Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-287

MITRE ↗

Improper Authentication

1,116
CRITICAL
1,386
HIGH
1,045
MEDIUM
94
LOW
3,718 CVEs · Page 8/75
8.1
CVE-2026-62547

Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer). Supp

8.1
CVE-2026-12255

The MainWP Child WordPress plugin before 6.1.2 does not verify the requester's identity in its site-registration reques

8.1
CVE-2026-14300

The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) WordPress plugin before 7.8.0 does not bin

8.1
CVE-2026-12695

The miniOrange 2FA WordPress plugin before 6.2.6 does not validate the submitted one-time password against the targeted

8.1
CVE-2026-14309

The Chat On Desk Order Notifications WordPress plugin before 1.0.9 does not verify that the one-time password has been

8.1
CVE-2026-14836

The Login & Register Forms WordPress plugin before 3.2.5 does not properly enforce the rate limit on its password-reset

8.1
CVE-2026-12586

The Lenxel WP WordPress theme through 1.0.31 does not perform any authorization or ownership check on its password-reset

8.1
CVE-2026-70482

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.0 until 0.11.0, when ENAB

8.1
CVE-2026-15459

The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including,

8.1
CVE-2026-64665

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, when OAuth login was

8.1
CVE-2026-16030

The MStore API WordPress plugin before 4.21.0 does not correctly verify the cryptographic signature of the token used t

8.1
CVE-2026-13600

The AutoNetTV Relay WordPress plugin before 3.0.14 does not perform any capability or authentication check before settin

8.1
CVE-2026-18468

The Login & Register Forms WordPress plugin before 4.0.2 does not bind the password reset verification state to the acc

8.1
CVE-2026-18469

The Login & Register Forms WordPress plugin before 4.0.2 does not enforce its password reset attempt limit against a se

8.1
CVE-2026-18961

The Social Login, Passkeys, Magic Link & Email OTP – Passwordless Login by VentraConnect plugin for WordPress is vulnera

8.1
CVE-2026-12359

IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Ident

8.1
CVE-2026-17197

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to bypass security restrictions due to improper validation of

8.1
CVE-2026-16867

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to access server resources with the privileges of an authenti

8.1
CVE-2026-44472

Saleor is an e-commerce platform. From 2.10.0rc1 until 3.21.67, 3.22.63, and 3.23.22, the account activation flow treats

8.1
CVE-2026-52793

Froxlor is open source server administration software. Prior to 2.3.7, the API authentication path in lib/Froxlor/Api/Fr

8.1
CVE-2026-76338

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who has access to a trus

8.1
CVE-2026-17000

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to improper au

8.1
CVE-2026-18052

The ManageWP Worker WordPress plugin before 4.9.37 does not bind the account being logged in to the signature which auth

8.1
CVE-2026-76793

The Firebase Authentication WordPress plugin before 1.7.1 does not require the email address in an authentication token

8.1
CVE-2026-77567

Filament is a collection of full-stack components for accelerated Laravel development. Prior to versions 4.12.0 and 5.7.

8.1
CVE-2026-68569

Improper Authentication vulnerability in Apache Tomcat meant that in some circumstances (e.g. CLIENT-CERT, SPNEGO) that

8.1
CVE-2026-80192

@better-auth/sso before 1.6.27 (and before 1.4.8 in the 1.4.x line and before 1.7.0-rc.5 in the 1.7 prerelease line) con

8.1
CVE-2026-19718

The BlogVault Backup & Staging WordPress plugin before 6.65, MalCare WordPress Security Plugin WordPress plugin before

8.0
CVE-2026-0407

An insufficient authentication vulnerability in NETGEAR WiFi range extenders allows a network adjacent attacker with Wi

8.0
CVE-2026-0408

A path traversal vulnerability in NETGEAR WiFi range extenders allows an attacker with LAN authentication to access the

8.0
CVE-2026-59224

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, backend/open_webu

8.0
CVE-2026-50365

Improper authentication in Windows RPC API allows an unauthorized attacker to elevate privileges over an adjacent networ

8.0
CVE-2026-55626

xrdp is an open source RDP server. In versions 0.10.6 and prior, when an authenticated user session is initialized using

8.0
CVE-2026-60579

Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core).

8.0
CVE-2026-61067

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supp

7.9
CVE-2026-44711

pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.8.7, symlink attacks on pa

7.9
CVE-2026-20891

Improper authentication for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 2: Device Drivers may al

7.8
CVE-2026-0405

An authentication bypass vulnerability in NETGEAR Orbi devices allows users connected to the local network to access th

7.8
CVE-2026-24294

Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-26128

Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-26141

Improper authentication in Azure Arc allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-34990

OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16

7.8
CVE-2026-12112

A flaw was found in the foreman-mcp-server. A session management vulnerability in the MCP Server allows unauthenticated

7.8
CVE-2026-57107

Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges locally.

7.7
CVE-2026-32174

Improper authentication in Azure Bot Service allows an authorized attacker to elevate privileges over a network.

7.7
CVE-2026-58423

LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories

7.7
CVE-2026-53514

Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, and in 1.6.14 and later when

7.7
CVE-2026-56793

Dell OpenManage Server Administrator, versions prior to 11.1.0.2, contains an Improper Authentication vulnerability. An

7.6
CVE-2026-44166

Pocketbase is an open source web backend written in go. Prior to 0.22.42 and 0.37.4, in some situations, if an attacker

7.6
CVE-2026-60578

Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core).

Frequently Asked Questions

What is CWE-287?

CWE-287 (Improper Authentication) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-287?

There are 5,272 CVE records associated with CWE-287 in our database. Of these, 1116 are critical severity, 1386 are high severity, and 1045 are medium severity.

How can I protect against CWE-287 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-287 using AI-powered security agents.

Detect CWE-287 Vulnerabilities

CyberStrike's AI agents automatically detect improper authentication vulnerabilities across your infrastructure.

Get Started