CWE-287— Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.— MITRE CWE catalog
5,115 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-287page 93 of 103
- CVE-2026-25893CRITICALCVSS 9.8EG 9.82026-02-09
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.2.10, an authentication bypass vulnerability in FUXA allows an unauthenticated, remote attacker to gain administrative access via the heartbeat refresh AP…
- CVE-2026-25922HIGHCVSS 8.8EG 8.82026-02-12
authentik is an open-source identity provider. Prior to 2025.8.6, 2025.10.4, and 2025.12.4, when using a SAML Source that has the option Verify Assertion Signature under Verification Certificate enabled and not Verify Response Signature, o…
- CVE-2026-25937MEDIUMCVSS 6.5EG 6.52026-03-18
GLPI is a free Asset and IT management software package. Starting in version 11.0.0 and prior to version 11.0.6, a malicious actor with knowledge of a user's credentials can bypass MFA and steal their account. Version 11.0.6 fixes the issu…
- CVE-2026-26035CRITICALCVSS 9.8EG 9.82026-08-12
An Improper Authentication vulnerability [CWE-287] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11, FortiWeb 7.2.0 through 7.2.12, FortiWeb 7.0.0 through 7.0.12 may allow …
- CVE-2026-26077MEDIUMCVSS 6.5EG 6.52026-02-26
Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, several webhook endpoints (SendGrid, Mailjet, Mandrill, Postmark, SparkPost) in the `WebhooksController` accepted requests without a vali…
- CVE-2026-26119HIGHCVSS 8.8EG 8.82026-02-17
Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges over a network.
- CVE-2026-26128HIGHCVSS 7.8EG 7.82026-03-10
Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges locally.
- CVE-2026-26141HIGHCVSS 7.8EG 7.82026-03-10
Improper authentication in Azure Arc allows an authorized attacker to elevate privileges locally.
- CVE-2026-27134HIGHCVSS 8.1EG 8.12026-02-21
Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations. In versions 0.49.0 through 0.50.0, when using a custom Cluster or Clients CA with a multistage CA chain consisting of m…
- CVE-2026-27197CRITICALCVSS 9.1EG 9.12026-02-21
Sentry is a developer-first error tracking and performance monitoring tool. Versions 21.12.0 through 26.1.0 have a critical vulnerability in its SAML SSO implementation which allows an attacker to take over any user account by using a mal…
- CVE-2026-2756MEDIUMCVSS 5.0EG 5.02026-03-21
A security vulnerability has been detected in OmniPEMF NeoRhythm up to 20260308. This affects an unknown function of the component BLE Interface. Such manipulation leads to missing authentication. The attack can only be initiated within th…
- CVE-2026-27611MEDIUMCVSS 6.5EG 6.52026-02-25
FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to versions 1.1.3-stable and 1.2.6-beta, when users share password-protected files, the recipient can completely bypass the password and still download the file. Thi…
- CVE-2026-27856HIGHCVSS 5.9EG 7.42026-03-27
Doveadm credentials are verified using direct comparison which is susceptible to timing oracle attack. An attacker can use this to determine the configured credentials. Figuring out the credential will lead into full access to the affected…
- CVE-2026-27939HIGHCVSS 8.8EG 8.82026-02-27
Statmatic is a Laravel and Git powered content management system (CMS). Starting in version 6.0.0 and prior to version 6.4.0, Authenticated Control Panel users may under certain conditions obtain elevated privileges without completing the …
- CVE-2026-27960CRITICALCVSS 9.8EG 9.82026-05-05
OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. In versions 6.6.0 through 6.9.12, there is a privilege escalation vulnerability that can be exploited by unauthenticated attackers to quer…
- CVE-2026-27968MEDIUMCVSS 4.3EG 4.32026-02-26
Packistry is a self-hosted Composer repository designed to handle PHP package distribution. Prior to version 0.13.0, RepositoryAwareController::authorize() verified token presence and ability, but did not enforce token expiration. As a res…
- CVE-2026-2812MEDIUMCVSS 5.3EG 5.32026-05-20
ArcGIS Server contains an improper authentication vulnerability in an undocumented administrative endpoint. An unauthenticated attacker could exploit this issue by sending a crafted request to the endpoint. Successful exploitation may resu…
- CVE-2026-28215CRITICALCVSS 9.1EG 9.12026-02-26
hoppscotch is an open source API development ecosystem. Prior to version 2026.2.0, an unauthenticated attacker can overwrite the entire infrastructure configuration of a self-hosted Hoppscotch instance including OAuth provider credentials …
- CVE-2026-28323CRITICALCVSS 9.8EG 9.82026-07-30
SolarWinds Web Help Desk is found to be affected by a SAML authentication bypass vulnerability. This requires the SAML 2.0 authentication method to be enabled.
