CWE-287— Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.— MITRE CWE catalog
4,942 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-287page 90 of 99
- CVE-2026-13690HIGHCVSS 7.4EG 7.42026-07-29
The UsersWP WordPress plugin before 1.2.67 does not validate the selected authentication provider in its two-factor login handler, allowing an attacker who already knows a user's credentials to bypass the second authentication factor and …
- CVE-2026-1410MEDIUMCVSS 6.4EG 6.42026-01-26
A vulnerability was detected in Beetel 777VR1 up to 01.00.09/01.00.09_55. Impacted is an unknown function of the component UART Interface. The manipulation results in missing authentication. An attack on the physical device is feasible. Th…
- CVE-2026-14291HIGHCVSS 7.5EG 7.52026-07-23
The security-ninja-premium WordPress plugin before 5.290 does not verify the second authentication factor in one of its two-factor authentication code paths, allowing an unauthenticated attacker who knows a user's password to complete auth…
- CVE-2026-14300HIGHCVSS 8.1EG 8.12026-07-29
The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) WordPress plugin before 7.8.0 does not bind the one-time code used by its optional email-verification (Profile Completion) feature to the account it was issued f…
- CVE-2026-14305MEDIUMCVSS 5.3EG 5.32026-07-30
The WP Delicious WordPress plugin before 1.10.2 does not perform an authorization check on one of its AJAX actions, allowing unauthenticated users to modify limited post metadata (a like counter and an associated identifier list) on arbit…
- CVE-2026-14541HIGHCVSS 8.0EG 8.02026-07-31
An authentication bypass and audience confusion vulnerability exists in the Google OAuth provider component of Google mcp-toolbox version 1.4.0. When a Google authService is initialized with mcpEnabled: true but lacks an explicitly defined…
- CVE-2026-14568MEDIUMCVSS 6.5EG 6.52026-07-27
The User Frontend: AI Powered Frontend Post Submission, User Directory, User Profile, Membership & User Registration WordPress plugin before 4.3.8 does not correctly verify ownership before deleting an attachment, allowing unauthenticated …
- CVE-2026-14622HIGHCVSS 7.3EG 7.32026-07-04
A vulnerability was found in jairiidriss restaurant-website-php-mysql up to 521428b5b612449df0cf4a5d15ee40cba67f3d35. This vulnerability affects unknown code of the file /admin/ajax_files of the component AJAX Endpoint. Performing a manipu…
- CVE-2026-14627MEDIUMCVSS 5.6EG 5.62026-07-04
A security vulnerability has been detected in NousResearch hermes-agent up to 0.15.2. This affects the function DiscordAdapter._is_allowed_user of the file gateway/platforms/discord.py of the component Discord Platform Integration. Such ma…
- CVE-2026-14714MEDIUMCVSS 6.5EG 6.52026-07-05
A weakness has been identified in zhayujie chatgpt-on-wechat CowAgent 2.1.0. This issue affects the function verify_server of the file channel/wechatmp/common.py of the component wx Endpoint. This manipulation of the argument wechatmp_toke…
- CVE-2026-15087MEDIUMCVSS 5.9EG 5.92026-07-10
vulnerability in Drupal Clean RESTful allows . This issue affects Clean RESTful versions: *.*.
- CVE-2026-15089CRITICALCVSS 9.1EG 9.12026-07-10
vulnerability in Drupal Commerce guest registration allows . This issue affects Commerce guest registration versions: *.*.
- CVE-2026-15192MEDIUMCVSS 6.5EG 6.52026-07-09
A vulnerability has been found in mettle sendportal up to 3.0.1. This issue affects the function sendgrid/postmark/postal/mailjet of the component APIv1 Webhooks. The manipulation leads to missing authentication. The attack is possible to …
- CVE-2026-1524CRITICALCVSS 9.8EG 9.82026-03-11
An edgecase in SSO implementation in Neo4j Enterprise edition versions prior to version 2026.02 can lead to unauthorised access under the following conditions: If a neo4j admin configures two or more OIDC providers AND configures one or …
- CVE-2026-15240HIGHCVSS 7.5EG 7.52026-07-30
The Customer Switching WordPress plugin before 2.1.3 does not securely bind an active user-switching session to the operator who initiated it, allowing a lower-privileged account that an operator is currently switched into to be resolved a…
- CVE-2026-15348MEDIUMCVSS 6.3EG 6.32026-07-23
The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 7.0.4 via the `wpdmppdl` parameter. This is due to the `download()` function — hook…
- CVE-2026-15491HIGHCVSS 7.3EG 7.32026-07-12
A weakness has been identified in RafyMrX TOKO-ONLINE-ROTI up to ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99. This affects an unknown part. This manipulation causes missing authentication. The attack is possible to be carried out remotely. Th…
- CVE-2026-15542HIGHCVSS 7.3EG 7.32026-07-13
A vulnerability has been found in will-moss Isaiah up to 1.36.9. This affects an unknown function of the file app/main.go of the component Websocket Connection Authentication. The manipulation leads to improper authentication. The attack c…
- CVE-2026-15557HIGHCVSS 7.3EG 7.32026-07-13
A weakness has been identified in waooAI waoowaoo up to 0.4.1. Affected by this vulnerability is the function getInternalTaskSession/getAuthSession/requireUserAuth/requireProjectAuth/requireProjectAuthLight in the library src/lib/api-auth.…
- CVE-2026-15611CRITICALCVSS 9.1EG 9.12026-07-23
Logto allows unverified email-based SSO account linking, enabling an attacker to register an identity at a permissive IdP using a victim’s email and gain unauthorized access to the victim’s account.
- CVE-2026-1568CRITICALCVSS 9.6EG 9.62026-02-03
Rapid7 InsightVM versions before 8.34.0 contain a signature verification issue on the Assertion Consumer Service (ACS) cloud endpoint that could allow an attacker to gain unauthorized access to InsightVM accounts setup via "Security Cons…
- CVE-2026-15981CRITICALCVSS 9.8EG 9.82026-07-23
The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.4.4. This is due to the mo_saml_validate_signature() function performing a loose boolean check on the…
- CVE-2026-16015MEDIUMCVSS 6.3EG 6.32026-07-17
A vulnerability was determined in poco-ai poco-claw up to 0.5.4. This vulnerability affects the function create_task of the file executor_manager/app/api/v1/tasks.py of the component executor_manager API. Executing a manipulation can lead …
- CVE-2026-16076MEDIUMCVSS 6.3EG 6.32026-07-18
A vulnerability has been found in AstrBotDevs AstrBot up to 4.25.5. This issue affects the function OpenApiRoute.chat_send of the file astrbot/dashboard/routes/open_api.py of the component API. Such manipulation of the argument Username le…
- CVE-2026-16083MEDIUMCVSS 5.3EG 5.32026-07-18
A security flaw has been discovered in Sipeed PicoClaw up to 0.2.9. This affects the function webhook.ParseRequest of the file pkg/channels/line/line.go of the component LINE Webhook. The manipulation results in authentication bypass by ca…
- CVE-2026-16198MEDIUMCVSS 5.6EG 5.62026-07-18
A vulnerability was detected in Sipeed PicoClaw up to 0.2.9. The impacted element is an unknown function of the file web/backend/middleware/access_control.go of the component First Run Setup. Performing a manipulation of the argument allow…
- CVE-2026-16209HIGHCVSS 7.3EG 7.32026-07-19
A vulnerability has been found in Gerapy up to 0.9.13. The impacted element is an unknown function of the file gerapy/server/core/views.py of the component Project Upload Endpoint. Such manipulation leads to missing authentication. The att…
- CVE-2026-16210HIGHCVSS 7.3EG 7.32026-07-19
A vulnerability was found in newpanjing simpleui 2026.01.13. This affects the function self.get_action of the file simpleui/admin.py of the component AjaxAdmin AJAX Endpoint. Performing a manipulation results in missing authentication. Rem…
- CVE-2026-16232CRITICALCVSS 9.1EG 9.1⚠ KEV2026-07-22
An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful …
- CVE-2026-1740HIGHCVSS 9.8EG 7.32026-02-02
A vulnerability was found in EFM ipTIME A8004T 14.18.2. This impacts the function httpcon_check_session_url of the file /cgi/timepro.cgi of the component Hidden Hiddenloginsetup Interface. The manipulation results in improper authenticatio…
- CVE-2026-1743LOWCVSS 3.1EG 3.12026-02-02
A vulnerability has been found in DJI Mavic Mini, Air, Spark and Mini SE up to 01.00.0500. Affected by this vulnerability is an unknown functionality of the component Enhanced Wi-Fi Pairing. The manipulation leads to authentication bypass …
- CVE-2026-18215MEDIUMCVSS 6.8EG 6.82026-07-31
Keycloak provides a way to let users log in using Microsoft accounts while restricting access to a specific organization (tenant). A flaw was discovered where this restriction is ignored when using the token exchange feature. This means an…
- CVE-2026-20127CRITICALCVSS 10.0EG 10.0⚠ KEV2026-02-25
A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an u…
- CVE-2026-20129CRITICALCVSS 9.8EG 9.82026-02-25
A vulnerability in the API user authentication of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to gain access to an affected system as a user who has the netadmin role. The vulnerability is due to i…
- CVE-2026-20182CRITICALCVSS 10.0EG 10.0⚠ KEV2026-05-14
May 2026: This security advisory provides the details and fix information for a vulnerability that was discovered and fixed after the was disclosed in February 2026. This new advisory is for a new vulnerability in the control connection h…
- CVE-2026-2065MEDIUMCVSS 8.8EG 6.32026-02-06
A security flaw has been discovered in Flycatcher Toys smART Pixelator 2.0. Affected by this issue is some unknown functionality of the component Bluetooth Low Energy Interface. Performing a manipulation results in missing authentication. …
- CVE-2026-20655MEDIUMCVSS 5.5EG 5.52026-02-11
An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3. An attacker with physical access to a locked device may be able to view sensitive user info…
- CVE-2026-21004MEDIUMCVSS 6.5EG 6.52026-03-16
Improper authentication in Smart Switch prior to version 3.7.69.15 allows adjacent attackers to trigger a denial of service.
