Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer). Supp
The MainWP Child WordPress plugin before 6.1.2 does not verify the requester's identity in its site-registration reques
The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) WordPress plugin before 7.8.0 does not bin
The miniOrange 2FA WordPress plugin before 6.2.6 does not validate the submitted one-time password against the targeted
The Chat On Desk Order Notifications WordPress plugin before 1.0.9 does not verify that the one-time password has been
The Login & Register Forms WordPress plugin before 3.2.5 does not properly enforce the rate limit on its password-reset
The Lenxel WP WordPress theme through 1.0.31 does not perform any authorization or ownership check on its password-reset
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.0 until 0.11.0, when ENAB
The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including,
Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, when OAuth login was
The MStore API WordPress plugin before 4.21.0 does not correctly verify the cryptographic signature of the token used t
The AutoNetTV Relay WordPress plugin before 3.0.14 does not perform any capability or authentication check before settin
The Login & Register Forms WordPress plugin before 4.0.2 does not bind the password reset verification state to the acc
The Login & Register Forms WordPress plugin before 4.0.2 does not enforce its password reset attempt limit against a se
The Social Login, Passkeys, Magic Link & Email OTP – Passwordless Login by VentraConnect plugin for WordPress is vulnera
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Ident
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to bypass security restrictions due to improper validation of
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to access server resources with the privileges of an authenti
Saleor is an e-commerce platform. From 2.10.0rc1 until 3.21.67, 3.22.63, and 3.23.22, the account activation flow treats
Froxlor is open source server administration software. Prior to 2.3.7, the API authentication path in lib/Froxlor/Api/Fr
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who has access to a trus
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to improper au
The ManageWP Worker WordPress plugin before 4.9.37 does not bind the account being logged in to the signature which auth
The Firebase Authentication WordPress plugin before 1.7.1 does not require the email address in an authentication token
Filament is a collection of full-stack components for accelerated Laravel development. Prior to versions 4.12.0 and 5.7.
Improper Authentication vulnerability in Apache Tomcat meant that in some circumstances (e.g. CLIENT-CERT, SPNEGO) that
@better-auth/sso before 1.6.27 (and before 1.4.8 in the 1.4.x line and before 1.7.0-rc.5 in the 1.7 prerelease line) con
The BlogVault Backup & Staging WordPress plugin before 6.65, MalCare WordPress Security Plugin WordPress plugin before
An insufficient authentication vulnerability in NETGEAR WiFi range extenders allows a network adjacent attacker with Wi
A path traversal vulnerability in NETGEAR WiFi range extenders allows an attacker with LAN authentication to access the
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, backend/open_webu
Improper authentication in Windows RPC API allows an unauthorized attacker to elevate privileges over an adjacent networ
xrdp is an open source RDP server. In versions 0.10.6 and prior, when an authenticated user session is initialized using
Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core).
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supp
pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.8.7, symlink attacks on pa
Improper authentication for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 2: Device Drivers may al
An authentication bypass vulnerability in NETGEAR Orbi devices allows users connected to the local network to access th
Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges locally.
Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges locally.
Improper authentication in Azure Arc allows an authorized attacker to elevate privileges locally.
OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16
A flaw was found in the foreman-mcp-server. A session management vulnerability in the MCP Server allows unauthenticated
Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges locally.
Improper authentication in Azure Bot Service allows an authorized attacker to elevate privileges over a network.
LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories
Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, and in 1.6.14 and later when
Dell OpenManage Server Administrator, versions prior to 11.1.0.2, contains an Improper Authentication vulnerability. An
Pocketbase is an open source web backend written in go. Prior to 0.22.42 and 0.37.4, in some situations, if an attacker
Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core).
Frequently Asked Questions
What is CWE-287?
CWE-287 (Improper Authentication) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-287?
There are 5,272 CVE records associated with CWE-287 in our database. Of these, 1116 are critical severity, 1386 are high severity, and 1045 are medium severity.
How can I protect against CWE-287 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-287 using AI-powered security agents.
Detect CWE-287 Vulnerabilities
CyberStrike's AI agents automatically detect improper authentication vulnerabilities across your infrastructure.
Get Started