Alpine is a scaffolding library in Java. Alpine prior to version 1.10.4 allows Authentication Filter bypass. The Authent
In versions `<=8.5.1` of `jsonwebtoken` library, lack of algorithm definition in the `jwt.verify()` function can lead to
authentik is an open-source Identity provider focused on flexibility and versatility. In versions prior to 2022.10.4, an
A vulnerability was found in SourceCodester Company Website CMS 1.0. It has been declared as critical. Affected by this
Velneo vClient on its 28.1.3 version, does not correctly check the certificate of authenticity by default. This could al
Broken access controls on PDFtron WebviewerUI in M-Files Hubshare before 3.3.11.3 allows unauthenticated attackers to u
Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 did not use strict comparison for the legacy_
Improper access control vulnerability in Samsung Account prior to version 13.1.0.1 allows attackers to access to the aut
Improper access control vulnerability in TelephonyUI prior to SMR Jul-2022 Release 1 allows attackers to change preferre
Improper access control vulnerability in Samsung Dex for PC prior to SMR Aug-2022 Release 1 allows local attackers to sc
OpenHarmony-v3.1.2 and prior versions have a permission bypass vulnerability. Local attackers can bypass permission cont
OpenHarmony-v3.1.2 and prior versions have a permission bypass vulnerability. LAN attackers can bypass the distributed p
Prometheus Exporter Toolkit is a utility package to build exporters. Prior to versions 0.7.2 and 0.8.2, if someone has a
OpenHarmony-v3.1.2 and prior versions had a vulnerability that telephony in communication subsystem sends public events
Dell BIOS versions contain an Improper Authentication vulnerability. A locally authenticated malicious user could potent
A vulnerability in the smart card login authentication of Cisco Duo for macOS could allow an unauthenticated attacker wi
Wyse Device Agent version 14.6.1.4 and below contain an Improper Authentication vulnerability. A malicious user could po
A flaw was found in the way samba implemented SMB1 authentication. An attacker could use this flaw to retrieve the plain
A vulnerability classified as problematic has been found in GE Voluson S8. Affected is the file /uscgi-bin/users.cgi of
The server checks the user's cookie in a non-standard way, and a value is entered in the cookie value name of the status
Authentication Bypass vulnerability in CodexShaper's WP OAuth2 Server plugin <= 1.0.1 at WordPress.
TYPO3 is an open source PHP based web content management system. In versions prior to 8.7.49, 9.5.38, 10.4.33, 11.5.20,
IBM Security Verify Governance, Identity Manager 10.0.1 software component could allow an authenticated user to modify
Improper authentication vulnerability in Samsung Internet prior to 16.0.2.19 allows attackers to bypass secret mode pass
Improper access control vulnerability in Knox Manage prior to SMR Apr-2022 Release 1 allows that physical attackers can
An access control issue in Wavlink WiFi-Repeater RPTA2-77W.M4300.01.GD.2017Sep19 allows attackers to obtain the key info
Improper authentication vulnerability in Samsung WindowManagerService prior to SMR Dec-2022 Release 1 allows attacker to
An authentication issue was addressed with improved state management. This issue is fixed in tvOS 15.5. A local user may
A vulnerability, which was classified as critical, was found in Platinum Mobile 1.0.4.850. Affected is /MobileHandler.as
The Candlepin component of Red Hat Satellite was affected by an improper authentication flaw. Few factors could allow an
After performing a sequence of Power FW950, FW1010 maintenance operations a SRIOV network adapter can be improperly con
A vulnerability in the web server of Secomea GateManager allows a local user to impersonate as the previous user under s
Some smartphones have authentication-related (including session management) vulnerabilities as the setup wizard is bypas
Opencast is a free and open source solution for automated video capture and distribution at scale. Prior to Opencast 10.
Nextcloud mail is a Mail app for the Nextcloud home server product. Versions of Nextcloud mail prior to 1.12.2 were foun
Due to a bug in the handling of the communication between the client and server, it was possible for one client, already
A unverified password change in Fortinet FortiADC version 6.2.0 through 6.2.3, 6.1.x, 6.0.x, 5.x.x allows an authenticat
TYPO3 is an open source PHP based web content management system released under the GNU GPL. It has been discovered that
The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) allows attackers
Improper access control vulnerability in S Assistant prior to version 7.5 allows attacker to remotely get senstive infor
Dell iDRAC 8 prior to version 2.82.82.82 contain a denial of service vulnerability. An unauthenticated remote attacker c
fleet is an open source device management, built on osquery. Versions prior to 4.9.1 expose a limited ability to spoof S
The web interface of the 1734-AENTR communication module mishandles authentication for HTTP POST requests. A remote, una
ImpressCMS before 1.4.3 has Incorrect Access Control because include/findusers.php allows access by unauthenticated atta
CreateWiki is Miraheze's MediaWiki extension for requesting & creating wikis. Without the patch for this issue, anonymou
A vulnerability has been identified in SICAM T (All versions < V3.0). Affected devices do not restrict unauthenticated a
A vulnerability in the login page of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacke
Meridian Cooperative Utility Software versions 22.02 and 22.03 allows remote attackers to obtain sensitive information s
Improper authentication vulnerability in Scheduler of Cybozu Garoon 4.10.0 to 5.5.1 allows a remote attacker to obtain s
The OAuth Single Sign On WordPress plugin before 6.22.6 doesn't validate that OAuth access token requests are legitimate
Frequently Asked Questions
What is CWE-287?
CWE-287 (Improper Authentication) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-287?
There are 5,272 CVE records associated with CWE-287 in our database. Of these, 1116 are critical severity, 1386 are high severity, and 1045 are medium severity.
How can I protect against CWE-287 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-287 using AI-powered security agents.
Detect CWE-287 Vulnerabilities
CyberStrike's AI agents automatically detect improper authentication vulnerabilities across your infrastructure.
Get Started