CWE-287— Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.— MITRE CWE catalog
4,942 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-287page 91 of 99
- CVE-2026-22752CRITICALCVSS 9.6EG 9.62026-07-16
Authentication bypass by primary weakness vulnerability in Spring Security Spring Authorization Server. This issue affects Spring Authorization Server: from 7.0.0 through 7.0.4, from 1.5.0 through 1.5.6, from 1.4.0 through 1.4.9, from 1.3…
- CVE-2026-22764MEDIUMCVSS 6.5EG 4.32026-01-29
Dell OpenManage Network Integration, versions prior to 3.9, contains an Improper Authentication vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.
- CVE-2026-23600CRITICALCVSS 10.0EG 10.02026-03-02
A remote authentication bypass vulnerability exists in HPE AutoPass License Server (APLS).
- CVE-2026-23708HIGHCVSS 7.5EG 7.52026-04-14
A improper authentication vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR on-premise 7.6.0 through 7.6.3, FortiSOAR on-premise 7.5.0 through 7.5.2 may allow an unauthenticated att…
- CVE-2026-23813CRITICALCVSS 9.8EG 9.82026-03-11
A vulnerability has been identified in the web-based management interface of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. In some cases this could enable reset…
- CVE-2026-23906CRITICALCVSS 9.8EG 9.82026-02-10
Affected Products and Versions * Apache Druid * Affected Versions: 0.17.0 through 35.x (all versions prior to 36.0.0) * Prerequisites: * druid-basic-security extension enabled * LDAP authenticator configured * Underlying L…
- CVE-2026-24003MEDIUMCVSS 5.3EG 4.32026-01-26
EVerest is an EV charging software stack. In versions up to and including 2025.12.1, it is possible to bypass the sequence state verification including authentication, and send requests that transition to forbidden states relative to the c…
- CVE-2026-24038HIGHCVSS 8.1EG 8.12026-01-22
Horilla is a free and open source Human Resource Management System (HRMS). In version 1.4.0, the OTP handling logic has a flawed equality check that can be bypassed. When an OTP expires, the server returns None, and if an attacker omits th…
- CVE-2026-24241HIGHCVSS 7.5EG 7.52026-02-24
NVIDIA Delegated Licensing Service for all appliance platforms contains a vulnerability where an attacker could exploit an improper authentication issue. A successful exploit of this vulnerability might lead to information disclosure.
- CVE-2026-24294HIGHCVSS 7.8EG 7.82026-03-10
Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges locally.
- CVE-2026-24898CRITICALCVSS 9.8EG 9.82026-03-03
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0, an unauthenticated token disclosure vulnerability in the MedEx callback endpoint allows any unauthenticated visitor to…
- CVE-2026-25748HIGHCVSS 7.5EG 8.62026-02-12
authentik is an open-source identity provider. Prior to 2025.10.4 and 2025.12.4, with a malformed cookie it was possible to bypass authentication when using forward authentication in the authentik Proxy Provider when used in conjunction wi…
- CVE-2026-25804CRITICALCVSS 9.1EG 9.12026-02-06
Antrea is a Kubernetes networking solution intended to be Kubernetes native. Prior to versions 2.3.2 and 2.4.3, Antrea's network policy priority assignment system has a uint16 arithmetic overflow bug that causes incorrect OpenFlow priority…
- CVE-2026-25893CRITICALCVSS 9.8EG 9.82026-02-09
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.2.10, an authentication bypass vulnerability in FUXA allows an unauthenticated, remote attacker to gain administrative access via the heartbeat refresh AP…
- CVE-2026-25922HIGHCVSS 8.8EG 8.82026-02-12
authentik is an open-source identity provider. Prior to 2025.8.6, 2025.10.4, and 2025.12.4, when using a SAML Source that has the option Verify Assertion Signature under Verification Certificate enabled and not Verify Response Signature, o…
- CVE-2026-25937MEDIUMCVSS 6.5EG 6.52026-03-18
GLPI is a free Asset and IT management software package. Starting in version 11.0.0 and prior to version 11.0.6, a malicious actor with knowledge of a user's credentials can bypass MFA and steal their account. Version 11.0.6 fixes the issu…
- CVE-2026-26077MEDIUMCVSS 6.5EG 6.52026-02-26
Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, several webhook endpoints (SendGrid, Mailjet, Mandrill, Postmark, SparkPost) in the `WebhooksController` accepted requests without a vali…
- CVE-2026-26119HIGHCVSS 8.8EG 8.82026-02-17
Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges over a network.
