The User Registration & User Profile – Profile Builder WordPress plugin before 3.4.9 has a bug allowing any user to rese
WP Cerber before 8.9.3 allows MFA bypass via wordpress_logged_in_[hash] manipulation.
Delta Electronics DIAEnergie Version 1.7.5 and prior may allow an attacker to add a new administrative user without bein
Zoho ManageEngine ADSelfService Plus version 6103 and prior allows CAPTCHA bypass due to improper parameter validation.
This vulnerability allows an attacker who has access to the WBM to read and write settings-parameters of the device by s
VMware Workspace ONE Access and Identity Manager, allow the /cfg web app and diagnostic endpoints, on port 8443, to be a
webctrl.cgi.elf on Christie Digital DWU850-GS V06.46 devices allows attackers to perform any desired action via a crafte
A vulnerability in the TACACS+ authentication, authorization and accounting (AAA) feature of Cisco Enterprise NFV Infras
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can by
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can by
Apache Shiro before 1.8.0, when using Apache Shiro with Spring Boot, a specially crafted HTTP request may cause an authe
XSS Hunter Express before 2021-09-17 does not properly enforce authentication requirements for paths.
A flaw was found in Red Hat DataGrid 8.x (8.0.0, 8.0.1, 8.1.0 and 8.1.1) and Infinispan (10.0.0 through 12.0.0). An atta
An improper access control vulnerability in GitHub Enterprise Server allowed a workflow job to execute in a self-hosted
Webauthn Framework 3.3.x before 3.3.4 has Incorrect Access Control. An attacker that controls a user's system is able to
Couchbase Server 6.5.x and 6.6.x through 6.6.2 has Incorrect Access Control. Externally managed users are not prevented
ECOA BAS controller suffers from an authentication bypass vulnerability. An unauthenticated attacker through cookie pois
IBM Cloud Pak for Security (CP4S) 1.7.0.0, 1.7.1.0, 1.7.2.0, and 1.8.0.0 could allow an attacker to perform unauthorized
An issue in the administrator authentication panel of PTCL HG150-Ub v3.0 allows attackers to bypass authentication via m
Grafana is an open source data visualization platform. In affected versions unauthenticated and authenticated users are
There is an improper authentication vulnerability in Hero-CT060 before 1.0.0.200. The vulnerability is due to that when
The usage of an internal HTTP header created an authentication bypass vulnerability (CWE-287), allowing an attacker to v
An issue was discovered in Talend Data Catalog before 7.3-20210930. After setting up SAML/OAuth, authentication is not c
A flaw was found in Apache ShenYu Admin. The incorrect use of JWT in ShenyuAdminBootstrap allows an attacker to bypass a
4MOSAn GCB Doctor’s login page has improper validation of Cookie, which allows an unauthenticated remote attacker to byp
Nodebb is an open source Node.js based forum software. In affected versions incorrect logic present in the token verific
The authentication algorithm of the WebHMI portal is sound, but the implemented mechanism can be bypassed as the result
Maharashtra State Electricity Board Mahavitara Android Application 8.20 and prior is vulnerable to remote account takeov
OpUtils in Zoho ManageEngine OpManager 12.5 before 125490 mishandles authentication for a few audit directories.
A vulnerability has been identified in SiPass integrated V2.76 (All versions), SiPass integrated V2.80 (All versions), S
The RegistrationMagic WordPress plugin made it possible for unauthenticated users to log in as any site user, including
Zoho ManageEngine ServiceDesk Plus MSP before 10.5 Build 10534 is vulnerable to unauthenticated remote code execution du
Zoho ManageEngine Access Manager Plus before 4203 allows anyone to view a few data elements (e.g., access control detail
Zoho ManageEngine PAM360 before build 5303 allows attackers to modify a few aspects of application state because of a fi
An authentication bypass vulnerability exists in the CMD_DEVICE_GET_RSA_KEY_REQUEST functionality of the home_security b
basic/BasicAuthProvider.java in AuthGuard before 0.9.0 allows authentication via an inactive identifier.
Dell EMC iDRAC9 versions 4.40.00.00 and later, but prior to 4.40.10.00, contain an improper authentication vulnerability
A vulnerability found in UniFi Protect application V1.18.1 and earlier permits a malicious actor who has already gained
In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditio
Properly formatted POST requests to multiple resources on the HTTP and HTTPS web servers of the Digi PortServer TS 16 Ra
Zoho ManageEngine Desktop Central before build 10.0.647 allows a single authentication secret from multiple agents to co
VMware Carbon Black Cloud Workload appliance 1.0.0 and 1.01 has an authentication bypass vulnerability that may allow a
Ampache is a web based audio/video streaming application and file manager. Versions prior to 4.4.1 allow unauthenticated
Improper authentication of Non-EAPOL/WAPI plaintext frames during four-way handshake can lead to arbitrary network packe
Improper authentication of un-encrypted plaintext Wi-Fi frames in an encrypted network can lead to information disclosur
eLabFTW is an electronic lab notebook manager for research teams. In versions prior to 4.2.0 there is a vulnerability wh
Open5GS 2.1.3 listens on 0.0.0.0:3000 and has a default password of 1423 for the admin account.
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6020
Attackers can access the CGE account management function without privilege for permission elevation and execute arbitrar
Frequently Asked Questions
What is CWE-287?
CWE-287 (Improper Authentication) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-287?
There are 5,272 CVE records associated with CWE-287 in our database. Of these, 1116 are critical severity, 1386 are high severity, and 1045 are medium severity.
How can I protect against CWE-287 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-287 using AI-powered security agents.
Detect CWE-287 Vulnerabilities
CyberStrike's AI agents automatically detect improper authentication vulnerabilities across your infrastructure.
Get Started