Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-287

MITRE ↗

Improper Authentication

1,116
CRITICAL
1,386
HIGH
1,045
MEDIUM
94
LOW
3,718 CVEs · Page 9/75
7.6
CVE-2026-53958

4gaBoards is a boards system for realtime project management. Prior to 3.3.9, 4gaBoards allows an authenticated user to

7.6
CVE-2026-79938

Dell PowerProtect Cyber Recovery, versions prior to 20.3, contain an Improper Authentication vulnerability. A low privil

7.5
CVE-2025-67158

An authentication bypass in the /cgi-bin/jvsweb.cgi endpoint of Revotech I6032W-FHW v1.0.0014 - 20210517 allows attacker

7.5
CVE-2025-69273

Improper Authentication vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Authentication Bypass.This

7.5
CVE-2025-68931

Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, AES/CBC/PKCS5Padding

7.5
CVE-2026-1368

The Video Conferencing with Zoom WordPress plugin before 4.6.6 contains an AJAX handler that has its nonce verification

7.5
CVE-2026-32815

SiYuan is a personal knowledge management system. In versions 3.6.0 and below, the WebSocket endpoint (/ws) allows unaut

7.5
CVE-2026-33512

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the API plugin exposes a `decryptStr

7.5
CVE-2026-33665

n8n is an open source workflow automation platform. Prior to versions 2.4.0 and 1.121.0, when LDAP authentication is ena

7.5
CVE-2026-34834

Bulwark Webmail is a self-hosted webmail client for Stalwart Mail Server. Prior to version 1.4.10, the verifyIdentity()

7.5
CVE-2026-40177

ajenti.plugin.core defines all necessary core elements to allow Ajenti to run properly. Prior to 0.112, if the 2FA was a

7.5
CVE-2026-23708

A improper authentication vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5.0 through 7.5

7.5
CVE-2026-42855

arduino-esp32 is an Arduino core for the ESP32, ESP32-S2, ESP32-S3, ESP32-C3, ESP32-C6 and ESP32-H2 microcontrollers. Pr

7.5
CVE-2026-44478

hoppscotch is an open source API development ecosystem. The fix for CVE-2026-28215 in version 2026.2.0 addresses the una

7.5
CVE-2026-48896

Insufficient state checks lead to a vector that allows to bypass 2FA checks.

7.5
CVE-2026-48897

Insufficient state checks lead to a vector that allows to bypass 2FA checks.

7.5
CVE-2026-44847

MaxKB is an open-source AI assistant for enterprise. Prior to 2.9.0, MaxKB's webhook trigger endpoint (/api/trigger/v1/w

7.5
CVE-2026-40964

Authentication Bypass in cf-auth-proxy in Cloud Foundry Foundation all installations allows an unauthenticated remote at

7.5
CVE-2026-8293

The Really Simple Security WordPress plugin before 9.5.10.1 does not enforce the second-factor challenge in two of its

7.5
CVE-2026-48929

Rocket.Chat in versions <8.5.1, <8.4.4, <8.3.6, <8.2.6, <8.1.6, <8.0.7, <7.13.9, and <7.10.13 is vulnerable to unauthent

7.5
CVE-2026-50559

Quarkus is a Java framework for building cloud-native applications. Prior to versions 3.37.0, 3.36.3, 3.33.2.1, 3.33.3,

7.5
CVE-2026-11703

Missing SNI/ALPN binding on stateful (session-ID) resumption, which previously skipped the binding check performed for t

7.5
CVE-2026-41896

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.

7.5
CVE-2026-56219

Capgo before 12.128.2 contains a NULL-auth bypass vulnerability in the public.get_org_user_access_rbac function that all

7.5
CVE-2026-55727

A flaw in the authentication mechanism for video stream requests in Genetec Security Center 5.14.0.0 prior to build 5.14

7.5
CVE-2026-59954

Apollo is a reliable configuration management system suitable for microservice configuration management scenarios. Prior

7.5
CVE-2026-59955

Apollo is a reliable configuration management system suitable for microservice configuration management scenarios. Prior

7.5
CVE-2026-48812

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.221, FreeScout's

7.5
CVE-2026-60598

Vulnerability in the PeopleSoft Enterprise CS Student Records product of Oracle PeopleSoft (component: Research Tracking

7.5
CVE-2026-60927

Vulnerability in the Oracle Public Sector Financials product of Oracle E-Business Suite (component: Internal Operations)

7.5
CVE-2026-60931

Vulnerability in the Oracle Public Sector Financials product of Oracle E-Business Suite (component: Internal Operations)

7.5
CVE-2026-61188

Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: In

7.5
CVE-2026-62493

Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: Internal Operations). Supported v

7.5
CVE-2026-14291

The security-ninja-premium WordPress plugin before 5.290 does not verify the second authentication factor in one of its

7.5
CVE-2026-10697

Improper Authentication vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transfer: before 2025.1.5,

7.5
CVE-2026-12493

The Clover Payment Gateway by Zaytech for WooCommerce WordPress plugin before 1.3.6 does not verify that an approved ext

7.5
CVE-2026-54635

pytonapi is a Python SDK for TONAPI that provides REST API, streaming, and webhook access to the TON blockchain. From 2.

7.5
CVE-2026-15240

The Customer Switching WordPress plugin before 2.1.3 does not securely bind an active user-switching session to the oper

7.5
CVE-2026-14541

An authentication bypass and audience confusion vulnerability exists in the Google OAuth provider component of Google mc

7.5
CVE-2026-14830

The FlxWoo WordPress plugin before 3.1.1 does not verify with the payment processor that a checkout session was actually

7.5
CVE-2026-15206

The SMS Alert WordPress plugin before 3.9.8 does not bind its "mobile verified" session flag to the phone number that w

7.5
CVE-2026-16261

The login-social WordPress plugin through 1.0.4 does not validate password-reset requests against a reset key or the req

7.5
CVE-2026-15372

The WP 2FA WordPress plugin before 4.1.0 does not validate the second authentication factor when one of its supported m

7.5
CVE-2026-16036

The miniOrange 2FA WordPress plugin before 6.2.7 does not bind the second factor being configured during the pre-login

7.5
CVE-2026-16055

The Contest Gallery WordPress plugin before 30.0.7 does not route its front-end login through the standard WordPress au

7.5
CVE-2026-71467

A flaw was found in search-v2-api. The authentication middleware in the affected component unconditionally skips authent

7.5
CVE-2026-42018

JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is di

7.5
CVE-2026-17175

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due t

7.5
CVE-2026-73054

SiYuan versions before v3.7.4 contain an authentication bypass vulnerability in the WebSocket endpoint caused by differe

7.5
CVE-2026-60679

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t

Frequently Asked Questions

What is CWE-287?

CWE-287 (Improper Authentication) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-287?

There are 5,272 CVE records associated with CWE-287 in our database. Of these, 1116 are critical severity, 1386 are high severity, and 1045 are medium severity.

How can I protect against CWE-287 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-287 using AI-powered security agents.

Detect CWE-287 Vulnerabilities

CyberStrike's AI agents automatically detect improper authentication vulnerabilities across your infrastructure.

Get Started