VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (5,090)

page 172 of 255
  • CVE-2016-1307MedFeb 7, 2016
    risk 0.35cvss 5.4epss 0.01

    The Openfire server in Cisco Finesse Desktop 10.5(1) and 11.0(1) and Unified Contact Center Express 10.6(1) has a hardcoded account, which makes it easier for remote attackers to obtain access via an XMPP session, aka Bug ID CSCuw79085.

  • CVE-2026-101004MedSep 28, 2026
    risk 0.34cvss 5.3epss 0.01

    A security vulnerability has been detected in notionnext-org NotionNext up to 4.10.10. Affected by this issue is the function cleanCache of the file pages/api/cache.js of the component Authentication Guard. The manipulation of the argument token leads to missing authentication.…

  • CVE-2026-100903MedSep 28, 2026
    risk 0.34cvss 5.3epss 0.00

    A vulnerability was identified in ООО НПО Ритм GEOritm up to 2.45.1. This affects an unknown part of the file /restapi/objects/obj-groups of the component REST API. Such manipulation of the argument objectId leads to missing authentication. The attack can be launched…

  • CVE-2026-93964MedSep 20, 2026
    risk 0.34cvss 5.3epss 0.00

    A vulnerability was detected in NginxProxyManager nginx-proxy-manager up to 2.15.1. This impacts the function internalCertificate.validate of the file backend/internal/certificate.js of the component Validate Route. The manipulation results in missing authentication. The attack…

  • CVE-2026-93984MedSep 19, 2026
    risk 0.34cvss 5.3epss 0.00

    OpenPanel tracking API through 2.3.0 fails to verify client secret cryptographic hash before authorizing revenue events and bot filtering. Attackers with only a public client ID can supply arbitrary dummy secrets to inject forged revenue metrics and bypass bot detection filters.

  • CVE-2026-89093MedSep 19, 2026
    risk 0.34cvss 5.3epss 0.01

    The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to Information Exposure by Spoofing in all versions up to, and including, 2.15.33. This is due to the `is_ai_bot_user()` function identifying privileged internal AI…

  • CVE-2026-85350MedSep 18, 2026
    risk 0.34cvss 5.3epss 0.00

    The UpsellWP WordPress plugin before 2.2.10 does not check that products added to the cart through a Frequently Bought Together campaign belong to that campaign, allowing unauthenticated users to buy arbitrary products at the campaign's discounted price.

  • CVE-2026-19607MedSep 16, 2026
    risk 0.34cvss 5.3epss 0.01

    A flaw was found in the first-broker-login flow of the keycloak-services component. This component handles the initial authentication and account linking when a user logs in via an external identity provider. The issue allows an attacker to register a matching username on an…

  • CVE-2026-86781MedSep 11, 2026
    risk 0.34cvss 5.3epss 0.00

    The SSL Zen — SSL Certificate Installer & HTTPS Redirects WordPress plugin before 4.7.40 does not perform capability or nonce checks on a certificate-file download routine that runs early in the WordPress admin request lifecycle, allowing any authenticated user, including…

  • CVE-2026-82758MedSep 7, 2026
    risk 0.34cvss —epss 0.01

    Improper Authentication vulnerability in ash-project ash_authentication_oauth2_server allows an unauthenticated attacker to register OAuth clients even when Dynamic Client Registration is gated by an initial access token. resolve_secret/3 in AshAuthentication.Oauth2Server…

  • CVE-2026-85701MedSep 4, 2026
    risk 0.34cvss 5.3epss 0.01

    A vulnerability has been found in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. This issue affects the function ChatCompletion.create of the file g4f/__init__.py of the component Authentication Check. Such manipulation leads to missing…

  • CVE-2026-85637MedSep 4, 2026
    risk 0.34cvss 5.3epss 0.01

    A security flaw has been discovered in jofpin trape 1.0.0/2.0. Affected by this issue is the function join_room of the file core/sockets.py of the component Admin Endpoint. The manipulation results in missing authentication. The attack may be launched remotely. The exploit has…

  • CVE-2026-85636MedSep 4, 2026
    risk 0.34cvss 5.3epss 0.01

    A vulnerability was identified in jofpin trape 1.0.0. Affected by this vulnerability is an unknown functionality of the file core/stats.py of the component Login Endpoint. The manipulation leads to missing authentication. The attack may be initiated remotely. The exploit is…

  • CVE-2026-44476MedAug 25, 2026
    risk 0.34cvss —epss 0.01

    Doorkeeper is an OAuth 2 provider for Ruby on Rails. In version 1.9.0, an attacker who knows only a dynamically registered client's client_id, which is public information, can authenticate as that client at the token endpoint and obtain an access token without providing its…

  • CVE-2026-78863MedAug 25, 2026
    risk 0.34cvss 6.3epss 0.01

    A vulnerability was found in liketrek TREK up to 3.0.22. Impacted is the function loginUser of the file server/src/services/authService.ts of the component Pre-2FA mfa_token Handler. The manipulation results in improper authentication. The attack may be performed from remote.…

  • CVE-2026-19709MedAug 19, 2026
    risk 0.34cvss 5.3epss 0.00

    The Membership For WooCommerce WordPress plugin before 3.1.2 does not check that an API consumer secret has actually been generated before comparing it against the one supplied in a request, allowing unauthenticated attackers to reach its REST routes and disclose any user's…

  • CVE-2026-16905MedAug 14, 2026
    risk 0.34cvss 5.3epss 0.00

    IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper authentication.

  • CVE-2026-68760MedAug 12, 2026
    risk 0.34cvss 5.3epss 0.00

    An unauthenticated user may bypass authentication under specific cache conditions.

  • CVE-2026-16282MedAug 8, 2026
    risk 0.34cvss 5.3epss 0.00

    The Appointment Hour Booking WordPress plugin before 1.5.88 does not validate a client-supplied booking price against the server-side configured service price, allowing unauthenticated users to submit an arbitrary final price (including zero or negative) that is stored as the…

  • CVE-2026-14547MedAug 6, 2026
    risk 0.34cvss 5.3epss 0.00

    The Estatik Real Estate Plugin WordPress plugin before 4.3.3 does not properly enforce its anti-spam check or restrict the recipient routing of its property request form, allowing unauthenticated users to send emails to arbitrary recipients with arbitrary subject, body and…