VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (5,056)

page 57 of 253
  • CVE-2026-85596CriSep 4, 2026
    risk 0.57cvss 9.8epss 0.00

    Traefik versions >= v3.7.0 and <= v3.7.10 contain an authentication bypass in the Kubernetes Ingress NGINX provider. The TLS option generated for an Ingress carrying the nginx.ingress.kubernetes.io/auth-tls-secret annotation was named after the Ingress namespace and name. As a…

  • CVE-2026-85595CriSep 4, 2026
    risk 0.57cvss 9.8epss 0.00

    Traefik versions before v2.11.55 and versions v3.0.0 through v3.7.10 contain an authentication bypass vulnerability in the digestAuth middleware where unknown usernames receive an empty secret instead of rejection. Attackers can compute a valid digest response using the empty…

  • CVE-2026-19806HigSep 1, 2026
    risk 0.57cvss 8.8epss 0.00

    The Support Genix – Helpdesk, AI Chatbot, Knowledge Base & Customer Support Ticketing System plugin for WordPress is vulnerable to Authentication Bypass leading to Administrator Account Takeover in all versions up to, and including, 1.4.52 via the `guest_ticket_login()`…

  • CVE-2026-78236HigAug 26, 2026
    risk 0.57cvss 8.8epss 0.00

    An insecure PIN derivation mechanism in ABR allows a low-privileged user to escalate privileges to administrator by communicating over Cross-Process Communication (XPC) while masquerading as an Apple-signed process.

  • CVE-2026-24170HigAug 25, 2026
    risk 0.57cvss 8.8epss 0.01

    NVIDIA UFM Enterprise contains a vulnerability in the web interface authorization component, where an authenticated user could cause improper authentication by sending specially crafted HTTP requests. A successful exploit of this vulnerability might lead to code execution and…

  • CVE-2026-19842HigAug 19, 2026
    risk 0.57cvss 8.8epss 0.00

    The SAML Single Sign On WordPress plugin before 5.4.7 does not verify the signature of a SAML response before storing the certificate it carries, and offers an administrator a one-click control that promotes that stored certificate to the site's trusted signing certificate,…

  • CVE-2026-21582HigAug 18, 2026
    risk 0.57cvss —epss 0.00

    This High severity BASM (Broken Authentication & Session Management) vulnerability known as CVE-2026-21582 was introduced in version 7.2.1 of Crowd Data Center. This BASM (Broken Authentication & Session Management) vulnerability, with a CVSS Score of 8.8, allows an…

  • CVE-2026-15315HigAug 18, 2026
    risk 0.57cvss 8.8epss 0.00

    Tapo C120 v1 and C200 v5 contain an improper authentication vulnerability within the login authentication verification module. An attacker on the local network can exploit weaknesses in challenge parameter validation to bypass normal authentication controls and obtain…

  • CVE-2026-70922HigAug 18, 2026
    risk 0.57cvss 8.8epss 0.00

    Vulnerability in the Oracle Financial Services Enterprise Case Management product of Oracle Financial Services Applications (component: Web UI). Supported versions that are affected are 8.0.8.2 and 8.1.2.11. Easily exploitable vulnerability allows low privileged attacker with…

  • CVE-2026-56654CriAug 13, 2026
    risk 0.57cvss 9.8epss 0.00

    Privilege Escalation via Access Token Scope Escalation in API

  • CVE-2026-62827HigAug 11, 2026
    risk 0.57cvss 8.8epss 0.01

    Improper authentication in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-51584CriAug 11, 2026
    risk 0.57cvss 9.8epss 0.00

    An issue in usememos v0.27.1 allows a remote attacker to achieve account takeover via the ssoCredentials branch of the SignIn handler in server/router/api/v1/auth_service.go, because SSO identity is matched only on an attacker-controllable identifier without binding to the IdP's…

  • CVE-2026-72533HigAug 11, 2026
    risk 0.57cvss 8.8epss 0.00

    An authentication bypass vulnerability in Portainer CE through 2.44.0 allows authenticated low-privileged users to bypass Docker proxy authorization checks via non-canonical URL normalization, defeating all authorization middleware. The proxy endpoint fails to normalize request…

  • CVE-2026-18786HigAug 10, 2026
    risk 0.57cvss 8.8epss 0.00

    The CheckView WordPress plugin before 2.3.2 does not restrict its REST API authentication filter to its own routes and unconditionally discards the authentication error raised for any request whose URI merely contains a CheckView WordPress plugin before 2.3.2-specific string,…

  • CVE-2026-58075HigAug 4, 2026
    risk 0.57cvss —epss 0.00

    A vulnerability allowing an unauthenticated attacker to read arbitrary files from the host, which can be further leveraged toescalate privileges locally.

  • CVE-2026-14596HigAug 1, 2026
    risk 0.57cvss 8.8epss 0.00

    The DynamicKit for Elementor WordPress plugin before 1.0.3 does not validate the host of a user-supplied URL used as the base of the password-reset link it emails, allowing unauthenticated attackers to send a target user a legitimately-formatted reset email whose link points to…

  • CVE-2026-66014HigJul 27, 2026
    risk 0.57cvss 8.8epss 0.01

    JFrog Artifactory contains an authentication handling weakness in internal request processing that, under specific conditions, may allow an attacker to escalate privileges beyond the intended access level.

  • CVE-2026-62534HigJul 21, 2026
    risk 0.57cvss 8.8epss 0.00

    Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Web Utilities). Supported versions that are affected are 12.2.11-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise…

  • CVE-2026-62478HigJul 21, 2026
    risk 0.57cvss 8.8epss 0.00

    Vulnerability in the Oracle Public Sector Financials product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to…

  • CVE-2026-62476HigJul 21, 2026
    risk 0.57cvss 8.8epss 0.00

    Vulnerability in the Oracle Public Sector Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to…