Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-287

MITRE ↗

Improper Authentication

1,116
CRITICAL
1,386
HIGH
1,045
MEDIUM
94
LOW
3,718 CVEs · Page 6/75
8.8
CVE-2026-61110

Vulnerability in the Oracle Applications DBA product of Oracle E-Business Suite (component: ADPatch). Supported version

8.8
CVE-2026-61121

Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll). Supported versions th

8.8
CVE-2026-61127

Vulnerability in the Oracle Communications Service Catalog and Design product of Oracle Communications (component: Solut

8.8
CVE-2026-61149

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (comp

8.8
CVE-2026-61168

Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security). The supported version that

8.8
CVE-2026-61179

Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Pr

8.8
CVE-2026-61180

Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Pr

8.8
CVE-2026-61243

Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product of Oracle PeopleSoft (component: Staffin

8.8
CVE-2026-61311

Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Internal Operations). Supported

8.8
CVE-2026-61320

Vulnerability in the Oracle Payables product of Oracle E-Business Suite (component: Internal Operations). Supported ver

8.8
CVE-2026-61322

Vulnerability in the TeleSales product of Oracle E-Business Suite (component: Internal Operations). Supported versions

8.8
CVE-2026-62447

Vulnerability in the Oracle Trade Management product of Oracle E-Business Suite (component: Claim LOV). Supported versi

8.8
CVE-2026-62464

Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported vers

8.8
CVE-2026-62476

Vulnerability in the Oracle Public Sector Payroll product of Oracle E-Business Suite (component: Internal Operations).

8.8
CVE-2026-62478

Vulnerability in the Oracle Public Sector Financials product of Oracle E-Business Suite (component: Internal Operations)

8.8
CVE-2026-62496

Vulnerability in the Oracle Yard Management product of Oracle E-Business Suite (component: Internal Operations). Suppor

8.8
CVE-2026-62498

Vulnerability in the Oracle Flow Manufacturing product of Oracle E-Business Suite (component: Internal Operations). Sup

8.8
CVE-2026-62534

Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Web Utilities). Suppo

8.8
CVE-2026-66014

JFrog Artifactory contains an authentication handling weakness in internal request processing that, under specific condi

8.8
CVE-2026-14596

The DynamicKit for Elementor WordPress plugin before 1.0.3 does not validate the host of a user-supplied URL used as the

8.8
CVE-2026-18786

The CheckView WordPress plugin before 2.3.2 does not restrict its REST API authentication filter to its own routes and

8.8
CVE-2026-72533

An authentication bypass vulnerability in Portainer CE through 2.44.0 allows authenticated low-privileged users to bypas

8.8
CVE-2026-62827

Improper authentication in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a networ

8.8
CVE-2026-70922

Vulnerability in the Oracle Financial Services Enterprise Case Management product of Oracle Financial Services Applicati

8.8
CVE-2026-50191

4gaBoards is a boards system for realtime project management. Prior to 3.3.8, 4gaBoards is vulnerable to pre-account tak

8.8
CVE-2026-19842

The SAML Single Sign On WordPress plugin before 5.4.7 does not verify the signature of a SAML response before storing t

8.8
CVE-2026-24170

NVIDIA UFM Enterprise contains a vulnerability in the web interface authorization component, where an authenticated user

8.8
CVE-2026-78236

An insecure PIN derivation mechanism in ABR allows a low-privileged user to escalate privileges to administrator by comm

8.7
CVE-2026-40165

authentik is an open-source identity provider. Versions 2025.12.4 and prior, and versions 2026.2.0-rc1 through 2026.2.2

8.7
CVE-2026-56223

Capgo before 12.128.2 contains a cross-domain SSO account takeover vulnerability in the provision-user endpoint that all

8.7
CVE-2026-82466

Rodauth before 2.46.0 contains an authentication bypass vulnerability in the webauthn_login route that allows logged-in

8.6
CVE-2025-66698

An issue in Semantic machines v5.4.8 allows attackers to bypass authentication via sending a crafted HTTP request to var

8.6
CVE-2026-25748

authentik is an open-source identity provider. Prior to 2025.10.4 and 2025.12.4, with a malformed cookie it was possible

8.6
CVE-2026-32173

Improper authentication in Azure SRE Agent allows an unauthorized attacker to disclose information over a network.

8.6
CVE-2026-49202

Internal multimedia session archives are accessible without authentication, exacerbated by loose Cross-Origin Resource S

8.6
CVE-2026-61436

PraisonAI before 4.6.78 fails to verify Svix webhook signatures in AgentMail webhook mode, allowing unauthenticated atta

8.6
CVE-2026-53591

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.223, an unauthen

8.6
CVE-2026-60327

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supp

8.5
CVE-2026-32246

Tinyauth is an authentication and authorization server. Prior to 5.0.3, the OIDC authorization endpoint allows users wit

8.4
CVE-2026-44810

Improper authentication in Windows Cryptographic Services allows an unauthorized attacker to elevate privileges locally.

8.4
CVE-2026-54320

Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows. Prior to 0.1

8.3
CVE-2026-34072

Cr*nMaster (cronmaster) is a Cronjob management UI with human readable syntax, live logging and log history for cronjobs

8.3
CVE-2026-49203

Crucial management API endpoints for cellular eSIM allocation do not validate caller authorization, allowing remote prof

8.3
CVE-2026-45567

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, th

8.3
CVE-2026-56675

9Router is an AI router & token saver. Prior to 0.5.2, 9router treats loopback requests as trusted and allows /v1/* acce

8.3
CVE-2026-53516

Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, Better Auth's OAuth callback

8.3
CVE-2026-67327

better-auth versions >= 1.1.3 and < 1.6.22 (and pre-release versions >= 1.7.0-beta.0 and < 1.7.0-beta.10) are vulnerable

8.3
CVE-2026-17101

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code or obtain sensitive information due

8.2
CVE-2025-71057

Improper session management in D-Link Wireless N 300 ADSL2+ Modem Router DSL-124 ME_1.00 allows attackers to execute a s

8.2
CVE-2026-28787

OneUptime is a solution for monitoring and managing online services. In version 10.0.11 and prior, the WebAuthn authenti

Frequently Asked Questions

What is CWE-287?

CWE-287 (Improper Authentication) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-287?

There are 5,272 CVE records associated with CWE-287 in our database. Of these, 1116 are critical severity, 1386 are high severity, and 1045 are medium severity.

How can I protect against CWE-287 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-287 using AI-powered security agents.

Detect CWE-287 Vulnerabilities

CyberStrike's AI agents automatically detect improper authentication vulnerabilities across your infrastructure.

Get Started