CWE-287— Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.— MITRE CWE catalog
5,115 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-287page 91 of 103
- CVE-2026-15611CRITICALCVSS 9.1EG 9.12026-07-23
Logto allows unverified email-based SSO account linking, enabling an attacker to register an identity at a permissive IdP using a victim’s email and gain unauthorized access to the victim’s account.
- CVE-2026-1568CRITICALCVSS 9.6EG 9.62026-02-03
Rapid7 InsightVM versions before 8.34.0 contain a signature verification issue on the Assertion Consumer Service (ACS) cloud endpoint that could allow an attacker to gain unauthorized access to InsightVM accounts setup via "Security Cons…
- CVE-2026-15981CRITICALCVSS 9.8EG 9.82026-07-23
The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.4.4. This is due to the mo_saml_validate_signature() function performing a loose boolean check on the…
- CVE-2026-16015MEDIUMCVSS 6.3EG 6.32026-07-17
A vulnerability was determined in poco-ai poco-claw up to 0.5.4. This vulnerability affects the function create_task of the file executor_manager/app/api/v1/tasks.py of the component executor_manager API. Executing a manipulation can lead …
- CVE-2026-16030HIGHCVSS 8.1EG 8.12026-08-07
The MStore API WordPress plugin before 4.21.0 does not correctly verify the cryptographic signature of the token used to authenticate its phone-based login, allowing unauthenticated attackers who know a registered user's phone number to f…
- CVE-2026-16036HIGHCVSS 7.5EG 7.52026-08-05
The miniOrange 2FA WordPress plugin before 6.2.7 does not bind the second factor being configured during the pre-login two-factor challenge to the target account's existing factor, allowing an attacker who knows a user's password to rebin…
- CVE-2026-16055HIGHCVSS 7.5EG 7.52026-08-05
The Contest Gallery WordPress plugin before 30.0.7 does not route its front-end login through the standard WordPress authentication flow, issuing an authentication cookie directly after the password check, which bypasses installed brute-f…
- CVE-2026-16076MEDIUMCVSS 6.3EG 6.32026-07-18
A vulnerability has been found in AstrBotDevs AstrBot up to 4.25.5. This issue affects the function OpenApiRoute.chat_send of the file astrbot/dashboard/routes/open_api.py of the component API. Such manipulation of the argument Username le…
- CVE-2026-16083MEDIUMCVSS 5.3EG 5.32026-07-18
A security flaw has been discovered in Sipeed PicoClaw up to 0.2.9. This affects the function webhook.ParseRequest of the file pkg/channels/line/line.go of the component LINE Webhook. The manipulation results in authentication bypass by ca…
- CVE-2026-16198MEDIUMCVSS 5.6EG 5.62026-07-18
A vulnerability was detected in Sipeed PicoClaw up to 0.2.9. The impacted element is an unknown function of the file web/backend/middleware/access_control.go of the component First Run Setup. Performing a manipulation of the argument allow…
- CVE-2026-16209HIGHCVSS 7.3EG 7.32026-07-19
A vulnerability has been found in Gerapy up to 0.9.13. The impacted element is an unknown function of the file gerapy/server/core/views.py of the component Project Upload Endpoint. Such manipulation leads to missing authentication. The att…
- CVE-2026-16210HIGHCVSS 7.3EG 7.32026-07-19
A vulnerability was found in newpanjing simpleui 2026.01.13. This affects the function self.get_action of the file simpleui/admin.py of the component AjaxAdmin AJAX Endpoint. Performing a manipulation results in missing authentication. Rem…
- CVE-2026-16232CRITICALCVSS 9.8EG 9.8⚠ KEV2026-07-22
An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful …
- CVE-2026-16257HIGHCVSS 8.2EG 8.22026-08-10
The Arvow AI SEO Writer WordPress plugin before 1.5.4 does not properly restrict access to one of its REST endpoints, whose only access control can be bypassed by unauthenticated users through type juggling when the Arvow AI SEO Writer Wor…
- CVE-2026-16261HIGHCVSS 7.5EG 7.52026-08-02
The login-social WordPress plugin through 1.0.4 does not validate password-reset requests against a reset key or the requester's identity, and it issues authentication sessions from unverified third-party sign-in data, allowing unauthentic…
- CVE-2026-16269MEDIUMCVSS 4.8EG 4.82026-08-08
The Newsletters WordPress plugin before 4.16 does not strictly compare its API authentication key, allowing unauthenticated attackers to bypass the API authentication via type juggling and perform privileged actions such as modifying subsc…
- CVE-2026-16282MEDIUMCVSS 5.3EG 5.32026-08-08
The Appointment Hour Booking WordPress plugin before 1.5.88 does not validate a client-supplied booking price against the server-side configured service price, allowing unauthenticated users to submit an arbitrary final price (including z…
- CVE-2026-16299CRITICALCVSS 9.8EG 9.82026-08-10
The Single Sign On For TNG WordPress plugin before 2.2.0 does not properly validate a password reset request, allowing unauthenticated attackers to reset the password of arbitrary users, including administrators, which could lead to a full…
- CVE-2026-16656CRITICALCVSS 9.8EG 9.82026-08-19
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to gain root privileges due to improper authentication.