- CVE-2026-28408CRITICALCVSS 9.8EG 9.82026-02-27
WeGIA is a web manager for charitable institutions. Prior to version 3.6.5, the script in adicionar_tipo_docs_atendido.php does not go through the project's central controller and does not have its own authentication and permission checks.…
- CVE-2026-28428MEDIUMCVSS 5.3EG 5.32026-03-06
Talishar is a fan-made Flesh and Blood project. Prior to commit a9c218e, an authentication bypass vulnerability in Talishar's game endpoint validation logic allows any unauthenticated attacker to perform authenticated game actions — incl…
- CVE-2026-28471MEDIUMCVSS 5.3EG 5.32026-03-05
OpenClaw version 2026.1.14-1 prior to 2026.2.2, with the Matrix plugin installed and enabled, contain a vulnerability in which DM allowlist matching could be bypassed by exact-matching against sender display names and localparts without ho…
- CVE-2026-28514CRITICALCVSS 9.8EG 9.82026-03-06
Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to versions 7.8.6, 7.9.8, 7.10.7, 7.11.4, 7.12.4, 7.13.3, and 8.0.0, a critical authentication bypass vulnerability exists in Rocket.Chat's account se…
- CVE-2026-28787CRITICALCVSS 9.0EG 9.02026-03-06
OneUptime is a solution for monitoring and managing online services. In version 10.0.11 and prior, the WebAuthn authentication implementation does not store the challenge on the server side. Instead, the challenge is returned to the client…
- CVE-2026-28800HIGHCVSS 8.0EG 8.02026-03-06
Natro Macro is an open-source Bee Swarm Simulator macro written in AutoHotkey. Prior to version 1.1.0, anyone with Discord Remote Control set up in a non-private channel gives access to any user with the permission to send message in said …
- CVE-2026-29093CRITICALCVSS 9.8EG 9.82026-03-06
WWBN AVideo is an open source video platform. Prior to version 24.0, the official docker-compose.yml publishes the memcached service on host port 11211 (0.0.0.0:11211) with no authentication, while the Dockerfile configures PHP to store al…
- CVE-2026-29145CRITICALCVSS 9.1EG 9.12026-04-09
CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apache Tomcat, Apache Tomcat Native. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M7 thro…
- CVE-2026-29193HIGHCVSS 8.2EG 8.22026-03-07
ZITADEL is an open source identity management platform. From version 4.0.0 to 4.12.0, a vulnerability in Zitadel's login V2 UI allowed users to bypass login behavior and security policies and self-register new accounts or sign in using pas…
- CVE-2026-29792CRITICALCVSS 9.8EG 9.82026-03-10
Feathersjs is a framework for creating web APIs and real-time applications with TypeScript or JavaScript. From 5.0.0 to before 5.0.42, an unauthenticated attacker can send a crafted GET request directly to /oauth/:provider/callback with a …
- CVE-2026-2991CRITICALCVSS 7.3EG 9.82026-03-18
The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 4.1.2. This is due to the `patientSocialLogin()` function not verifying the social …
- CVE-2026-30223HIGHCVSS 8.8EG 8.82026-03-06
OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.11.1, when JWT authentication is configured using either "authJwtPubKeyPath" (local RSA public key) or "authJwtHmacSecret" (HMAC secret), the co…
- CVE-2026-3053CRITICALCVSS 9.8EG 9.82026-02-24
A vulnerability was determined in DataLinkDC dinky up to 1.2.5. This affects the function addInterceptors of the file dinky-admin/src/main/java/org/dinky/configure/AppConfig.java of the component OpenAPI Endpoint. Executing a manipulation …
- CVE-2026-30831CRITICALCVSS 9.8EG 9.82026-03-06
Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to versions 7.10.8, 7.11.5, 7.12.5, 7.13.4, 8.0.2, 8.1.1, and 8.2.0, authentication vulnerabilities exist in Rocket.Chat's enterprise DDP Streamer ser…
- CVE-2026-30836CRITICALCVSS 10.0EG 10.02026-03-19
Step CA is an online certificate authority for secure, automated certificate management for DevOps. Versions 0.30.0-rc6 and below do not safeguard against unauthenticated certificate issuance through the SCEP UpdateReq. This issue has been…
- CVE-2026-30851HIGHCVSS 8.8EG 8.82026-03-07
Caddy is an extensible server platform that uses TLS by default. From version 2.10.0 to before version 2.11.2, forward_auth copy_headers does not strip client-supplied headers, allowing identity injection and privilege escalation. This iss…
- CVE-2026-30863CRITICALCVSS 9.8EG 9.82026-03-07
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.10 and 9.5.0-alpha.11, the Google, Apple, and Facebook authentication adapters use JWT verification to validate i…
- CVE-2026-30949HIGHCVSS 8.8EG 8.82026-03-10
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-alpha.5 and 8.6.18, the Keycloak authentication adapter does not validate the azp (authorized party) claim of Keycloak a…
- CVE-2026-30967HIGHCVSS 8.8EG 8.82026-03-10
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-alpha.9. and 8.6.22, the OAuth2 authentication adapter, when configured without the useridField option, only verifies th…
- CVE-2026-31387MEDIUMCVSS 5.3EG 5.32026-05-19
Improper Authentication vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue.
