VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (4,804)

page 198 of 241
  • CVE-2026-50365HigJul 14, 2026
    risk 0.00cvss 8.0epss 0.00

    Improper authentication in Windows RPC API allows an unauthorized attacker to elevate privileges over an adjacent network.

  • CVE-2026-57107HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges locally.

  • CVE-2026-56185MedJul 14, 2026
    risk 0.00cvss 6.5epss 0.01

    Improper authentication in Windows Admin Center allows an authorized attacker to disclose information over a network.

  • CVE-2026-56169HigJul 14, 2026
    risk 0.00cvss 8.1epss 0.01

    Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-50338HigJul 14, 2026
    risk 0.00cvss 8.2epss 0.00

    Improper authentication in Azure Spring Apps allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-22099HigJul 13, 2026
    risk 0.00cvss epss 0.00

    The charging station does not require authentication for Bluetooth commands to perform actions. The functionality exposed includes sensitive information leakage, triggering reboots, or pushing a firmware update URL.

  • CVE-2026-15557HigJul 13, 2026
    risk 0.00cvss 7.3epss 0.00

    A weakness has been identified in waooAI waoowaoo up to 0.4.1. Affected by this vulnerability is the function getInternalTaskSession/getAuthSession/requireUserAuth/requireProjectAuth/requireProjectAuthLight in the library src/lib/api-auth.ts of the component Internal Task Header…

  • CVE-2026-15542HigJul 13, 2026
    risk 0.00cvss 7.3epss 0.00

    A vulnerability has been found in will-moss Isaiah up to 1.36.9. This affects an unknown function of the file app/main.go of the component Websocket Connection Authentication. The manipulation leads to improper authentication. The attack can be initiated remotely. The pull…

  • CVE-2026-15491HigJul 12, 2026
    risk 0.00cvss 7.3epss 0.00

    A weakness has been identified in RafyMrX TOKO-ONLINE-ROTI up to ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99. This affects an unknown part. This manipulation causes missing authentication. The attack is possible to be carried out remotely. This product adopts a rolling release…

  • CVE-2026-55377HigJul 10, 2026
    risk 0.00cvss 8.1epss 0.00

    Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 1.41.0, Logto's Account Center step-up check accepted any active verification record that belonged to the current user and had isVerified === true. A WebAuthn registration verification record for…

  • CVE-2026-59151CriJul 10, 2026
    risk 0.00cvss 9.6epss 0.00

    Prowler is a cloud security platform. Prior to 5.30.3, Prowler's SAML authentication flow trusted the email domain asserted in a SAMLResponse when deciding which tenant should receive the final token, and the ACS finish logic in api/src/backend/api/v1/views.py recalculated the…

  • CVE-2026-56666MedJul 10, 2026
    risk 0.00cvss 4.8epss 0.00

    ZITADEL is an open source identity management platform. Prior to 4.15.3, ZITADEL's external identity provider handler checks that the local user's email is verified but does not verify that the external IdP confirmed ownership of the same email before auto-linking by email,…

  • CVE-2026-56675HigJul 10, 2026
    risk 0.00cvss 8.3epss 0.00

    9Router is an AI router & token saver. Prior to 0.5.2, 9router treats loopback requests as trusted and allows /v1/* access without an API key, so a same-host reverse proxy that forwards public traffic to the backend through 127.0.0.1 causes src/dashboardGuard.js to misclassify…

  • CVE-2026-56312MedJul 10, 2026
    risk 0.00cvss 6.5epss 0.00

    Capgo before 12.128.2 contains an improper validation vulnerability in the accept_invitation endpoint that creates user accounts before captcha validation is enforced. Attackers can bypass captcha protection by sending POST requests with invalid captcha tokens to create unwanted…

  • CVE-2026-12598HigJul 10, 2026
    risk 0.00cvss 8.1epss 0.00

    The LoginPress Pro plugin for WordPress is vulnerable to authentication bypass in versions up to and including 6.2.3 via the Spotify Social Login addon. This is due to the loginpress_on_spotify_login() function trusting the unverified 'email' field returned by Spotify's /v1/me…

  • CVE-2026-12597HigJul 10, 2026
    risk 0.00cvss 8.1epss 0.00

    The LoginPress Pro plugin for WordPress is vulnerable to Authentication Bypass via the GitHub OAuth callback in versions up to, and including, 6.2.3. The vulnerability exists in the loginpress_on_github_login() function, which blindly trusts the first element…

  • CVE-2026-12595HigJul 10, 2026
    risk 0.00cvss 8.1epss 0.00

    The LoginPress Pro plugin for WordPress is vulnerable to Authentication Bypass via Unverified OAuth Email in all versions up to and including 6.2.3. The vulnerability exists in the loginpress_on_discord_login() Discord OAuth callback handler, which accepts the email field…

  • CVE-2026-15192MedJul 9, 2026
    risk 0.00cvss 6.5epss 0.01

    A vulnerability has been found in mettle sendportal up to 3.0.1. This issue affects the function sendgrid/postmark/postal/mailjet of the component APIv1 Webhooks. The manipulation leads to missing authentication. The attack is possible to be carried out remotely. The exploit has…

  • CVE-2026-59208MedJul 9, 2026
    risk 0.00cvss 6.8epss 0.00

    n8n is an open source workflow automation platform. Prior to 2.27.4 and from 2.28.0 prior to 2.28.1, n8n instances configured with more than one trusted token-exchange issuer resolved external identities to local accounts using only the JWT sub claim and ignored the iss claim,…

  • CVE-2026-55761MedJul 8, 2026
    risk 0.00cvss 5.9epss 0.00

    Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. In versions 2.39.0 through 2.39.3 and 2.40.0 until 2.43.0, unauthenticated restore and administrator…