- CVE-2026-21508HIGHCVSS 7.0EG 7.02026-02-10
Improper authentication in Windows Storage allows an authorized attacker to elevate privileges locally.
- CVE-2026-21633HIGHCVSS 8.8EG 8.82026-01-05
A malicious actor with access to the adjacent network could obtain unauthorized access to a UniFi Protect Camera by exploiting a discovery protocol vulnerability in the Unifi Protect Application (Version 6.1.79 and earlier). Affect…
- CVE-2026-2165HIGHCVSS 9.8EG 7.32026-02-08
A weakness has been identified in detronetdip E-commerce 1.0.0. Impacted is an unknown function of the file /Admin/assets/backend/seller/add_seller.php of the component Account Creation Endpoint. Executing a manipulation of the argument em…
- CVE-2026-2174HIGHCVSS 9.8EG 7.32026-02-08
A security flaw has been discovered in code-projects Contact Management System 1.0. This affects an unknown part of the component CRUD Endpoint. The manipulation of the argument ID results in improper authentication. The attack may be laun…
- CVE-2026-21854CRITICALCVSS 9.8EG 9.82026-01-07
The Tarkov Data Manager is a tool to manage the Tarkov item data. Prior to 02 January 2025, an authentication bypass vulnerability in the login endpoint allows any unauthenticated user to gain full admin access to the Tarkov Data Manager a…
- CVE-2026-21881CRITICALCVSS 9.1EG 9.12026-01-08
Kanboard is project management software focused on Kanban methodology. Versions 1.2.48 and below is vulnerable to a critical authentication bypass when REVERSE_PROXY_AUTH is enabled. The application blindly trusts HTTP headers for user aut…
- CVE-2026-21891CRITICALCVSS 9.8EG 9.42026-01-08
ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In versions up to and including 1.5.0, the application checks the validity of the username but appears to skip, misinterpret, or incorrectly val…
- CVE-2026-22099HIGHCVSS 8.7EG 8.72026-07-13
The charging station does not require authentication for Bluetooth commands to perform actions. The functionality exposed includes sensitive information leakage, triggering reboots, or pushing a firmware update URL.
- CVE-2026-22236CRITICALCVSS 9.8EG 9.82026-01-14
The vulnerability exists in BLUVOYIX due to improper authentication in the BLUVOYIX backend APIs. An unauthenticated remote attacker could exploit this vulnerability by sending specially crafted HTTP requests to the vulnerable APIs. Succes…
- CVE-2026-2248CRITICALCVSS 9.8EG 9.82026-02-11
METIS WIC devices (versions <= oscore 2.1.234-r18) expose a web-based shell at the /console endpoint that does not require authentication. Accessing this endpoint allows a remote attacker to execute arbitrary operating system commands with…
- CVE-2026-2249CRITICALCVSS 9.8EG 9.82026-02-11
METIS DFS devices (versions <= oscore 2.1.234-r18) expose a web-based shell at the /console endpoint that does not require authentication. Accessing this endpoint allows a remote attacker to execute arbitrary operating system commands with…
- CVE-2026-22594HIGHCVSS 8.1EG 8.12026-01-10
Ghost is a Node.js content management system. In versions 5.105.0 through 5.130.5 and 6.0.0 through 6.10.3, a vulnerability in Ghost's 2FA mechanism allows staff users to skip email 2FA. This issue has been patched in versions 5.130.6 and …
Map vulnerabilities like CWE-287 to your infrastructure
EchelonGraph correlates every CVE — across CWE-287 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →