CWE-287
Improper Authentication
Description
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94
CVEs mapped to this weakness (5,056)
page 210 of 253| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-16209 | Hig | 0.00 | 7.3 | 0.01 | Jul 19, 2026 | A vulnerability has been found in Gerapy up to 0.9.13. The impacted element is an unknown function of the file gerapy/server/core/views.py of the component Project Upload Endpoint. Such manipulation leads to missing authentication. The attack may be launched remotely. The… | ||
| CVE-2026-16198 | Med | 0.00 | 5.6 | 0.01 | Jul 19, 2026 | A vulnerability was detected in Sipeed PicoClaw up to 0.2.9. The impacted element is an unknown function of the file web/backend/middleware/access_control.go of the component First Run Setup. Performing a manipulation of the argument allowed_cidrs results in authentication… | ||
| CVE-2026-16083 | Med | 0.00 | 5.3 | 0.01 | Jul 18, 2026 | A security flaw has been discovered in Sipeed PicoClaw up to 0.2.9. This affects the function webhook.ParseRequest of the file pkg/channels/line/line.go of the component LINE Webhook. The manipulation results in authentication bypass by capture-replay. The attack may be launched… | ||
| CVE-2026-16076 | Med | 0.00 | 6.3 | 0.01 | Jul 18, 2026 | A vulnerability has been found in AstrBotDevs AstrBot up to 4.25.5. This issue affects the function OpenApiRoute.chat_send of the file astrbot/dashboard/routes/open_api.py of the component API. Such manipulation of the argument Username leads to authentication bypass by… | ||
| CVE-2026-16015 | Med | 0.00 | 6.3 | 0.01 | Jul 17, 2026 | A vulnerability was determined in poco-ai poco-claw up to 0.5.4. This vulnerability affects the function create_task of the file executor_manager/app/api/v1/tasks.py of the component executor_manager API. Executing a manipulation can lead to missing authentication. The exploit… | ||
| CVE-2026-12585 | Hig | 0.00 | 8.1 | 0.00 | Jul 16, 2026 | The Abandoned Cart Lite for WooCommerce WordPress plugin before 6.8.2 does not protect the integrity of its cart-recovery tokens or bind them to the requesting account, allowing unauthenticated attackers to forge a recovery link that logs them in as another user when the… | ||
| CVE-2026-12492 | Cri | 0.00 | 9.8 | 0.01 | Jul 16, 2026 | The Happy Coders OTP Login for WooCommerce WordPress plugin before 2.8 does not verify that a one-time password was actually validated before authenticating a user based on a supplied identifier, allowing unauthenticated attackers to log in as any existing user, including… | ||
| CVE-2026-55652 | Cri | 0.00 | 9.8 | 0.01 | Jul 15, 2026 | Wekan is open source kanban built with Meteor. Prior to 9.46, header-login with HEADER_LOGIN_TRUSTED_IPS uses getRequestIp() in server/lib/headerLoginAuth.js to trust the client-supplied X-Forwarded-For header before the real socket address, allowing an unauthenticated attacker… | ||
| CVE-2026-52893 | Cri | 0.00 | — | 0.00 | Jul 15, 2026 | Wekan is open source kanban built with Meteor. Prior to 9.32, the Wekan Accounts.onCreateUser hook in server/models/users.js merges OIDC logins into existing accounts when the OIDC email or username matches an existing Wekan user, without verifying ownership or checking… | ||
| CVE-2026-46485 | Hig | 0.00 | 8.2 | 0.00 | Jul 15, 2026 | Dashy is a self-hostable personal dashboard. Prior to 4.0.8, Dashy deployments using OIDC can allow unauthenticated users or non-admin authenticated users to write changes to the main config.yaml through the config-saving functionality despite configured permissions, allowing… | ||
| CVE-2026-47159 | Med | 0.00 | — | 0.01 | Jul 15, 2026 | Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's SSO discovery and pre-validation flow returned organization-related SSO metadata including organizationIdentifier values for arbitrary email addresses and allowed a valid pre-validation… | ||
