data processing error vulnerability in Leia-B29 2.0.0.49(M03). Successful exploitation could bypass lock scre
Dell BIOS contains an improper authentication vulnerability. A malicious user with physical access to the system may po
Improper authentication in SecSettings prior to SMR Sep-2023 Release 1 allows attacker to access Captive Portal Wi-Fi in
Improper authentication in SecSettings prior to SMR Mar-2023 Release 1 allows attacker to reset the setting.
Nextcloud android is an android app for interfacing with the nextcloud home server ecosystem. In versions from 3.7.0 and
Nextcloud iOS is an ios application used to interface with the nextcloud home cloud ecosystem. In versions prior to 4.7.
In SEPolicy, there is a possible way to access the factory MAC address due to a permissions bypass. This could lead to l
An improper implementation logic in Secure Folder prior to SMR Jan-2023 Release 1 allows the Secure Folder container rem
Improper access control vulnerability in telecom application prior to SMR JAN-2023 Release 1 allows local attackers to g
The undo_mark_statuses_as_sensitive method in app/services/approve_appeal_service.rb in Mastodon 3.5.x before 3.5.3 does
IBM Robotic Process Automation 21.0.0 - 21.0.7 and 23.0.0 is vulnerable to client-side validation bypass for credential
On version 3.0.0 through 3.1.1, Apache DolphinScheduler's python gateway suffered from improper authentication: an attac
Access Control Bypass Vulnerability in the SolarWinds Platform that allows an underprivileged user to read arbitrary r
The FULL - Customer plugin for WordPress is vulnerable to Information Disclosure via the /health REST route in versions
A vulnerability classified as problematic was found in Field Logic DataCube4 up to 20231001. This vulnerability affects
Standard users can directly operate and set printer configuration information , such as IP, in some Lenovo Printers with
The Nextcloud iOS Files app allows users of iOS to interact with Nextcloud, a self-hosted productivity platform. Prior t
Doorkeeper is an OAuth 2 provider for Ruby on Rails / Grape. Prior to version 5.6.6, Doorkeeper automatically processes
TYPO3 is an open source PHP based web content management system released under the GNU GPL. In typo3 installations there
Improper access control vulnerability in Phone application prior to SMR Feb-2023 Release 1 allows local attackers to acc
An Authentication Bypass Using an Alternate Path or Channel vulnerability in the Schweitzer Engineering Laboratories Rea
Improper authentication in GallerySearchProvider of Gallery prior to version 14.5.01.2 allows attacker to access search
A fully compromised ESXi host can force VMware Tools to fail to authenticate host-to-guest operations, impacting the con
The Operating System hosting the FACSChorus application is configured to allow transmission of hashed user credentials u
Due to missing authentication check in SAP Host Agent - version 7.22, an unauthenticated attacker can set an undocumente
Discourse is an open source discussion platform. When editing a topic, there is a vulnerability that enables a user to b
Jetty is a Java based web server and servlet engine. Versions 9.4.21 through 9.4.51, 10.0.15, and 11.0.15 are vulnerable
A logic issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.2, macOS Monterey 12
Concrete CMS (previously concrete5) versions 8.5.12 and below, and 9.0 through 9.1.3 is vulnerable to possible Auth bypa
Improper authentication in the Intel(R) SUR software before version 2.4.8902 may allow a privileged user to potentially
Improper Authentication of RemoteUI of Office / Small Office Multifunction Printers and Laser Printers(*) which may allo
IBM Robotic Process Automation 21.0.0 through 21.0.7.6 and 23.0.0 through 23.0.6 is vulnerable to client side validation
Improper Authentication vulnerability in Apache Software Foundation Apache Pulsar Broker allows a client to stay connect
MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x: Device ve
A vulnerability in the authentication functionality of Cisco Wireless LAN Controller (WLC) Software could allow an unaut
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. A critical vulnerability has been discovered i
Roxy-wi is an open source web interface for managing Haproxy, Nginx, Apache and Keepalived servers. A vulnerability in R
DataHub is an open-source metadata platform. Prior to version 0.8.45, the `StatelessTokenService` of the DataHub metadat
A flaw was found with the JWT token. A self-signed JWT token could be injected into the update manager and bypass the au
Some Dahua products have access control vulnerability in the password reset process. Attackers can exploit this vulnerab
This vulnerability allows remote attackers to bypass authentication on affected installations of Commvault CommCell 11.2
An issue was discovered on Crestron HD-MD4X2-4K-E 1.0.0.2159 devices. When the administrative web interface of the HDMI
Frequently Asked Questions
What is CWE-287?
CWE-287 (Improper Authentication) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-287?
There are 5,272 CVE records associated with CWE-287 in our database. Of these, 1116 are critical severity, 1386 are high severity, and 1045 are medium severity.
How can I protect against CWE-287 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-287 using AI-powered security agents.
Detect CWE-287 Vulnerabilities
CyberStrike's AI agents automatically detect improper authentication vulnerabilities across your infrastructure.
Get Started