CWE-287— Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.— MITRE CWE catalog
5,116 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-287page 101 of 103
- CVE-2026-62144CRITICALCVSS 9.1EG 9.12026-07-22
An authentication bypass vulnerability in Check Point Security Management and Multi-Domain Security Management allows an unauthenticated remote attacker to execute administrative commands on the Management Server. Successful exploitation m…
- CVE-2026-62447HIGHCVSS 8.8EG 8.82026-07-21
Vulnerability in the Oracle Trade Management product of Oracle E-Business Suite (component: Claim LOV). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network …
- CVE-2026-62464HIGHCVSS 8.8EG 8.82026-07-21
Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network…
- CVE-2026-62476HIGHCVSS 8.8EG 8.82026-07-21
Vulnerability in the Oracle Public Sector Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacke…
- CVE-2026-62478HIGHCVSS 8.8EG 8.82026-07-21
Vulnerability in the Oracle Public Sector Financials product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged atta…
- CVE-2026-62493HIGHCVSS 7.5EG 7.52026-07-21
Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.11-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with n…
- CVE-2026-62496HIGHCVSS 8.8EG 8.82026-07-21
Vulnerability in the Oracle Yard Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.6-12.2.15. Easily exploitable vulnerability allows low privileged attacker with…
- CVE-2026-62498HIGHCVSS 8.8EG 8.82026-07-21
Vulnerability in the Oracle Flow Manufacturing product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.7-12.2.15. Easily exploitable vulnerability allows low privileged attacker w…
- CVE-2026-62534HIGHCVSS 8.8EG 8.82026-07-21
Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Web Utilities). Supported versions that are affected are 12.2.11-12.2.15. Easily exploitable vulnerability allows low privileged attacker wi…
- CVE-2026-62547HIGHCVSS 8.1EG 8.12026-07-21
Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker…
- CVE-2026-62669HIGHCVSS 7.4EG 7.42026-08-19
Grav Login Plugin adds login, basic ACL, and session wide messages to Grav. Prior to 3.8.11, the Grav Login plugin login.regenerate2FASecret task checks only that the pending-session user exists rather than requiring $user->authorized. Aft…
- CVE-2026-6274CRITICALCVSS 9.8EG 9.82026-06-05
Improper Authentication, Missing authentication for critical function, Weak Authentication vulnerability in DTS Electronics Industry and Trade Ltd. Co. Redline WR3200 allows Accessing Functionality Not Properly Constrained by ACLs. This i…
- CVE-2026-62825CRITICALCVSS 9.8EG 10.02026-07-24
Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network.
- CVE-2026-62827HIGHCVSS 8.8EG 8.82026-08-11
Improper authentication in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
- CVE-2026-62896CRITICALCVSS 9.6EG 9.62026-08-06
Improper authentication in Microsoft Teams allows an authorized attacker to elevate privileges over a network.
- CVE-2026-63238MEDIUMCVSS 6.5EG 6.52026-07-29
An authentication bypass vulnerability in Koollab LMS allowed an unauthenticated attacker to take over any account, including administrator accounts, by supplying a valid user UUID without providing primary credentials via the 2FA validati…
- CVE-2026-63456CRITICALCVSS 9.8EG 9.82026-08-04
Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web authentication mechanisms and access system functions. Successful exploitation could allo…
- CVE-2026-6456HIGHCVSS 8.8EG 8.82026-05-20
The Account Switcher plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.2. This is due to the `rememberLogin` REST API endpoint using a loose comparison (`!=` instead of `!==`) for secret v…
- CVE-2026-64665HIGHCVSS 8.1EG 8.12026-08-06
Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, when OAuth login was enabled with a provider that does not guarantee verified email addresses, an unauthenticated attacker could sign in as …
- CVE-2026-64745LOWCVSS 2.4EG 2.42026-07-27
This issue was addressed with additional restrictions on the lock screen. This issue is fixed in macOS Sequoia 15.7.8, macOS Tahoe 26.6. A person with physical access to a locked device may be able to access contacts and photos.