- CVE-2026-26128HIGHCVSS 7.8EG 7.82026-03-10
Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges locally.
- CVE-2026-26141HIGHCVSS 7.8EG 7.82026-03-10
Improper authentication in Azure Arc allows an authorized attacker to elevate privileges locally.
- CVE-2026-27134HIGHCVSS 8.1EG 8.12026-02-21
Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations. In versions 0.49.0 through 0.50.0, when using a custom Cluster or Clients CA with a multistage CA chain consisting of m…
- CVE-2026-27197CRITICALCVSS 9.1EG 9.12026-02-21
Sentry is a developer-first error tracking and performance monitoring tool. Versions 21.12.0 through 26.1.0 have a critical vulnerability in its SAML SSO implementation which allows an attacker to take over any user account by using a mal…
- CVE-2026-2756MEDIUMCVSS 5.0EG 5.02026-03-21
A security vulnerability has been detected in OmniPEMF NeoRhythm up to 20260308. This affects an unknown function of the component BLE Interface. Such manipulation leads to missing authentication. The attack can only be initiated within th…
- CVE-2026-27611MEDIUMCVSS 6.5EG 6.52026-02-25
FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to versions 1.1.3-stable and 1.2.6-beta, when users share password-protected files, the recipient can completely bypass the password and still download the file. Thi…
- CVE-2026-27856HIGHCVSS 5.9EG 7.42026-03-27
Doveadm credentials are verified using direct comparison which is susceptible to timing oracle attack. An attacker can use this to determine the configured credentials. Figuring out the credential will lead into full access to the affected…
- CVE-2026-27939HIGHCVSS 8.8EG 8.82026-02-27
Statmatic is a Laravel and Git powered content management system (CMS). Starting in version 6.0.0 and prior to version 6.4.0, Authenticated Control Panel users may under certain conditions obtain elevated privileges without completing the …
- CVE-2026-27960CRITICALCVSS 9.8EG 9.82026-05-05
OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. In versions 6.6.0 through 6.9.12, there is a privilege escalation vulnerability that can be exploited by unauthenticated attackers to quer…
- CVE-2026-27968MEDIUMCVSS 4.3EG 4.32026-02-26
Packistry is a self-hosted Composer repository designed to handle PHP package distribution. Prior to version 0.13.0, RepositoryAwareController::authorize() verified token presence and ability, but did not enforce token expiration. As a res…
- CVE-2026-2812MEDIUMCVSS 5.3EG 5.32026-05-20
ArcGIS Server contains an improper authentication vulnerability in an undocumented administrative endpoint. An unauthenticated attacker could exploit this issue by sending a crafted request to the endpoint. Successful exploitation may resu…
- CVE-2026-28215CRITICALCVSS 9.1EG 9.12026-02-26
hoppscotch is an open source API development ecosystem. Prior to version 2026.2.0, an unauthenticated attacker can overwrite the entire infrastructure configuration of a self-hosted Hoppscotch instance including OAuth provider credentials …
- CVE-2026-28323CRITICALCVSS 9.8EG 9.82026-07-30
SolarWinds Web Help Desk is found to be affected by a SAML authentication bypass vulnerability. This requires the SAML 2.0 authentication method to be enabled.
- CVE-2026-28408CRITICALCVSS 9.8EG 9.82026-02-27
WeGIA is a web manager for charitable institutions. Prior to version 3.6.5, the script in adicionar_tipo_docs_atendido.php does not go through the project's central controller and does not have its own authentication and permission checks.…
- CVE-2026-28428MEDIUMCVSS 5.3EG 5.32026-03-06
Talishar is a fan-made Flesh and Blood project. Prior to commit a9c218e, an authentication bypass vulnerability in Talishar's game endpoint validation logic allows any unauthenticated attacker to perform authenticated game actions — incl…
- CVE-2026-28471MEDIUMCVSS 5.3EG 5.32026-03-05
OpenClaw version 2026.1.14-1 prior to 2026.2.2, with the Matrix plugin installed and enabled, contain a vulnerability in which DM allowlist matching could be bypassed by exact-matching against sender display names and localparts without ho…
- CVE-2026-28514CRITICALCVSS 9.8EG 9.82026-03-06
Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to versions 7.8.6, 7.9.8, 7.10.7, 7.11.4, 7.12.4, 7.13.3, and 8.0.0, a critical authentication bypass vulnerability exists in Rocket.Chat's account se…
- CVE-2026-28787CRITICALCVSS 9.0EG 9.02026-03-06
OneUptime is a solution for monitoring and managing online services. In version 10.0.11 and prior, the WebAuthn authentication implementation does not store the challenge on the server side. Instead, the challenge is returned to the client…
- CVE-2026-28800HIGHCVSS 8.0EG 8.02026-03-06
Natro Macro is an open-source Bee Swarm Simulator macro written in AutoHotkey. Prior to version 1.1.0, anyone with Discord Remote Control set up in a non-private channel gives access to any user with the permission to send message in said …
- CVE-2026-29093CRITICALCVSS 9.8EG 9.82026-03-06
WWBN AVideo is an open source video platform. Prior to version 24.0, the official docker-compose.yml publishes the memcached service on host port 11211 (0.0.0.0:11211) with no authentication, while the Dockerfile configures PHP to store al…
- CVE-2026-29145CRITICALCVSS 9.1EG 9.12026-04-09
CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apache Tomcat, Apache Tomcat Native. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M7 thro…
- CVE-2026-29193HIGHCVSS 8.2EG 8.22026-03-07
ZITADEL is an open source identity management platform. From version 4.0.0 to 4.12.0, a vulnerability in Zitadel's login V2 UI allowed users to bypass login behavior and security policies and self-register new accounts or sign in using pas…
- CVE-2026-29792CRITICALCVSS 9.8EG 9.82026-03-10
Feathersjs is a framework for creating web APIs and real-time applications with TypeScript or JavaScript. From 5.0.0 to before 5.0.42, an unauthenticated attacker can send a crafted GET request directly to /oauth/:provider/callback with a …
- CVE-2026-2991CRITICALCVSS 7.3EG 9.82026-03-18
The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 4.1.2. This is due to the `patientSocialLogin()` function not verifying the social …
- CVE-2026-30223HIGHCVSS 8.8EG 8.82026-03-06
OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.11.1, when JWT authentication is configured using either "authJwtPubKeyPath" (local RSA public key) or "authJwtHmacSecret" (HMAC secret), the co…
- CVE-2026-3053HIGHCVSS 9.8EG 7.32026-02-24
A vulnerability was determined in DataLinkDC dinky up to 1.2.5. This affects the function addInterceptors of the file dinky-admin/src/main/java/org/dinky/configure/AppConfig.java of the component OpenAPI Endpoint. Executing a manipulation …
- CVE-2026-30831CRITICALCVSS 9.8EG 9.82026-03-06
Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to versions 7.10.8, 7.11.5, 7.12.5, 7.13.4, 8.0.2, 8.1.1, and 8.2.0, authentication vulnerabilities exist in Rocket.Chat's enterprise DDP Streamer ser…
- CVE-2026-30836CRITICALCVSS 10.0EG 10.02026-03-19
Step CA is an online certificate authority for secure, automated certificate management for DevOps. Versions 0.30.0-rc6 and below do not safeguard against unauthenticated certificate issuance through the SCEP UpdateReq. This issue has been…
- CVE-2026-30851HIGHCVSS 8.8EG 8.82026-03-07
Caddy is an extensible server platform that uses TLS by default. From version 2.10.0 to before version 2.11.2, forward_auth copy_headers does not strip client-supplied headers, allowing identity injection and privilege escalation. This iss…
- CVE-2026-30863CRITICALCVSS 9.8EG 9.82026-03-07
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.10 and 9.5.0-alpha.11, the Google, Apple, and Facebook authentication adapters use JWT verification to validate i…
- CVE-2026-30949HIGHCVSS 8.8EG 8.82026-03-10
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-alpha.5 and 8.6.18, the Keycloak authentication adapter does not validate the azp (authorized party) claim of Keycloak a…
- CVE-2026-30967HIGHCVSS 8.8EG 8.82026-03-10
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-alpha.9. and 8.6.22, the OAuth2 authentication adapter, when configured without the useridField option, only verifies th…
Map vulnerabilities like CWE-287 to your infrastructure
EchelonGraph correlates every CVE — across CWE-287 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →