CWE-287— Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.— MITRE CWE catalog
4,943 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-287page 92 of 99
- CVE-2026-30967HIGHCVSS 8.8EG 8.82026-03-10
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-alpha.9. and 8.6.22, the OAuth2 authentication adapter, when configured without the useridField option, only verifies th…
- CVE-2026-31387MEDIUMCVSS 5.3EG 5.32026-05-19
Improper Authentication vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue.
- CVE-2026-3192MEDIUMCVSS 8.1EG 5.62026-02-25
A security vulnerability has been detected in Chia Blockchain 2.1.0. This issue affects the function _authenticate of the file rpc_server_base.py of the component RPC Credential Handler. The manipulation leads to improper authentication. T…
- CVE-2026-3194MEDIUMCVSS 7.0EG 4.52026-02-25
A flaw has been found in Chia Blockchain 2.1.0. The affected element is the function send_transaction/get_private_key of the component RPC Server Master Passphrase Handler. This manipulation causes missing authentication. The attack can on…
- CVE-2026-31946CRITICALCVSS 9.8EG 9.82026-03-30
OpenOlat is an open source web-based e-learning platform for teaching, learning, assessment and communication. From version 10.5.4 to before version 20.2.5, OpenOLAT's OpenID Connect implicit flow implementation does not verify JWT signatu…
- CVE-2026-32072MEDIUMCVSS 6.2EG 6.22026-04-14
Improper authentication in Windows Active Directory allows an unauthorized attacker to perform spoofing locally.
- CVE-2026-32136CRITICALCVSS 9.8EG 9.82026-03-11
AdGuard Home is a network-wide software for blocking ads and tracking. Prior to 0.107.73, an unauthenticated remote attacker can bypass all authentication in AdGuardHome by sending an HTTP/1.1 request that requests an upgrade to HTTP/2 cle…
- CVE-2026-32173HIGHCVSS 7.5EG 8.62026-04-03
Improper authentication in Azure SRE Agent allows an unauthorized attacker to disclose information over a network.
- CVE-2026-32174HIGHCVSS 7.7EG 7.72026-06-18
Improper authentication in Azure Bot Service allows an authorized attacker to elevate privileges over a network.
- CVE-2026-3224CRITICALCVSS 9.8EG 9.82026-03-03
Authentication bypass in the Microsoft Entra ID (Azure AD) authentication mode in Devolutions Server 2025.3.15.0 and earlier allows an unauthenticated user to authenticate as an arbitrary Entra ID user via a forged JSON Web Token (JWT).
- CVE-2026-32246HIGHCVSS 7.1EG 7.12026-03-12
Tinyauth is an authentication and authorization server. Prior to 5.0.3, the OIDC authorization endpoint allows users with a TOTP-pending session (password verified, TOTP not yet completed) to obtain authorization codes. An attacker who kno…
- CVE-2026-32253CRITICALCVSS 9.8EG 9.82026-05-22
Sunshine is a self-hosted game stream host for Moonlight. In versions prior to 2026.516.143833, the client-certificate authentication can be bypassed because of how OpenSSL verification results are handled. In src/crypto.cpp, the custom ve…
- CVE-2026-32305MEDIUMCVSS 5.3EG 5.32026-03-20
Traefik is an HTTP reverse proxy and load balancer. Versions 2.11.40 and below, 3.0.0-beta1 through 3.6.11, and 3.7.0-ea.1 are vulnerable to mTLS bypass through the TLS SNI pre-sniffing logic related to fragmented ClientHello packets. When…
- CVE-2026-32730HIGHCVSS 8.1EG 8.12026-03-18
ApostropheCMS is an open-source content management framework. Prior to version 4.28.0, the bearer token authentication middleware in `@apostrophecms/express/index.js` (lines 386-389) contains an incorrect MongoDB query that allows incomple…
- CVE-2026-32804HIGHCVSS 8.1EG 8.12026-06-17
Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Authentication vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Unauthorized access.
- CVE-2026-32815HIGHCVSS 7.5EG 7.52026-03-19
SiYuan is a personal knowledge management system. In versions 3.6.0 and below, the WebSocket endpoint (/ws) allows unauthenticated connections when specific URL parameters are provided (?app=siyuan&id=auth&type=auth). This bypass, intended…
- CVE-2026-32879MEDIUMCVSS 4.9EG 4.92026-03-23
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Starting in version 0.10.0, a logic flaw in the universal secure verification flow allows an authenticated user with a registered pass…
- CVE-2026-33042MEDIUMCVSS 5.3EG 5.32026-03-18
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.29 and 8.6.49, a user can sign up without providing credentials by sending an empty `authData` object, bypassing t…
- CVE-2026-33117CRITICALCVSS 9.1EG 9.12026-05-12
The Java Key Vault Keys library in the Azure SDK for Java contains an issue in the local cryptographic verification path where authentication tag comparison was implemented incorrectly. In affected applications that use the vulnerable loca…
- CVE-2026-33124HIGHCVSS 8.8EG 8.82026-03-20
Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. Versions prior to 0.17.0-beta1 allow any authenticated user to change their own password without verifying the current password through the /use…
- CVE-2026-33175HIGHCVSS 8.8EG 8.82026-04-03
OAuthenticator is software that allows OAuth2 identity providers to be plugged in and used with JupyterHub. Prior to version 17.4.0, an authentication bypass vulnerability in oauthenticator allows an attacker with an unverified email addre…
- CVE-2026-33215MEDIUMCVSS 6.5EG 6.52026-03-24
NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. The nats-server provides an MQTT client interface. Prior to versions 2.11.15 and 2.12.5, Sessions and Messages can by hijacked via MQTT Client …
- CVE-2026-33246MEDIUMCVSS 5.4EG 5.42026-03-25
NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. The nats-server offers a `Nats-Request-Info:` message header, providing information about a request. This is supposed to provide enough informa…
- CVE-2026-33248MEDIUMCVSS 4.2EG 4.22026-03-25
NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, when using mTLS for client identity, with `verify_and_map` to derive a NATS identity from the client cert…
- CVE-2026-33314MEDIUMCVSS 6.5EG 6.52026-03-19
pyLoad is a free and open-source download manager written in Python. Prior to version 0.5.0b3.dev97, a Host Header Spoofing vulnerability in the @local_check decorator allows unauthenticated external attackers to bypass local-only restrict…
- CVE-2026-33322CRITICALCVSS 9.8EG 9.82026-03-24
MinIO is a high-performance object storage system. From RELEASE.2022-11-08T05-27-07Z to before RELEASE.2026-03-17T21-25-16Z, a JWT algorithm confusion vulnerability in MinIO's OpenID Connect authentication allows an attacker who knows the …
- CVE-2026-33377HIGHCVSS 7.1EG 7.12026-05-13
An Editor can overwrite a dashboard not owned by them to acquire admin on that specific dashboard. The user must have write access to the dashboard to escalate privilege.
- CVE-2026-33409CRITICALCVSS 9.1EG 9.12026-03-24
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.52 and 9.6.0-alpha.41, an authentication bypass vulnerability allows an attacker to log in as any user who has li…
- CVE-2026-33432CRITICALCVSS 9.1EG 9.12026-04-20
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions up to and including 8.2.8.2, when LDAP authentication is enabled, Roxy-WI constructs an LDAP search filter by directly concatenating the use…
- CVE-2026-33473MEDIUMCVSS 5.7EG 5.72026-03-24
Vikunja is an open-source self-hosted task management platform. Starting in version 0.13 and prior to version 2.2.1, any user that has enabled 2FA can have their TOTP reused during the standard 30 second validity window. Version 2.2.1 patc…
- CVE-2026-33512HIGHCVSS 7.5EG 7.52026-03-23
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the API plugin exposes a `decryptString` action without any authentication. Anyone can submit ciphertext and receive plaintext. Ciphertext is issued public…
- CVE-2026-33665HIGHCVSS 7.5EG 7.52026-03-25
n8n is an open source workflow automation platform. Prior to versions 2.4.0 and 1.121.0, when LDAP authentication is enabled, n8n automatically linked an LDAP identity to an existing local account if the LDAP email attribute matched the lo…
- CVE-2026-33716CRITICALCVSS 9.4EG 9.42026-03-23
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the standalone live stream control endpoint at `plugin/Live/standAloneFiles/control.json.php` accepts a user-supplied `streamerURL` parameter that override…