- CVE-2026-65329MEDIUMCVSS 5.9EG 5.92026-08-17
An authentication issue was addressed with improved state management. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1. An attacker in a privileged network position may be able to bypass IPSec authentication and intercept network traffi…
- CVE-2026-65400CRITICALCVSS 9.8EG 9.8⚠ KEV2026-08-06
An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26.6.1. An attacker on the network may be able to authenticate to Screen Sharing without va…
- CVE-2026-65633HIGHCVSS 7.6EG 7.62026-08-25
Improper Authentication vulnerability in team-alembic AshAuthentication allows purpose-limited JWTs to be replayed as full bearer API credentials when a resource uses stateless bearer-token verification. The bearer-token authentication he…
- CVE-2026-6569HIGHCVSS 7.3EG 7.32026-04-19
A vulnerability was identified in kodcloud KodExplorer up to 4.52. This impacts the function fileGet of the file /app/controller/share.class.php of the component fileGet Endpoint. Such manipulation of the argument fileUrl leads to improper…
- CVE-2026-6577HIGHCVSS 7.3EG 7.32026-04-19
A vulnerability was identified in liangliangyy DjangoBlog up to 2.1.0.0. The impacted element is an unknown function of the file owntracks/views.py of the component logtracks Endpoint. The manipulation leads to missing authentication. The …
- CVE-2026-6579MEDIUMCVSS 6.5EG 6.52026-04-19
A weakness has been identified in liangliangyy DjangoBlog up to 2.1.0.0. This impacts an unknown function of the file blog/views.py of the component Clean Endpoint. This manipulation causes missing authentication. The attack may be initiat…
- CVE-2026-6582HIGHCVSS 7.3EG 7.32026-04-19
A flaw has been found in TransformerOptimus SuperAGI up to 0.0.14. Affected by this issue is the function get_vector_db_details of the file superagi/controllers/vector_dbs.py of the component Vector Database Management Endpoint. Executing …
- CVE-2026-6588MEDIUMCVSS 6.5EG 6.52026-04-20
A weakness has been identified in serge-chat serge up to 1.4TB. The impacted element is the function download_model/delete_model of the file api/src/serge/routers/model.py of the component Model API Endpoint. Executing a manipulation can l…
- CVE-2026-66014CRITICALCVSS 9.8EG 9.82026-07-27
JFrog Artifactory contains an authentication handling weakness in internal request processing that, under specific conditions, may allow an attacker to escalate privileges beyond the intended access level.
- CVE-2026-6635HIGHCVSS 7.3EG 7.32026-04-20
A security vulnerability has been detected in rowboatlabs rowboat up to 0.1.67. This impacts the function tool_call of the file apps/experimental/tools_webhook/app.py of the component tools_webhook. Such manipulation of the argument X-Tool…
- CVE-2026-66908HIGHCVSS 7.5EG 7.52026-08-24
Improper Authentication vulnerability in Apache Camel Platform HTTP Main component. This issue affects Apache Camel: from 4.8.0 before 4.22.0. The camel-main embedded HTTP server can protect its endpoints with JWT authentication, con…
- CVE-2026-6729MEDIUMCVSS 6.3EG 6.32026-04-20
HKUDS OpenHarness prior to PR #159 remediation contains a session key derivation vulnerability that allows authenticated participants in shared chats or threads to hijack other users' sessions by exploiting a shared ohmo session key that l…
- CVE-2026-67327HIGHCVSS 8.3EG 8.32026-08-01
better-auth versions >= 1.1.3 and < 1.6.22 (and pre-release versions >= 1.7.0-beta.0 and < 1.7.0-beta.10) are vulnerable to account takeover via pre-account hijacking on magic-link and email-OTP sign-in when open email/password registratio…
- CVE-2026-67335MEDIUMCVSS 5.3EG 5.32026-08-01
better-auth versions before 1.6.2 fail to validate the OAuth state parameter against the stored nonce when using cookie-backed state storage without PKCE. Attackers can forge the state parameter and supply an attacker-controlled authorizat…
- CVE-2026-68569HIGHCVSS 8.1EG 8.12026-08-25
Improper Authentication vulnerability in Apache Tomcat meant that in some circumstances (e.g. CLIENT-CERT, SPNEGO) that a user would be authenticated even if the user did not exist in the DataSourceRealm. This issue affects Apache Tomca…
- CVE-2026-68760MEDIUMCVSS 5.3EG 5.32026-08-12
An unauthenticated user may bypass authentication under specific cache conditions.