- CVE-2026-3192HIGHCVSS 8.1EG 8.12026-02-25
A security vulnerability has been detected in Chia Blockchain 2.1.0. This issue affects the function _authenticate of the file rpc_server_base.py of the component RPC Credential Handler. The manipulation leads to improper authentication. T…
- CVE-2026-3194HIGHCVSS 7.0EG 7.02026-02-25
A flaw has been found in Chia Blockchain 2.1.0. The affected element is the function send_transaction/get_private_key of the component RPC Server Master Passphrase Handler. This manipulation causes missing authentication. The attack can on…
- CVE-2026-31946CRITICALCVSS 9.8EG 9.82026-03-30
OpenOlat is an open source web-based e-learning platform for teaching, learning, assessment and communication. From version 10.5.4 to before version 20.2.5, OpenOLAT's OpenID Connect implicit flow implementation does not verify JWT signatu…
- CVE-2026-32072MEDIUMCVSS 6.2EG 6.22026-04-14
Improper authentication in Windows Active Directory allows an unauthorized attacker to perform spoofing locally.
- CVE-2026-32136CRITICALCVSS 9.8EG 9.82026-03-11
AdGuard Home is a network-wide software for blocking ads and tracking. Prior to 0.107.73, an unauthenticated remote attacker can bypass all authentication in AdGuardHome by sending an HTTP/1.1 request that requests an upgrade to HTTP/2 cle…
- CVE-2026-32173HIGHCVSS 7.5EG 8.62026-04-03
Improper authentication in Azure SRE Agent allows an unauthorized attacker to disclose information over a network.
- CVE-2026-32174HIGHCVSS 7.7EG 7.72026-06-18
Improper authentication in Azure Bot Service allows an authorized attacker to elevate privileges over a network.
- CVE-2026-3224CRITICALCVSS 9.8EG 9.82026-03-03
Authentication bypass in the Microsoft Entra ID (Azure AD) authentication mode in Devolutions Server 2025.3.15.0 and earlier allows an unauthenticated user to authenticate as an arbitrary Entra ID user via a forged JSON Web Token (JWT).
- CVE-2026-32246HIGHCVSS 7.1EG 7.12026-03-12
Tinyauth is an authentication and authorization server. Prior to 5.0.3, the OIDC authorization endpoint allows users with a TOTP-pending session (password verified, TOTP not yet completed) to obtain authorization codes. An attacker who kno…
- CVE-2026-32253CRITICALCVSS 9.8EG 9.82026-05-22
Sunshine is a self-hosted game stream host for Moonlight. In versions prior to 2026.516.143833, the client-certificate authentication can be bypassed because of how OpenSSL verification results are handled. In src/crypto.cpp, the custom ve…
- CVE-2026-32305MEDIUMCVSS 5.3EG 5.32026-03-20
Traefik is an HTTP reverse proxy and load balancer. Versions 2.11.40 and below, 3.0.0-beta1 through 3.6.11, and 3.7.0-ea.1 are vulnerable to mTLS bypass through the TLS SNI pre-sniffing logic related to fragmented ClientHello packets. When…
Map vulnerabilities like CWE-287 to your infrastructure
EchelonGraph correlates every CVE — across CWE-287 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →