Apache Guacamole 1.2.0 and 1.3.0 do not properly validate responses received from a SAML identity provider. If SAML supp
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R7000
The All in One SEO WordPress plugin before 4.1.5.3 is affected by a Privilege Escalation issue, which was discovered dur
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of multiple NETG
A flaw was found in StarWind Stack. The endpoint for setting a new password doesn’t check the current username and old p
capsule-proxy is a reverse proxy for Capsule Operator which provides multi-tenancy in Kubernetes. In versions prior to 0
CAMS for HIS Server contained in the following Yokogawa Electric products improperly authenticate the receiving packets.
Improper authentication in Veeam Backup & Replication 9.5U3, 9.5U4,10.x and 11.x component used for Microsoft System Cen
A flaw was found in the Pacemaker configuration tool (pcs). The pcs daemon was allowing expired accounts, and accounts w
There is no account authentication and permission check logic in the firmware and existing apps of SiHAS's SGW-300, ACM-
An Access Control vulnerability exists in Nacos 2.0.3 in the access prompt page; enter username and password, click on l
An issue was discovered in the auth component in Dovecot 2.2 and 2.3 before 2.3.20. When two passdb configuration entrie
An issue was discovered in Aviatrix Gateway before 6.6.5712 and 6.7.x before 6.7.1376. Because Gateway API functions mis
An improper password check exists in the login functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. An atta
A flaw was found in Samba. The security vulnerability occurs when KDC and the kpasswd service share a single account and
Indy Node is the server portion of a distributed ledger purpose-built for decentralized identity. In versions 1.12.4 and
Unverified Password Change in GitHub repository phpfusion/phpfusion prior to 9.10.20.
OpenHarmony-v3.1.1 and prior versions have a permission bypass vulnerability. LAN attackers can bypass permission contro
The WAVLINK Quantum D4G (WN531G3) running firmware version M31G3.V5030.200325 uses IP addresses to hold sessions and doe
A improper authentication vulnerability exists in Rocket.Chat <v5, <v4.8.2 and <v4.7.5 that allowed two factor authentic
Boodskap IoT Platform v4.4.9-02 allows attackers to escalate privileges via a crafted request sent to /api/user/upsert/<
Bifrost is a heterogeneous middleware that synchronizes MySQL, MariaDB to Redis, MongoDB, ClickHouse, MySQL and other se
Agentflow BPM enterprise management system has improper authentication. A remote attacker with general user privilege ca
SolarWinds Platform was susceptible to Improper Input Validation. This vulnerability allows a remote adversary with vali
An issue was discovered in Veritas NetBackup Flex Scale through 3.0 and Access Appliance through 8.0.100. A default pass
Improper authentication vulnerability in UDR-JA1604/UDR-JA1608/UDR-JA1616 firmware versions 71x10.1.107112.43A and earli
Authentication bypass vulnerability in multiple Buffalo network devices allows a network-adjacent attacker to bypass aut
A support user exists on the device and appears to be a backdoor for Technical Support staff. The default password for t
Improper authentication in firmware for Intel(R) AMT before versions 11.8.93, 11.22.93, 11.12.93, 12.0.92, 14.1.67, 15.0
Velneo vClient on its 28.1.3 version, could allow an attacker with knowledge of the victims's username and hashed passwo
Flower, a web UI for the Celery Python RPC framework, all versions as of 05-02-2022 is vulnerable to an OAuth authentica
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version
matrix-android-sdk2 is the Matrix SDK for Android. Prior to version 1.5.1, an attacker cooperating with a malicious home
Matrix Javascript SDK is the Matrix Client-Server SDK for JavaScript. Prior to version 19.7.0, an attacker cooperating w
Matrix iOS SDK allows developers to build iOS apps compatible with Matrix. Prior to version 0.23.19, an attacker coopera
nheko is a desktop client for the Matrix communication application. All versions below 0.10.2 are vulnerable homeservers
Matrix JavaScript SDK is the Matrix Client-Server software development kit (SDK) for JavaScript. Prior to version 19.7.0
matrix-rust-sdk is an implementation of a Matrix client-server library in Rust, and matrix-sdk-crypto is the Matrix encr
matrix-nio is a Python Matrix client library, designed according to sans I/O principles. Prior to version 0.20, when a u
CodeIgniter is a PHP full-stack web framework. When an application uses (1) multiple session cookies (e.g., one for user
XWiki Platform Web Templates are templates for XWiki Platform, a generic wiki platform. By passing a template of the dis
Bifrost is a middleware package which can synchronize MySQL/MariaDB binlog data to other types of databases. Versions 1.
An issue was discovered in Logitech Options. The OAuth 2.0 state parameter was not properly validated. This leaves appli
Mist is the command-line interface for the makedeb Package Repository. Prior to version 0.9.5, a user-provided `sudo` bi
OpenHarmony-v3.1.2 and prior versions have a Missing permission validation vulnerability in param service of startup sub
OpenHarmony-v3.1.2 and prior versions had an Multiple path traversal vulnerability in appspawn and nwebspawn services. L
Linux users running Lens 5.2.6 and earlier could be compromised by visiting a malicious website. The malicious website c
A CWE-287: Improper Authentication vulnerability exists that could allow an attacker to take over the admin account when
An issue was discovered in the YugabyteDB 2.6.1 when using LDAP-based authentication in YCQL with Microsoft’s Active Dir
SFTPGo is configurable SFTP server with optional HTTP/S, FTP/S and WebDAV support. SFTPGo WebAdmin and WebClient support
Frequently Asked Questions
What is CWE-287?
CWE-287 (Improper Authentication) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-287?
There are 5,272 CVE records associated with CWE-287 in our database. Of these, 1116 are critical severity, 1386 are high severity, and 1045 are medium severity.
How can I protect against CWE-287 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-287 using AI-powered security agents.
Detect CWE-287 Vulnerabilities
CyberStrike's AI agents automatically detect improper authentication vulnerabilities across your infrastructure.
Get Started