- CVE-2026-7022HIGHCVSS 7.3EG 7.32026-04-26
A security vulnerability has been detected in SmythOS sre up to 0.0.15. Affected is the function AgentRuntime of the file packages/core/src/subsystems/AgentManager/AgentRuntime.class.ts of the component HTTP Header Handler. Such manipulati…
- CVE-2026-7042HIGHCVSS 7.3EG 7.32026-04-26
A flaw has been found in 666ghj MiroFish up to 0.1.2. This affects the function create_app of the file backend/app/__init__.py of the component REST API Endpoint. Executing a manipulation can lead to missing authentication. It is possible …
- CVE-2026-70482HIGHCVSS 8.1EG 8.12026-08-04
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.0 until 0.11.0, when ENABLE_OAUTH_TOKEN_EXCHANGE=True, /oauth/{provider}/token/exchange accepts a raw provider access token and validates it by …
- CVE-2026-70905CRITICALCVSS 9.8EG 9.82026-08-18
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Agent infrastructure). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated…
- CVE-2026-70922HIGHCVSS 8.8EG 8.82026-08-18
Vulnerability in the Oracle Financial Services Enterprise Case Management product of Oracle Financial Services Applications (component: Web UI). Supported versions that are affected are 8.0.8.2 and 8.1.2.11. Easily exploitable vulnerabil…
- CVE-2026-7112MEDIUMCVSS 5.6EG 5.62026-04-27
A vulnerability has been found in NousResearch hermes-agent 0.8.0. Affected by this vulnerability is the function _check_auth of the file gateway/platforms/api_server.py of the component API_SERVER_KEY Handler. The manipulation leads to im…
- CVE-2026-7113MEDIUMCVSS 5.6EG 5.62026-04-27
A vulnerability was found in NousResearch hermes-agent 0.8.0. Affected by this issue is some unknown functionality of the file gateway/platforms/webhook.py of the component Webhooks Endpoint. The manipulation of the argument _INSECURE_NO_A…
- CVE-2026-71277CRITICALCVSS 9.1EG 9.12026-08-05
rust-iot-platform's AuthToken request-guard implementation (api/src/main.rs) only checks whether the Authorization HTTP header is present, and never validates its value against any session, token store, or signature. Any request carrying a…
- CVE-2026-71326LOWCVSS 2.1EG 2.12026-08-06
Traefik is an open source HTTP reverse proxy and load balancer. From 3.6.11 until 3.6.25 and 3.7.10, Traefik's BasicAuth middleware in pkg/middlewares/auth/basic_auth.go deduplicates concurrent password checks with a singleflight key built…
- CVE-2026-71467HIGHCVSS 7.5EG 7.52026-08-11
A flaw was found in search-v2-api. The authentication middleware in the affected component unconditionally skips authentication when a request includes an `Upgrade: websocket` header. An unauthenticated attacker can exploit this by sending…
- CVE-2026-72533HIGHCVSS 8.8EG 8.82026-08-11
An authentication bypass vulnerability in Portainer CE through 2.44.0 allows authenticated low-privileged users to bypass Docker proxy authorization checks via non-canonical URL normalization, defeating all authorization middleware. The pr…
- CVE-2026-72917MEDIUMCVSS 5.9EG 5.92026-08-10
AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. From 1.0.0 to 1.15.0, AnythingLLM's unauthenticated account-recovery flow in server/utils/PasswordRecovery/index.js…
- CVE-2026-72922HIGHCVSS 8.2EG 8.22026-08-11
AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.70, AutoGPT's autogpt_platform/backend/backend/api/features/integrations/router.py webhook_ingress_gene…
- CVE-2026-73054HIGHCVSS 7.5EG 7.52026-08-15
SiYuan versions before v3.7.4 contain an authentication bypass vulnerability in the WebSocket endpoint caused by differential parsing of query parameters between authentication exemption and session quarantine checks. Unauthenticated attac…
Map vulnerabilities like CWE-287 to your infrastructure
EchelonGraph correlates every CVE — across CWE-287 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →