Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-287

MITRE ↗

Improper Authentication

1,116
CRITICAL
1,386
HIGH
1,045
MEDIUM
94
LOW
3,718 CVEs · Page 5/75
8.8
CVE-2026-27939

Statmatic is a Laravel and Git powered content management system (CMS). Starting in version 6.0.0 and prior to version 6

8.8
CVE-2026-30223

OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.11.1, when JWT authentica

8.8
CVE-2026-30949

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-a

8.8
CVE-2026-30967

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-a

8.8
CVE-2026-33124

Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. Versions prior to 0.17.0-

8.8
CVE-2026-33898

Incus is a system container and virtual machine manager. Prior to version 6.23.0, the web server spawned by `incus webui

8.8
CVE-2026-34121

An authentication bypass vulnerability within the HTTP handling of the DS configuration service in TP-Link Tapo C520WS v

8.8
CVE-2026-33175

OAuthenticator is software that allows OAuth2 identity providers to be plugged in and used with JupyterHub. Prior to ver

8.8
CVE-2026-39322

PolarLearn is a free and open-source learning program. In 0-PRERELEASE-15 and earlier, POST /api/v1/auth/sign-in creates

8.8
CVE-2026-8621

Crabbox prior to v0.12.0 contains an authentication bypass vulnerability that allows non-admin shared-token callers to i

8.8
CVE-2026-6456

The Account Switcher plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.

8.8
CVE-2026-46827

Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Self Service Manager). Supported ver

8.8
CVE-2026-49443

authentik is an open-source identity provider. Prior to versions 2025.12.6, 2026.2.4, and 2026.5.1, an attacker with the

8.8
CVE-2026-49194

The debugging routine SCREEN_CLICK(5053) enables a connection to skip the standard device login prompt entirely and dire

8.8
CVE-2026-46903

Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Business Logic Infrastructu

8.8
CVE-2026-46916

Vulnerability in the Oracle Process Manufacturing Product Development product of Oracle E-Business Suite (component: Qua

8.8
CVE-2026-46921

Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supp

8.8
CVE-2026-46928

Vulnerability in the Oracle Spares Management product of Oracle E-Business Suite (component: Internal Operations). Supp

8.8
CVE-2026-46929

Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Cost Planning). Supported ve

8.8
CVE-2026-46937

Vulnerability in the Oracle iSetup product of Oracle E-Business Suite (component: General Ledger Update Transform, Repor

8.8
CVE-2026-46940

Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Cost Planning). Supported ve

8.8
CVE-2026-46942

Vulnerability in the Oracle Process Manufacturing Process Planning product of Oracle E-Business Suite (component: Intern

8.8
CVE-2026-46951

Vulnerability in the Oracle Quality product of Oracle E-Business Suite (component: Internal Operations). Supported vers

8.8
CVE-2026-46952

Vulnerability in the Oracle Quality product of Oracle E-Business Suite (component: Internal Operations). Supported vers

8.8
CVE-2026-46961

Vulnerability in the Oracle Project Portfolio Analysis product of Oracle E-Business Suite (component: Internal Operation

8.8
CVE-2026-46962

Vulnerability in the Oracle Project Portfolio Analysis product of Oracle E-Business Suite (component: Internal Operation

8.8
CVE-2026-46972

Vulnerability in the Oracle Outsourced Mfg for Discrete Industries product of Oracle E-Business Suite (component: Intern

8.8
CVE-2026-46973

Vulnerability in the Oracle Outsourced Mfg for Discrete Industries product of Oracle E-Business Suite (component: Intern

8.8
CVE-2026-58253

NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.0, 2.12.

8.8
CVE-2026-12341

This vulnerability impacts all versions of IdentityIQ and allows an unauthenticated attacker unauthorized access to prot

8.8
CVE-2026-47037

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). The

8.8
CVE-2026-60423

Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported vers

8.8
CVE-2026-60464

Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Middleware (component: Core). Supported versio

8.8
CVE-2026-60583

Vulnerability in the Oracle Transportation Management product of Oracle Supply Chain (component: Install). The support

8.8
CVE-2026-60654

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management).

8.8
CVE-2026-60678

Vulnerability in the Oracle General Ledger product of Oracle E-Business Suite (component: Internal Operations). Support

8.8
CVE-2026-60863

Vulnerability in the Oracle Advanced Pricing product of Oracle E-Business Suite (component: Pricing Installation). Supp

8.8
CVE-2026-60872

Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Tools).

8.8
CVE-2026-60890

Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported vers

8.8
CVE-2026-60897

Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported vers

8.8
CVE-2026-60898

Vulnerability in the Oracle Warehouse Management product of Oracle E-Business Suite (component: Internal Operations). S

8.8
CVE-2026-60901

Vulnerability in the Oracle Project Intelligence product of Oracle E-Business Suite (component: Internal Operations). S

8.8
CVE-2026-60920

Vulnerability in the Oracle Customer Care product of Oracle E-Business Suite (component: Internal Operations). Supporte

8.8
CVE-2026-60924

Vulnerability in the Oracle Public Sector Payroll product of Oracle E-Business Suite (component: Internal Operations).

8.8
CVE-2026-60932

Vulnerability in the Oracle Labor Distribution product of Oracle E-Business Suite (component: Internal Operations). Sup

8.8
CVE-2026-60952

Vulnerability in the Oracle Transportation Execution product of Oracle E-Business Suite (component: Internal Operations)

8.8
CVE-2026-60989

Vulnerability in the Oracle Advanced Collections product of Oracle E-Business Suite (component: Internal Operations). S

8.8
CVE-2026-61010

Vulnerability in the Oracle Process Manufacturing Systems product of Oracle E-Business Suite (component: Internal Operat

8.8
CVE-2026-61098

Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle).

8.8
CVE-2026-61099

Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle).

Frequently Asked Questions

What is CWE-287?

CWE-287 (Improper Authentication) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-287?

There are 5,272 CVE records associated with CWE-287 in our database. Of these, 1116 are critical severity, 1386 are high severity, and 1045 are medium severity.

How can I protect against CWE-287 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-287 using AI-powered security agents.

Detect CWE-287 Vulnerabilities

CyberStrike's AI agents automatically detect improper authentication vulnerabilities across your infrastructure.

Get Started