- CVE-2026-16686HIGHCVSS 8.2EG 8.22026-08-19
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to access NFS-exported filesystems due to improper authentication.
- CVE-2026-16739MEDIUMCVSS 5.9EG 5.92026-08-14
The Epeken All Kurir for Woocommerce WordPress plugin through 2.1.2 does not verify that a payment-confirmation request originates from the owner of the targeted order, nor that any payment actually occurred, allowing unauthenticated attac…
- CVE-2026-16857HIGHCVSS 8.2EG 8.22026-08-19
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to manipulate network traffic and DNS configuration due to improper authentication.
- CVE-2026-16867CRITICALCVSS 9.8EG 9.82026-08-13
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to access server resources with the privileges of an authenticated user due to improper authentication during NTLM session negotiation.
- CVE-2026-16905MEDIUMCVSS 6.5EG 6.52026-08-14
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper authentication.
- CVE-2026-16972HIGHCVSS 7.5EG 7.52026-08-20
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to obtain sensitive information due to improper authentication.
- CVE-2026-17000CRITICALCVSS 9.8EG 9.82026-08-20
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to improper authentication.
- CVE-2026-17013MEDIUMCVSS 6.1EG 6.12026-08-12
The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not sanitise and escape a parameter before reflecting it into an inline script block, which could allow unauthenticated attackers to perform Reflected Cross-Site Scripting att…
- CVE-2026-17075HIGHCVSS 8.2EG 8.22026-08-13
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information and perform unauthorized operations due to improper validation of authentication tokens.
- CVE-2026-17099HIGHCVSS 7.3EG 7.32026-08-13
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to improper authentication.
- CVE-2026-17101CRITICALCVSS 9.6EG 9.62026-08-13
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code or obtain sensitive information due to improper authentication.
- CVE-2026-17142CRITICALCVSS 9.8EG 9.82026-08-20
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary commands due to improper authentication.
- CVE-2026-17175HIGHCVSS 6.5EG 7.52026-08-14
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper authentication enforcement.
- CVE-2026-17182CRITICALCVSS 9.8EG 9.82026-08-14
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to bypass authentication and obtain or alter sensitive information due to improper validation of request URI path segments.
- CVE-2026-17197CRITICALCVSS 9.8EG 9.82026-08-13
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to bypass security restrictions due to improper validation of client-asserted identity.
- CVE-2026-17203HIGHCVSS 7.5EG 7.52026-08-28
IBM Administration Runtime Expert for i 1R1M0 could allow a remote authenticated attacker to obtain sensitive information due to improper authentication enforcement.
- CVE-2026-1740CRITICALCVSS 9.8EG 9.82026-02-02
A vulnerability was found in EFM ipTIME A8004T 14.18.2. This impacts the function httpcon_check_session_url of the file /cgi/timepro.cgi of the component Hidden Hiddenloginsetup Interface. The manipulation results in improper authenticatio…
- CVE-2026-1743LOWCVSS 3.1EG 3.12026-02-02
A vulnerability has been found in DJI Mavic Mini, Air, Spark and Mini SE up to 01.00.0500. Affected by this vulnerability is an unknown functionality of the component Enhanced Wi-Fi Pairing. The manipulation leads to authentication bypass …
- CVE-2026-18031CRITICALCVSS 9.8EG 9.82026-08-19
The TabaPay Gateway WordPress plugin through 1.4.0 does not validate the payment callback before establishing a session for the account associated with the referenced order, allowing unauthenticated attackers to log in as any registered us…
- CVE-2026-18052HIGHCVSS 8.1EG 8.12026-08-22
The ManageWP Worker WordPress plugin before 4.9.37 does not bind the account being logged in to the signature which authorises the login, nor prevent an already used login link from being replayed, allowing attackers who obtain such a link…
- CVE-2026-18215HIGHCVSS 8.1EG 8.12026-07-31
Keycloak provides a way to let users log in using Microsoft accounts while restricting access to a specific organization (tenant). A flaw was discovered where this restriction is ignored when using the token exchange feature. This means an…
- CVE-2026-18216MEDIUMCVSS 6.5EG 6.52026-08-15
The Backup Migration WordPress plugin before 2.1.7 does not properly restrict a post-restore automatic login mechanism, allowing a user who administers one site of a multisite network to obtain a long-lived authenticated session as an admi…
- CVE-2026-18468HIGHCVSS 8.1EG 8.12026-08-10
The Login & Register Forms WordPress plugin before 4.0.2 does not bind the password reset verification state to the account being reset or to the party that completed the verification, keying it instead on a value the client controls, all…
- CVE-2026-18469HIGHCVSS 8.1EG 8.12026-08-10
The Login & Register Forms WordPress plugin before 4.0.2 does not enforce its password reset attempt limit against a server-derived value, keying both the verification code and the per-source attempt counter on client-controlled data, all…
- CVE-2026-18610MEDIUMCVSS 5.3EG 5.32026-08-03
A vulnerability was detected in NewType WebEIP up to 3.0. This affects an unknown part of the file /EIP_Com_FileList.aspx. The manipulation results in improper authentication. It is possible to launch the attack remotely. The exploit is no…
- CVE-2026-18651MEDIUMCVSS 5.4EG 5.42026-08-03
A flaw was found in 389 Directory Server. During SASL PLAIN authentication, the server installs connection-level bind credentials before performing the account-lock check. If the account is subsequently found to be locked, the bind is repo…
- CVE-2026-18759HIGHCVSS 8.5EG 8.52026-08-04
The background service of ABP or AES runs as NT AUTHORITY\SYSTEM and implements a file-based inter-process communication (IPC) mechanism protected by AES encryption. Because the encryption key file is readable by standard users and protect…
- CVE-2026-18786HIGHCVSS 8.8EG 8.82026-08-10
The CheckView WordPress plugin before 2.3.2 does not restrict its REST API authentication filter to its own routes and unconditionally discards the authentication error raised for any request whose URI merely contains a CheckView WordPre…
- CVE-2026-18810HIGHCVSS 7.3EG 7.32026-08-04
A security vulnerability has been detected in H3C NX15 V100R017. Impacted is an unknown function of the file /api/wizard/networkSetup. Such manipulation leads to missing authentication. The attack may be performed from remote. The vendor w…
- CVE-2026-18816MEDIUMCVSS 5.0EG 5.02026-08-04
A vulnerability was identified in Baserow up to 2.3.2. Affected by this vulnerability is the function verify of the file backend/src/baserow/api/two_factor_auth/views.py of the component 2FA Verify Endpoint. Such manipulation leads to impr…
- CVE-2026-18891HIGHCVSS 8.2EG 8.22026-08-28
IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to execute arbitrary flows and access sensitive information due to improper authentication.
Map vulnerabilities like CWE-287 to your infrastructure
EchelonGraph correlates every CVE — across CWE-287 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →