VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (5,090)

page 118 of 255
  • CVE-2026-88895HigSep 10, 2026
    risk 0.47cvss 7.2epss 0.01

    CyberPanel before 3.0.5 fails to enforce two-factor authentication on API endpoints, allowing attackers to bypass TOTP requirements using password-derived tokens. Attackers who obtain an administrator's password can derive API tokens and perform administrative operations or…

  • CVE-2026-87922HigSep 9, 2026
    risk 0.47cvss 7.3epss 0.01

    A security flaw has been discovered in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. Affected by this vulnerability is the function DBOperation.addCategory of the file includes/process.php of the component AJAX Backend. The manipulation of…

  • CVE-2026-86669HigSep 8, 2026
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was detected in aircheng-org iWebShop-5 up to 5.15. This affects the function Login of the file controllers/systemseller.php. Performing a manipulation of the argument Name results in improper authentication. It is possible to initiate the attack remotely. The…

  • CVE-2026-86306HigSep 7, 2026
    risk 0.47cvss 7.3epss 0.01

    A weakness has been identified in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. This affects an unknown part of the file App/Home/Model/UserModel.class.php of the component Cookie Helper. Executing a manipulation of the argument…

  • CVE-2026-86300HigSep 7, 2026
    risk 0.47cvss 7.3epss 0.01

    A flaw has been found in Tenda AC9 15.03.05.14. This impacts the function R7WebsSecurityHandler of the component Web Management. This manipulation causes improper authentication. The attack may be initiated remotely. The exploit has been published and may be used.

  • CVE-2026-86292HigSep 7, 2026
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was detected in SourceCodester Simple Traffic Offense System 1.0. Affected is an unknown function of the file saveuser.php of the component User Creation. Performing a manipulation of the argument position results in missing authentication. The attack may be…

  • CVE-2026-86214HigSep 6, 2026
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was determined in Mstfakts College-Management-System. Impacted is an unknown function of the file Front-end/login.php. This manipulation of the argument email causes improper authentication. It is possible to initiate the attack remotely. The exploit has been…

  • CVE-2026-85702HigSep 4, 2026
    risk 0.47cvss 7.3epss 0.01

    A security vulnerability has been detected in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. Affected is the function _conversation of the file server/backend.py of the component Backend Conversation API. Such manipulation of the argument model leads…

  • CVE-2026-84423HigSep 1, 2026
    risk 0.47cvss 7.3epss 0.01

    A vulnerability has been found in Casdoor up to 4.0.0. This affects an unknown function of the file controllers/resource.go of the component upload-resource API. Such manipulation leads to missing authentication. It is possible to launch the attack remotely. The exploit has been…

  • CVE-2026-82919HigAug 31, 2026
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was identified in cu silicon up to 0.1.5. Affected by this vulnerability is the function create_app of the file views.py of the component edit Endpoint. Such manipulation leads to missing authentication. The attack may be performed from remote. The exploit is…

  • CVE-2026-81202HigAug 26, 2026
    risk 0.47cvss 7.3epss 0.01

    A flaw has been found in itsourcecode Payroll System 1.0. The impacted element is the function create/read/update/delete of the file ajax.php of the component CRUD Operation Handler. Executing a manipulation of the argument action can lead to missing authentication. The attack…

  • CVE-2026-17099HigAug 13, 2026
    risk 0.47cvss 7.3epss 0.00

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to improper authentication.

  • CVE-2026-20885HigAug 11, 2026
    risk 0.47cvss 7.2epss 0.00

    Improper authentication in the Intel(R) TDX module for some Intel(R) platforms within Ring 0: Trust Domain may allow an information disclosure and escalation of privilege. System software adversary with a privileged user combined with a high complexity attack may enable…

  • CVE-2026-19342HigAug 9, 2026
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was detected in code-projects Task Management System 1.0. Affected is an unknown function of the file /index.php of the component Login. Performing a manipulation of the argument Password results in improper authentication. The attack is possible to be carried…

  • CVE-2026-18990HigAug 6, 2026
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was detected in letta-ai LettaBot 0.2.0. Impacted is an unknown function of the file src/api/server.ts of the component API Status Route. The manipulation results in missing authentication. The attack may be performed from remote. The exploit is now public and…

  • CVE-2026-18810HigAug 4, 2026
    risk 0.47cvss 7.3epss 0.01

    A security vulnerability has been detected in H3C NX15 V100R017. Impacted is an unknown function of the file /api/wizard/networkSetup. Such manipulation leads to missing authentication. The attack may be performed from remote. The vendor was contacted early about this disclosure.

  • CVE-2026-67327HigAug 1, 2026
    risk 0.47cvss 8.3epss 0.00

    better-auth versions >= 1.1.3 and < 1.6.22 (and pre-release versions >= 1.7.0-beta.0 and < 1.7.0-beta.10) are vulnerable to account takeover via pre-account hijacking on magic-link and email-OTP sign-in when open email/password registration is enabled. An attacker registers an…

  • CVE-2026-53516HigJul 15, 2026
    risk 0.47cvss 8.3epss 0.00

    Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, Better Auth's OAuth callback auto-link gate in handleOAuthUserInfo accepts implicit account linking when the OAuth provider asserts email_verified: true without requiring the local user…

  • CVE-2026-56675HigJul 10, 2026
    risk 0.47cvss 8.3epss 0.01

    9Router is an AI router & token saver. Prior to 0.5.2, 9router treats loopback requests as trusted and allows /v1/* access without an API key, so a same-host reverse proxy that forwards public traffic to the backend through 127.0.0.1 causes src/dashboardGuard.js to misclassify…

  • CVE-2026-10845HigJun 22, 2026
    risk 0.47cvss 7.3epss 0.00

    IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to bypass authentication and gain unauthorized access to JAX-WS applications.