VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (5,090)

page 136 of 255
  • CVE-2018-19937MedDec 31, 2018
    risk 0.43cvss 6.6epss 0.00

    A local, authenticated attacker can bypass the passcode in the VideoLAN VLC media player app before 3.1.5 for iOS by opening a URL and turning the phone.

  • CVE-2018-6686MedJul 27, 2018
    risk 0.43cvss 6.6epss 0.00

    Authentication Bypass vulnerability in TPM autoboot in McAfee Drive Encryption (MDE) 7.1.0 and above allows physically proximate attackers to bypass local security protection via specific set of circumstances.

  • CVE-2017-7562MedJul 26, 2018
    risk 0.43cvss 6.5epss 0.03

    An authentication bypass flaw was found in the way krb5's certauth interface before 1.16.1 handled the validation of client certificates. A remote attacker able to communicate with the KDC could potentially use this flaw to impersonate arbitrary principals under rare and…

  • CVE-2026-62367HigOct 9, 2026
    risk 0.42cvss —epss —

    Vikunja is an open-source self-hosted task management platform. In versions 1.0.0 through 2.3.0, when an administrator enables the per-provider `emailfallback` option on an OpenID Connect provider, Vikunja links an SSO login to a pre-existing local (username+password) account…

  • CVE-2026-100709HigSep 26, 2026
    risk 0.42cvss 7.5epss 0.00

    Froxlor through 2.3.10 stores only a numeric user ID in remembered-2FA tokens (panel_2fa_tokens) without recording the account namespace, and the remembered-token lookup during login is not constrained to the customer or administrator account type. Because customer and…

  • CVE-2026-80218HigSep 17, 2026
    risk 0.42cvss —epss 0.01

    Improper Authentication vulnerability in team-alembic AshAuthentication allows an attacker holding a sign-in token for one authenticated resource to be signed in as a user of a different resource. AshAuthentication.Strategy.Password.SignInWithTokenPreparation.extract_primary_key…

  • CVE-2026-92792HigSep 16, 2026
    risk 0.42cvss 7.5epss 0.01

    OpenNHP through 1.0.2 selects its trusted-execution attestation verifier based on attacker-supplied evidence containing a test_purpose key, causing the FallbackVerifier to execute unconditionally. Attackers can bypass attestation verification by including the test_purpose key in…

  • CVE-2026-81237MedSep 15, 2026
    risk 0.42cvss 6.5epss 0.00

    Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Improper Authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.

  • CVE-2026-47426HigSep 15, 2026
    risk 0.42cvss —epss 0.01

    Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the private_key_jwt client authentication path uses ClientJwksResolverCache without reliably binding a cached jwks_uri resolver and verified assertion to the expected clientID in…

  • CVE-2026-90513MedSep 13, 2026
    risk 0.42cvss 6.5epss 0.01

    A flaw has been found in simalexan api-lambda-send-email-ses up to bda6869aa81371d1e872242e74fe7d953edb818d. This issue affects the function SES.sendEmail of the file template.yml of the component API Gateway Endpoint. This manipulation of the argument…

  • CVE-2026-87924MedSep 9, 2026
    risk 0.42cvss 6.5epss 0.01

    A security vulnerability has been detected in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. This affects an unknown part of the file includes/invoice_bill.php of the component Invoice Generation. Such manipulation of the argument…

  • CVE-2026-79974MedSep 9, 2026
    risk 0.42cvss 6.4epss 0.00

    Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Authentication vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to unauthorized…

  • CVE-2026-80128MedSep 7, 2026
    risk 0.42cvss 6.4epss 0.00

    Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Authentication vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to protection…

  • CVE-2026-86293MedSep 7, 2026
    risk 0.42cvss 6.5epss 0.01

    A flaw has been found in SourceCodester Simple Traffic Offense System 1.0. Affected by this vulnerability is an unknown functionality of the file delete-user.php of the component Deletion Endpoint. Executing a manipulation of the argument ID can lead to missing authentication.…

  • CVE-2026-18056HigSep 6, 2026
    risk 0.42cvss 7.5epss 0.00

    The HivePress Authentication plugin for WordPress is vulnerable to Authentication Bypass via the access_token parameter in all versions up to, and including, 1.1.4. This is due to the authenticate_user function's Facebook authenticator resolving third-party identity by…

  • CVE-2026-82547MedAug 30, 2026
    risk 0.42cvss 6.5epss 0.01

    A vulnerability was found in Linux Foundation Magma 1.9.0. The affected element is an unknown function of the file tasks/amf/amf_fsm.cpp of the component Registration Complete Message Handler. The manipulation results in improper authentication. The attack can be launched…

  • CVE-2026-14216MedAug 26, 2026
    risk 0.42cvss 6.5epss 0.00

    The Booking for Appointments and Events Calendar WordPress plugin before 2.4.7 does not require authentication before processing its pending notification queue, allowing an unauthenticated user to force the dispatch of queued notifications and integration callbacks.

  • CVE-2026-65633HigAug 25, 2026
    risk 0.42cvss —epss 0.01

    Improper Authentication vulnerability in team-alembic AshAuthentication allows purpose-limited JWTs to be replayed as full bearer API credentials when a resource uses stateless bearer-token verification. The bearer-token authentication helper…

  • CVE-2026-78434MedAug 24, 2026
    risk 0.42cvss 6.5epss 0.01

    A flaw has been found in Faveo Helpdesk up to 2.0.3. This impacts the function FormController::post_ticket_reply of the file app/Http/Controllers/Client/helpdesk/FormController.php of the component post-ticket-reply Endpoint. This manipulation causes missing authentication. The…

  • CVE-2026-66908HigAug 24, 2026
    risk 0.42cvss 7.5epss 0.01

    Improper Authentication vulnerability in Apache Camel Platform HTTP Main component. This issue affects Apache Camel: from 4.8.0 before 4.22.0. The camel-main embedded HTTP server can protect its endpoints with JWT authentication, configured through authenticationEnabled…