VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (4,804)

page 160 of 241
  • CVE-2026-4583MedMar 23, 2026
    risk 0.33cvss 5.0epss 0.00

    A vulnerability was detected in Shenzhen HCC Technology MPOS M6 PLUS 1V.31-N. Affected by this issue is some unknown functionality of the component Bluetooth Handler. Performing a manipulation results in authentication bypass by capture-replay. The attack must originate from the…

  • CVE-2026-4582MedMar 23, 2026
    risk 0.33cvss 5.0epss 0.00

    A security vulnerability has been detected in Shenzhen HCC Technology MPOS M6 PLUS 1V.31-N. Affected by this vulnerability is an unknown functionality of the component Bluetooth. Such manipulation leads to missing authentication. The attack must be carried out from within the…

  • CVE-2026-2756MedMar 21, 2026
    risk 0.33cvss 5.0epss 0.00

    A security vulnerability has been detected in OmniPEMF NeoRhythm up to 20260308. This affects an unknown function of the component BLE Interface. Such manipulation leads to missing authentication. The attack can only be initiated within the local network. This attack is…

  • CVE-2025-62349MedJan 30, 2026
    risk 0.33cvss 6.2epss 0.00

    Salt contains an authentication protocol version downgrade weakness that can allow a malicious minion to bypass newer authentication/security features by using an older request payload format, enabling minion impersonation and circumventing protections introduced in response to…

  • CVE-2025-67859MedJan 14, 2026
    risk 0.33cvss epss 0.00

    A Improper Authentication vulnerability in TLP allows local users to arbitrarily control the power profile in use as well as the daemon’s log settings.This issue affects TLP: from 1.9 before 1.9.1.

  • CVE-2025-25452MedMar 6, 2025
    risk 0.33cvss 5.1epss 0.00

    An issue in TAAGSOLUTIONS GmbH MyTaag v.2024-11-24 and before allows a remote attacker to escalate privileges via the "/user" endpoint

  • CVE-2025-25451MedMar 6, 2025
    risk 0.33cvss 5.1epss 0.00

    An issue in TAAGSOLUTIONS GmbH MyTaag v.2024-11-24 and before allows a physically proximate attacker to escalate privileges via the "2fa_authorized" Local Storage key

  • CVE-2025-25450MedMar 6, 2025
    risk 0.33cvss 5.1epss 0.00

    An issue in TAAGSOLUTIONS GmbH MyTaag v.2024-11-24 and before allows a remote attacker to escalate privileges via the deactivation of the activated second factor to the /session endpoint

  • CVE-2024-22258MedMar 20, 2024
    risk 0.33cvss 6.1epss 0.01

    Spring Authorization Server versions 1.0.0 - 1.0.5, 1.1.0 - 1.1.5, 1.2.0 - 1.2.2 and older unsupported versions are susceptible to a PKCE Downgrade Attack for Confidential Clients. Specifically, an application is vulnerable when a Confidential Client uses PKCE for the…

  • CVE-2023-21307MedOct 30, 2023
    risk 0.33cvss 5.0epss 0.00

    In Bluetooth, there is a possible way for a paired Bluetooth device to access a long term identifier for an Android device due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for…

  • CVE-2023-30725MedSep 6, 2023
    risk 0.33cvss 5.1epss 0.00

    Improper authentication in LocalProvier of Gallery prior to version 14.5.01.2 allows attacker to access the data in content provider.

  • CVE-2023-21487MedMay 4, 2023
    risk 0.33cvss 5.1epss 0.00

    Improper access control vulnerability in Telephony framework prior to SMR May-2023 Release 1 allows local attackers to change a call setting.

  • CVE-2023-21484MedMay 4, 2023
    risk 0.33cvss 5.1epss 0.00

    Improper access control vulnerability in AppLock prior to SMR May-2023 Release 1 allows local attackers without proper permission to execute a privileged operation.

  • CVE-2022-46146MedNov 29, 2022
    risk 0.33cvss 6.2epss 0.01

    Prometheus Exporter Toolkit is a utility package to build exporters. Prior to versions 0.7.2 and 0.8.2, if someone has access to a Prometheus web.yml file and users' bcrypted passwords, they can bypass security by poisoning the built-in authentication cache. Versions 0.7.2 and…

  • CVE-2018-25043MedJun 17, 2022
    risk 0.33cvss 5.0epss 0.01

    A vulnerability classified as critical was found in uTorrent. This vulnerability affects unknown code of the component PRNG. The manipulation leads to weak authentication. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. It is…

  • CVE-2018-14637MedNov 30, 2018
    risk 0.33cvss 6.1epss 0.01

    The SAML broker consumer endpoint in Keycloak before version 4.6.0.Final ignores expiration conditions on SAML assertions. An attacker can exploit this vulnerability to perform a replay attack.

  • CVE-2018-1672MedOct 1, 2018
    risk 0.33cvss 5.0epss 0.01

    IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 may fail to set the correct user context in certain impersonation scenarios, which can allow a user to act with the identity of a different user. IBM X-Force ID: 144958.

  • CVE-2026-56080MedJun 19, 2026
    risk 0.32cvss 4.9epss 0.01

    Capgo before 12.128.2 contains a flaw in the Enforce Password Policy feature: after a Super Admin enables the policy and successfully changes their password to a compliant one, the backend does not update the password-compliance state. As a result, the backend continues to treat…

  • CVE-2026-9084MedMay 20, 2026
    risk 0.32cvss epss 0.00

    MISP’s OIDC authentication plugin allowed automatic linking of an OIDC identity to an existing local user account based on the email claim when the local account had no stored sub value. Under insecure or untrusted IdP configurations where email ownership is not enforced, an…

  • CVE-2026-32879MedMar 23, 2026
    risk 0.32cvss 4.9epss 0.00

    New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Starting in version 0.10.0, a logic flaw in the universal secure verification flow allows an authenticated user with a registered passkey to satisfy secure verification…