VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (5,090)

page 51 of 255
  • CVE-2026-87217CriSep 15, 2026
    risk 0.59cvss 9.1epss 0.00

    Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise…

  • CVE-2026-87176CriSep 15, 2026
    risk 0.59cvss 9.1epss 0.00

    Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise…

  • CVE-2026-87175CriSep 15, 2026
    risk 0.59cvss 9.1epss 0.00

    Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise…

  • CVE-2026-87173CriSep 15, 2026
    risk 0.59cvss 9.1epss 0.00

    Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise…

  • CVE-2026-87170CriSep 15, 2026
    risk 0.59cvss 9.1epss 0.00

    Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise…

  • CVE-2026-87129CriSep 15, 2026
    risk 0.59cvss 9.1epss 0.00

    Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP…

  • CVE-2026-87128CriSep 15, 2026
    risk 0.59cvss 9.1epss 0.00

    Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP…

  • CVE-2026-83202CriSep 15, 2026
    risk 0.59cvss 9.1epss 0.00

    Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM…

  • CVE-2026-83201CriSep 15, 2026
    risk 0.59cvss 9.1epss 0.00

    Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM…

  • CVE-2026-83154CriSep 15, 2026
    risk 0.59cvss 9.1epss 0.00

    Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: Open UI). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via SOAP to compromise Siebel CRM End User. …

  • CVE-2026-83104CriSep 15, 2026
    risk 0.59cvss 9.1epss 0.00

    Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). Supported versions that are affected are 12.2.1.19.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP…

  • CVE-2026-73952CriSep 15, 2026
    risk 0.59cvss 9.1epss 0.00

    Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Portlet Services). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to…

  • CVE-2026-73944CriSep 15, 2026
    risk 0.59cvss 9.1epss 0.00

    Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP…

  • CVE-2026-69854CriSep 8, 2026
    risk 0.59cvss 9.0epss 0.01

    Improper authentication in Spring Cloud Azure allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-19714CriAug 16, 2026
    risk 0.59cvss 9.1epss 0.00

    The Simple JWT Login WordPress plugin before 3.6.8 does not validate the audience of the Google identity tokens it accepts, allowing unauthenticated users to authenticate as any user whose email address such a token carries, up to and including an administrator. Every site with…

  • CVE-2026-71277CriAug 5, 2026
    risk 0.59cvss 9.1epss 0.00

    rust-iot-platform's AuthToken request-guard implementation (api/src/main.rs) only checks whether the Authorization HTTP header is present, and never validates its value against any session, token store, or signature. Any request carrying an arbitrary non-empty Authorization…

  • CVE-2026-15210CriAug 5, 2026
    risk 0.59cvss 9.1epss 0.00

    The OTP Login With Phone Number, OTP Verification WordPress plugin before 1.8.71 does not limit the number of OTP verification attempts or invalidate a one-time login code after a wrong guess, and an unauthenticated user can request a login code for any account. Because the code…

  • CVE-2026-14557CriAug 3, 2026
    risk 0.59cvss 9.1epss 0.01

    The SoftMarket — Digital Marketplace WordPress plugin through 1.0.0 does not properly validate an authentication token in one branch of its email-verification flow, allowing unauthenticated attackers to obtain a valid session as any verified user by supplying only that user's…

  • CVE-2026-47677criJul 13, 2026
    risk 0.59cvss —epss —

    # Authentication bypass in FacturaScripts: `/login?action=two-factor-validation` accepts brute-forceable TOTP without password or CSRF protection ## Summary `Core/Controller/Login.php::twoFactorValidationAction()` accepts an unauthenticated POST containing only `fsNick` and…

  • CVE-2026-15089CriJul 10, 2026
    risk 0.59cvss 9.1epss 0.00

    Vulnerability in Drupal Commerce guest registration. This issue affects Commerce guest registration versions: *.*.