VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (5,090)

page 52 of 255
  • CVE-2026-11374CriJun 23, 2026
    risk 0.59cvss 9.0epss 0.03

    In ManageEngine ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and ADAudit Plus, the SSO tickets generated to authenticate that session could be predicted by an unauthenticated user, leading to account takeover.

  • CVE-2026-36727CriJun 9, 2026
    risk 0.59cvss 9.1epss 0.01

    An insecure authentication vulnerability in the /api/social-sign-in endpoint of bookcars v8.3 allows attackers to bypass authentication via a forged JWT token.

  • CVE-2026-9090CriMay 28, 2026
    risk 0.59cvss 9.1epss 0.00

    Casdoor versions 2.362.0 and earlier contain a vulnerability that allows an attacker to bypass authentication by supplying an arbitrary signing certificate. The buildSpCertificateStore function extracts the X.509 certificate directly from the incoming SAMLResponse instead of…

  • CVE-2026-7876CriMay 27, 2026
    risk 0.59cvss 9.1epss 0.01

    IBM Aspera HSTS for CP4I 1.5.1 through 1.5.19 is affected by an authentication bypass vulnerability. A transfer client may be able to take advantage of this vulnerability to access files in the server's local storage that they should not have access to, when specific…

  • CVE-2026-44551CriMay 15, 2026
    risk 0.59cvss 9.1epss 0.02

    Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the LDAP authentication endpoint does not validate that the submitted password is non-empty before performing a Simple Bind against the LDAP server. The LdapForm…

  • CVE-2026-33432CriApr 20, 2026
    risk 0.59cvss 9.1epss 0.01

    Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions up to and including 8.2.8.2, when LDAP authentication is enabled, Roxy-WI constructs an LDAP search filter by directly concatenating the user-supplied login username into the…

  • CVE-2017-20235CriApr 3, 2026
    risk 0.59cvss 9.1epss 0.00

    ProSoft Technology ICX35-HWC version 1.3 and prior cellular gateways contain an authentication bypass vulnerability in the web user interface that allows unauthenticated attackers to gain access to administrative functions without valid credentials. Attackers can bypass the…

  • CVE-2025-15484CriApr 1, 2026
    risk 0.59cvss 9.1epss 0.00

    The Order Notification for WooCommerce WordPress plugin before 3.6.3 overrides WooCommerce's permission checks to grant full access to all unauthenticated requests, enabling complete read/write access to store resources like products, coupons, and customers.

  • CVE-2026-28215CriFeb 26, 2026
    risk 0.59cvss 9.1epss 0.01

    hoppscotch is an open source API development ecosystem. Prior to version 2026.2.0, an unauthenticated attacker can overwrite the entire infrastructure configuration of a self-hosted Hoppscotch instance including OAuth provider credentials and SMTP settings by sending a single…

  • CVE-2025-68926CriDec 30, 2025
    risk 0.59cvss 9.8epss 0.32

    RustFS is a distributed object storage system built in Rust. In versions prior to 1.0.0-alpha.78, RustFS implements gRPC authentication using a hardcoded static token `"rustfs rpc"` that is publicly exposed in the source code repository, hardcoded on both client and server…

  • CVE-2025-44005CriDec 17, 2025
    risk 0.59cvss 10.0epss 0.09

    An attacker can bypass authorization checks and force a Step CA ACME or SCEP provisioner to create certificates without completing certain protocol authorization checks.

  • CVE-2025-61922CriOct 16, 2025
    risk 0.59cvss 9.1epss 0.01

    PrestaShop Checkout is the PrestaShop official payment module in partnership with PayPal. Starting in version 1.3.0 and prior to versions 4.4.1 and 5.0.5, missing validation on the Express Checkout feature allows silent login, enabling account takeover via email. The…

  • CVE-2025-9064CriOct 14, 2025
    risk 0.59cvss 9.1epss 0.01

    A path traversal security issue exists within FactoryTalk View Machine Edition, allowing unauthenticated attackers on the same network as the device to delete any file within the panels operating system. Exploitation of this vulnerability is dependent on the knowledge of…

  • CVE-2025-59345CriSep 17, 2025
    risk 0.59cvss 9.1epss 0.00

    Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, The /api/v1/jobs and /preheats endpoints in Manager web UI are accessible without authentication. Any user with network access to the Manager can create, delete, and modify…

  • CVE-2025-45583CriSep 12, 2025
    risk 0.59cvss 9.1epss 0.00

    Incorrect access control in the FTP protocol of Audi UTR 2.0 Universal Traffic Recorder 2.0 allows attackers to authenticate into the service using any combination of username and password.

  • CVE-2025-55234HigSep 9, 2025
    risk 0.59cvss 8.8epss 0.20

    SMB Server might be susceptible to relay attacks depending on the configuration. An attacker who successfully exploited these vulnerabilities could perform relay attacks and make the users subject to elevation of privilege attacks. The SMB Server already supports mechanisms for…

  • CVE-2025-54918HigSep 9, 2025
    risk 0.59cvss 8.8epss 0.20

    Improper authentication in Windows NTLM allows an authorized attacker to elevate privileges over a network.

  • CVE-2025-21450CriJul 8, 2025
    risk 0.59cvss 9.1epss 0.00

    Cryptographic issue occurs due to use of insecure connection method while downloading.

  • CVE-2025-30282CriApr 8, 2025
    risk 0.59cvss 9.1epss 0.02

    ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Authentication vulnerability that could result in arbitrary code execution in the context of the current user. A high-privileged attacker could leverage this vulnerability to bypass…

  • CVE-2025-31122CriMar 31, 2025
    risk 0.59cvss —epss 0.00

    scratch-coding-hut.github.io is the website for Coding Hut. In 1.0-beta3 and earlier, the login link can be used to login to any account by changing the username in the username field.