VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (5,090)

page 162 of 255
  • CVE-2026-57175MedSep 24, 2026
    risk 0.35cvss 6.4epss 0.00

    Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the SAML backend accepted SAML responses on the Assertion Consumer Service endpoint without verifying that they matched a previously issued `AuthnRequest`. Applications using SAML…

  • CVE-2026-19273MedSep 14, 2026
    risk 0.35cvss 5.4epss 0.00

    IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.6_2, 6.2.1.0 - 6.2.1.2, 6.2.2.0 - 6.2.2.1 and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.6_2, 6.2.1.0 - 6.2.1.2, 6.2.2.0 - 6.2.2.1 Standard Edition could allow a remote authenticated attacker to bypass security restrictions…

  • CVE-2026-17628MedSep 14, 2026
    risk 0.35cvss 5.4epss 0.00

    IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to change the password of an account due to improper authentication.

  • CVE-2026-54176MedSep 14, 2026
    risk 0.35cvss 6.5epss 0.01

    backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. From 6.0.0 until 6.8.14 and 7.0.38, MyAccountController::postAccountInfoForm at POST /admin/edit-account-info…

  • CVE-2026-16892MedSep 4, 2026
    risk 0.35cvss 5.4epss 0.00

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper authentication during service-name matching.

  • CVE-2026-84840MedSep 2, 2026
    risk 0.35cvss 6.5epss 0.01

    A vulnerability was identified in tsi-coop tsi-dpdp-cms up to 0.5.0. This affects an unknown part of the file InterceptingFilter.java of the component Bootstrap Setup Endpoint. The manipulation leads to missing authentication. The attack can be initiated remotely. The exploit is…

  • CVE-2026-73733MedSep 1, 2026
    risk 0.35cvss 5.4epss 0.00

    Authentication bypasses in the API of HPE Networking Fabric Composer could allow an authenticated low privilege operator user to circumvent existing authentication controls. Successful exploitation could allow an attacker to retain limited access to the affected system after…

  • CVE-2025-15671MedAug 21, 2026
    risk 0.35cvss 5.4epss 0.00

    The Welcart e-Commerce WordPress plugin before 2.12.1 does not regenerate the session identifier on authentication and sets the session identifier from a user-supplied request parameter, allowing an unauthenticated attacker to fixate a shop member's session and take over their…

  • CVE-2026-74240MedAug 14, 2026
    risk 0.35cvss 5.4epss 0.00

    A flaw was found in Red Hat Quay's JWT (JSON Web Token) validation for federated robot accounts and single sign-on (SSO) authentication. Multiple issues related to audience verification and the enforcement of `azp` and `sub` claims were identified. These flaws could allow an…

  • CVE-2026-18960MedAug 10, 2026
    risk 0.35cvss 5.4epss 0.00

    The Block User Account WordPress plugin before 2.0.1 does not enforce its account block on every authentication path, allowing a blocked user who holds an application password created before the block to retain their full role-level read and write access through the REST API.

  • CVE-2026-18651MedAug 3, 2026
    risk 0.35cvss 5.4epss 0.00

    A flaw was found in 389 Directory Server. During SASL PLAIN authentication, the server installs connection-level bind credentials before performing the account-lock check. If the account is subsequently found to be locked, the bind is reported as failed to the client, but the…

  • CVE-2026-56312MedJul 10, 2026
    risk 0.35cvss 6.5epss 0.00

    Capgo before 12.128.2 contains an improper validation vulnerability in the accept_invitation endpoint that creates user accounts before captcha validation is enforced. Attackers can bypass captcha protection by sending POST requests with invalid captcha tokens to create unwanted…

  • CVE-2026-14714MedJul 5, 2026
    risk 0.35cvss 6.5epss 0.01

    A weakness has been identified in zhayujie chatgpt-on-wechat CowAgent 2.1.0. This issue affects the function verify_server of the file channel/wechatmp/common.py of the component wx Endpoint. This manipulation of the argument wechatmp_token causes missing authentication. The…

  • CVE-2026-58029MedJul 1, 2026
    risk 0.35cvss 6.5epss 0.00

    Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Api/ApiChangeAuthenticationData.Php, includes/Api/ApiLinkAccount.Php, includes/Api/ApiRemoveAuthenticationData.Php, includes/Specials/SpecialLinkAccounts.Php,…

  • CVE-2026-55955MedJun 29, 2026
    risk 0.35cvss 6.5epss 0.00

    Improper Authentication vulnerability in Apache Tomcat allowed a replay attack against the EncryptionInterceptor in the cluster component. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.13 through 9.0.18, from 8.5.38…

  • CVE-2026-55962MedJun 25, 2026
    risk 0.35cvss 6.5epss 0.00

    TLS 1.3 post-handshake authentication (PHA) issue where a server could accept a client's Finished message without the client having sent a Certificate and CertificateVerify. The post-handshake-auth exemption that allows an empty/absent peer certificate was only intended for the…

  • CVE-2026-39969MedMay 22, 2026
    risk 0.35cvss 6.5epss 0.00

    TypeBot is a chatbot builder tool. In versions 3.16.0 and prior, the WhatsApp Cloud API webhook endpoint (POST /v1/workspaces/{workspaceId}/whatsapp/{credentialsId}/webhook) does not verify the x-hub-signature-256 HMAC signature included by Meta in every webhook delivery. The…

  • CVE-2026-7714MedMay 4, 2026
    risk 0.35cvss 6.5epss 0.01

    A flaw has been found in crocodilestick Calibre-Web-Automated up to 4.0.6. Affected by this issue is some unknown functionality of the file cps/cwa_functions.py of the component Admin Endpoint. This manipulation causes missing authentication. It is possible to initiate the…

  • CVE-2026-41081MedApr 27, 2026
    risk 0.35cvss 6.5epss 0.00

    Improper Handling of TLS Client Authentication Failure Leading to Anonymous Principal Assignment in Apache Storm Versions Affected: up to 2.8.7 Description: When TLS transport is enabled in Apache Storm without requiring client certificate authentication (the default…

  • CVE-2026-40910MedApr 21, 2026
    risk 0.35cvss 6.5epss 0.00

    frp is a fast reverse proxy. From 0.43.0 to 0.68.0, frp contains an authentication bypass in the HTTP vhost routing path when routeByHTTPUser is used as part of access control. In proxy-style requests, the routing logic uses the username from Proxy-Authorization to select the…