| CVE-2026-44986 | Cri | 0.00 | 9.9 | 0.01 | Jul 15, 2026 | Penpot is an open-source design tool for design and code collaboration. Prior to 2.14.5, Penpot exposed teams_invitations.clj invitation tokens from create-team-invitations, embedded an existing profile id in auth.clj prepare-register-profile, and had auth.clj register-profile… | ||
| CVE-2026-61436 | Hig | 0.00 | 8.6 | 0.01 | Jul 15, 2026 | PraisonAI before 4.6.78 fails to verify Svix webhook signatures in AgentMail webhook mode, allowing unauthenticated attackers to forge message.received events. Attackers can send crafted JSON payloads to the webhook endpoint to invoke configured agents with arbitrary sender… | ||
| CVE-2026-61435 | Hig | 0.00 | 8.2 | 0.01 | Jul 15, 2026 | PraisonAI before 4.6.78 contains an authentication bypass in the Call API agent invocation endpoints (src/praisonai/praisonai/api/agent_invoke.py) when PRAISONAI_CALL_AUTH=disabled is configured. The safeguard intended to restrict the disabled-auth opt-out to localhost binding… | ||
| CVE-2026-56353 | Med | 0.00 | 4.8 | 0.00 | Jul 15, 2026 | n8n contains an authentication bypass in the Chat Trigger node when configured with n8n User Auth (a non-default configuration). In affected releases — before 1.123.22, the 2.0.0 through 2.9.2 line, and 2.10.0 — the authentication check on the Chat Trigger webhook endpoint… | ||
| CVE-2026-12281 | Hig | 0.00 | 8.1 | 0.00 | Jul 15, 2026 | The Shibboleth WordPress plugin before 2.5.4 does not fail closed when its HTTP header identity mode is enabled without an anti-spoofing key, treating any request that carries identity headers as an authenticated session without verifying them. On a deployment where untrusted… | ||
| CVE-2026-5270 | Cri | 0.00 | 9.8 | 0.01 | Jul 14, 2026 | An authentication bypass vulnerability exists in certain releases of Ciena Navigator Network Control Suite (NCS), Manage Control Plan (MCP), and Blue Planet products. The issue is caused by improper handling of HTTP request paths and headers, which allows an unauthenticated… | ||
| CVE-2026-50365 | Hig | 0.00 | 8.0 | 0.01 | Jul 14, 2026 | Improper authentication in Windows RPC API allows an unauthorized attacker to elevate privileges over an adjacent network. | ||
| CVE-2026-57107 | Hig | 0.00 | 7.8 | 0.00 | Jul 14, 2026 | Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-56185 | Med | 0.00 | 6.5 | 0.01 | Jul 14, 2026 | Improper authentication in Windows Admin Center allows an authorized attacker to disclose information over a network. |
- risk 0.00cvss 7.3epss 0.01
A vulnerability has been found in Gerapy up to 0.9.13. The impacted element is an unknown function of the file gerapy/server/core/views.py of the component Project Upload Endpoint. Such manipulation leads to missing authentication. The attack may be launched remotely. The…
- risk 0.00cvss 5.6epss 0.01
A vulnerability was detected in Sipeed PicoClaw up to 0.2.9. The impacted element is an unknown function of the file web/backend/middleware/access_control.go of the component First Run Setup. Performing a manipulation of the argument allowed_cidrs results in authentication…
- risk 0.00cvss 5.3epss 0.01
A security flaw has been discovered in Sipeed PicoClaw up to 0.2.9. This affects the function webhook.ParseRequest of the file pkg/channels/line/line.go of the component LINE Webhook. The manipulation results in authentication bypass by capture-replay. The attack may be launched…
- risk 0.00cvss 6.3epss 0.01
A vulnerability has been found in AstrBotDevs AstrBot up to 4.25.5. This issue affects the function OpenApiRoute.chat_send of the file astrbot/dashboard/routes/open_api.py of the component API. Such manipulation of the argument Username leads to authentication bypass by…
- risk 0.00cvss 6.3epss 0.01
A vulnerability was determined in poco-ai poco-claw up to 0.5.4. This vulnerability affects the function create_task of the file executor_manager/app/api/v1/tasks.py of the component executor_manager API. Executing a manipulation can lead to missing authentication. The exploit…
- risk 0.00cvss 8.1epss 0.00
The Abandoned Cart Lite for WooCommerce WordPress plugin before 6.8.2 does not protect the integrity of its cart-recovery tokens or bind them to the requesting account, allowing unauthenticated attackers to forge a recovery link that logs them in as another user when the…
- risk 0.00cvss 9.8epss 0.01
The Happy Coders OTP Login for WooCommerce WordPress plugin before 2.8 does not verify that a one-time password was actually validated before authenticating a user based on a supplied identifier, allowing unauthenticated attackers to log in as any existing user, including…
- risk 0.00cvss 9.8epss 0.01
Wekan is open source kanban built with Meteor. Prior to 9.46, header-login with HEADER_LOGIN_TRUSTED_IPS uses getRequestIp() in server/lib/headerLoginAuth.js to trust the client-supplied X-Forwarded-For header before the real socket address, allowing an unauthenticated attacker…
- risk 0.00cvss —epss 0.00
Wekan is open source kanban built with Meteor. Prior to 9.32, the Wekan Accounts.onCreateUser hook in server/models/users.js merges OIDC logins into existing accounts when the OIDC email or username matches an existing Wekan user, without verifying ownership or checking…
- risk 0.00cvss 8.2epss 0.00
Dashy is a self-hostable personal dashboard. Prior to 4.0.8, Dashy deployments using OIDC can allow unauthenticated users or non-admin authenticated users to write changes to the main config.yaml through the config-saving functionality despite configured permissions, allowing…
- risk 0.00cvss —epss 0.01
Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's SSO discovery and pre-validation flow returned organization-related SSO metadata including organizationIdentifier values for arbitrary email addresses and allowed a valid pre-validation…
- risk 0.00cvss 9.9epss 0.01
Penpot is an open-source design tool for design and code collaboration. Prior to 2.14.5, Penpot exposed teams_invitations.clj invitation tokens from create-team-invitations, embedded an existing profile id in auth.clj prepare-register-profile, and had auth.clj register-profile…
- risk 0.00cvss 8.6epss 0.01
PraisonAI before 4.6.78 fails to verify Svix webhook signatures in AgentMail webhook mode, allowing unauthenticated attackers to forge message.received events. Attackers can send crafted JSON payloads to the webhook endpoint to invoke configured agents with arbitrary sender…
- risk 0.00cvss 8.2epss 0.01
PraisonAI before 4.6.78 contains an authentication bypass in the Call API agent invocation endpoints (src/praisonai/praisonai/api/agent_invoke.py) when PRAISONAI_CALL_AUTH=disabled is configured. The safeguard intended to restrict the disabled-auth opt-out to localhost binding…
- risk 0.00cvss 4.8epss 0.00
n8n contains an authentication bypass in the Chat Trigger node when configured with n8n User Auth (a non-default configuration). In affected releases — before 1.123.22, the 2.0.0 through 2.9.2 line, and 2.10.0 — the authentication check on the Chat Trigger webhook endpoint…
- risk 0.00cvss 8.1epss 0.00
The Shibboleth WordPress plugin before 2.5.4 does not fail closed when its HTTP header identity mode is enabled without an anti-spoofing key, treating any request that carries identity headers as an authenticated session without verifying them. On a deployment where untrusted…
- risk 0.00cvss 9.8epss 0.01
An authentication bypass vulnerability exists in certain releases of Ciena Navigator Network Control Suite (NCS), Manage Control Plan (MCP), and Blue Planet products. The issue is caused by improper handling of HTTP request paths and headers, which allows an unauthenticated…
- risk 0.00cvss 8.0epss 0.01
Improper authentication in Windows RPC API allows an unauthorized attacker to elevate privileges over an adjacent network.
- risk 0.00cvss 7.8epss 0.00
Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges locally.
- risk 0.00cvss 6.5epss 0.01
Improper authentication in Windows Admin Center allows an authorized attacker to disclose information over a network.