VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (5,056)

page 211 of 253
  • CVE-2026-56169HigJul 14, 2026
    risk 0.00cvss 8.1epss 0.01

    Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-50338HigJul 14, 2026
    risk 0.00cvss 8.2epss 0.01

    Improper authentication in Azure Spring Apps allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-22099HigJul 13, 2026
    risk 0.00cvss —epss 0.00

    The charging station does not require authentication for Bluetooth commands to perform actions. The functionality exposed includes sensitive information leakage, triggering reboots, or pushing a firmware update URL.

  • CVE-2026-15557HigJul 13, 2026
    risk 0.00cvss 7.3epss 0.01

    A weakness has been identified in waooAI waoowaoo up to 0.4.1. Affected by this vulnerability is the function getInternalTaskSession/getAuthSession/requireUserAuth/requireProjectAuth/requireProjectAuthLight in the library src/lib/api-auth.ts of the component Internal Task Header…

  • CVE-2026-15542HigJul 13, 2026
    risk 0.00cvss 7.3epss 0.01

    A vulnerability has been found in will-moss Isaiah up to 1.36.9. This affects an unknown function of the file app/main.go of the component Websocket Connection Authentication. The manipulation leads to improper authentication. The attack can be initiated remotely. The pull…

  • CVE-2026-15491HigJul 12, 2026
    risk 0.00cvss 7.3epss 0.01

    A weakness has been identified in RafyMrX TOKO-ONLINE-ROTI up to ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99. This affects an unknown part. This manipulation causes missing authentication. The attack is possible to be carried out remotely. This product adopts a rolling release…

  • CVE-2026-55377HigJul 10, 2026
    risk 0.00cvss 8.1epss 0.00

    Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 1.41.0, Logto's Account Center step-up check accepted any active verification record that belonged to the current user and had isVerified === true. A WebAuthn registration verification record for…

  • CVE-2026-56675HigJul 10, 2026
    risk 0.00cvss 8.3epss 0.01

    9Router is an AI router & token saver. Prior to 0.5.2, 9router treats loopback requests as trusted and allows /v1/* access without an API key, so a same-host reverse proxy that forwards public traffic to the backend through 127.0.0.1 causes src/dashboardGuard.js to misclassify…

  • CVE-2026-56312MedJul 10, 2026
    risk 0.00cvss 6.5epss 0.00

    Capgo before 12.128.2 contains an improper validation vulnerability in the accept_invitation endpoint that creates user accounts before captcha validation is enforced. Attackers can bypass captcha protection by sending POST requests with invalid captcha tokens to create unwanted…

  • CVE-2026-12598HigJul 10, 2026
    risk 0.00cvss 8.1epss 0.01

    The LoginPress Pro plugin for WordPress is vulnerable to authentication bypass in versions up to and including 6.2.3 via the Spotify Social Login addon. This is due to the loginpress_on_spotify_login() function trusting the unverified 'email' field returned by Spotify's /v1/me…

  • CVE-2026-12597HigJul 10, 2026
    risk 0.00cvss 8.1epss 0.01

    The LoginPress Pro plugin for WordPress is vulnerable to Authentication Bypass via the GitHub OAuth callback in versions up to, and including, 6.2.3. The vulnerability exists in the loginpress_on_github_login() function, which blindly trusts the first element…

  • CVE-2026-12595HigJul 10, 2026
    risk 0.00cvss 8.1epss 0.01

    The LoginPress Pro plugin for WordPress is vulnerable to Authentication Bypass via Unverified OAuth Email in all versions up to and including 6.2.3. The vulnerability exists in the loginpress_on_discord_login() Discord OAuth callback handler, which accepts the email field…

  • CVE-2026-59208MedJul 9, 2026
    risk 0.00cvss 6.8epss 0.03

    n8n is an open source workflow automation platform. Prior to 2.27.4 and from 2.28.0 prior to 2.28.1, n8n instances configured with more than one trusted token-exchange issuer resolved external identities to local accounts using only the JWT sub claim and ignored the iss claim,…

  • CVE-2026-9695CriJul 8, 2026
    risk 0.00cvss 9.8epss 0.01

    An Improper Authentication vulnerability affecting DELMIA Apriso from Release 2020 through Release 2026 could allow an attacker to gain privileged access to the server.

  • CVE-2026-55076HigJul 7, 2026
    risk 0.00cvss 7.4epss 0.01

    Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, Coder's OIDC callback checked `email_verified` with a direct Go `bool` type assertion. When an IdP returned the claim as a non-boolean…

  • CVE-2026-37271CriJul 7, 2026
    risk 0.00cvss 9.8epss 0.01

    Fire-Boltt Smartwatch FB BGS001 Firmware: MOY-JS14-2.0.4 is vulnerable to Improper Authentication, The device accepts GATT Write Request commands without sufficient authentication or strong session validation. Under specific conditions, previously captured BLE packets can be…

  • CVE-2026-37270CriJul 7, 2026
    risk 0.00cvss 9.8epss 0.01

    Trueview Security camera T18161- AF v4.9.60.0 contains an authentication bypass vulnerability caused by improper password validation and the presence of hard-coded credentials in the firmware.

  • CVE-2026-55075HigJul 7, 2026
    risk 0.00cvss 7.4epss 0.00

    Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, two flaws in Coder's OIDC login chained into account takeover. Email-based user matching fell back to linking by email without checking…

  • CVE-2026-53483CriJul 7, 2026
    risk 0.00cvss 9.8epss 0.01

    Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 an improper authentication vulnerability. An unauthenticated…

  • CVE-2026-55727HigJul 6, 2026
    risk 0.00cvss 7.5epss 0.01

    A flaw in the authentication mechanism for video stream requests in Genetec Security Center 5.14.0.0 prior to build 5.14.178.18 may allow an unauthenticated attacker to access live video streams.