- CVE-2026-33746CRITICALCVSS 9.8EG 9.82026-04-02
Convoy is a KVM server management panel for hosting businesses. From version 3.9.0-beta to before version 4.5.1, the JWTService::decode() method did not verify the cryptographic signature of JWT tokens. While the method configured a symmet…
- CVE-2026-33898HIGHCVSS 8.8EG 8.82026-03-27
Incus is a system container and virtual machine manager. Prior to version 6.23.0, the web server spawned by `incus webui` incorrectly validates the authentication token such that an invalid value will be accepted. `incus webui` runs a loca…
- CVE-2026-34072CRITICALCVSS 9.8EG 9.82026-04-01
Cr*nMaster (cronmaster) is a Cronjob management UI with human readable syntax, live logging and log history for cronjobs. Prior to version 2.2.0, an authentication bypass in middleware allows unauthenticated requests with an invalid sessio…
- CVE-2026-34121HIGHCVSS 8.8EG 8.82026-04-02
An authentication bypass vulnerability within the HTTP handling of the DS configuration service in TP-Link Tapo C520WS v2.6 was identified, due to inconsistent parsing and authorization logic in JSON requests during authentication check. …
- CVE-2026-34123HIGHCVSS 7.0EG 7.02026-06-05
On Tapo C520WS v2, restricted accounts (for example, hub users) are intended to execute only a limited set of low‑sensitivity operations. Due to a logic flaw in the device’s API authorization mechanism, an attacker can craft requests t…
- CVE-2026-34204HIGHCVSS 7.1EG 7.12026-03-31
MinIO is a high-performance object storage system. Prior to version RELEASE.2026-03-26T21-24-40Z, a flaw in extractMetadataFromMime() allows any authenticated user with s3:PutObject permission to inject internal server-side encryption meta…
- CVE-2026-34389MEDIUMCVSS 6.5EG 6.52026-03-27
Fleet is open source device management software. Prior to 4.81.0, Fleet contained an issue in the user invitation flow where the email address provided during invite acceptance was not validated against the email address associated with th…
- CVE-2026-34500MEDIUMCVSS 6.5EG 6.52026-04-09
CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled and FFM is used in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M14 through 11.0.20, from 10.1.22 through 10.1.53, from 9.0…
- CVE-2026-34531MEDIUMCVSS 6.5EG 6.52026-04-01
Flask-HTTPAuth provides Basic, Digest and Token HTTP authentication for Flask routes. Prior to version 4.8.1, in a situation where the client makes a request to a token protected resource without passing a token, or passing an empty token,…
- CVE-2026-34727HIGHCVSS 7.4EG 7.42026-04-10
Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the OIDC callback handler issues a full JWT token without checking whether the matched user has TOTP two-factor authentication enabled. When a local user with …
- CVE-2026-34736MEDIUMCVSS 5.3EG 5.32026-04-02
Open edX Platform enables the authoring and delivery of online learning at any scale. From the maple release to before the ulmo release, an unauthenticated attacker can fully bypass the email verification process by combining two issues: t…
- CVE-2026-34834HIGHCVSS 7.5EG 7.52026-04-02
Bulwark Webmail is a self-hosted webmail client for Stalwart Mail Server. Prior to version 1.4.10, the verifyIdentity() function contained logic that returned true if no session cookies were present. This allowed unauthenticated attackers …
- CVE-2026-34873CRITICALCVSS 9.1EG 9.12026-04-01
An issue was discovered in Mbed TLS 3.5.0 through 4.0.0. Client impersonation can occur while resuming a TLS 1.3 session.
- CVE-2026-34917MEDIUMCVSS 4.3EG 4.32026-06-23
Low‑privileged session IDs generated for the web admin console could be reused in the XML‑RPC API, whose authentication is normally restricted to admin users. An attacker could leverage this to gain unauthorised access and exploit API�…
- CVE-2026-34990HIGHCVSS 7.8EG 7.82026-04-03
OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, a local unprivileged user can coerce cupsd into authenticating to an attacker-controlled localhost IPP servi…
- CVE-2026-35030CRITICALCVSS 9.1EG 9.12026-04-06
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.0, when JWT authentication is enabled (enable_jwt_auth: true), the OIDC userinfo cache uses token[:20] as the cache key. JWT headers produc…
- CVE-2026-35261MEDIUMCVSS 6.5EG 6.52026-06-17
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticate…
Map vulnerabilities like CWE-287 to your infrastructure
EchelonGraph correlates every CVE — across CWE-287 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →