VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (5,056)

page 78 of 253
  • CVE-2026-12526HigSep 2, 2026
    risk 0.53cvss 8.1epss 0.00

    The Advanced Custom Fields: Extended WordPress plugin before 0.9.2.7 does not verify that the requester is authorized to edit the targeted user account in the update-user action of its front-end Forms module; it only checks a capability when the submitted role is administrator…

  • CVE-2026-73777HigSep 1, 2026
    risk 0.53cvss 8.1epss 0.00

    Vulnerabilities have been identified in the API endpoint of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls.

  • CVE-2026-76548HigAug 29, 2026
    risk 0.53cvss 8.2epss 0.00

    The User Profile Builder WordPress plugin before 4.0.1 does not properly restrict its front-end file upload feature, granting unauthenticated visitors capabilities reserved to privileged roles. This allows them to list the site's media library and to modify unpublished posts,…

  • CVE-2026-19718HigAug 26, 2026
    risk 0.53cvss 8.1epss 0.00

    The BlogVault Backup & Staging WordPress plugin before 6.65, MalCare WordPress Security Plugin WordPress plugin before 6.65, The WP Remote WordPress Plugin WordPress plugin before 6.65 do not prevent unauthenticated users from obtaining data derived from the secret that binds a…

  • CVE-2026-68569HigAug 25, 2026
    risk 0.53cvss 8.1epss 0.01

    Improper Authentication vulnerability in Apache Tomcat meant that in some circumstances (e.g. CLIENT-CERT, SPNEGO) that a user would be authenticated even if the user did not exist in the DataSourceRealm. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from…

  • CVE-2026-76793HigAug 22, 2026
    risk 0.53cvss 8.1epss 0.00

    The Firebase Authentication WordPress plugin before 1.7.1 does not require the email address in an authentication token to be verified before matching it to a WordPress account and issuing a session, allowing unauthenticated attackers to log in as any user, including…

  • CVE-2026-18052HigAug 22, 2026
    risk 0.53cvss 8.1epss 0.00

    The ManageWP Worker WordPress plugin before 4.9.37 does not bind the account being logged in to the signature which authorises the login, nor prevent an already used login link from being replayed, allowing attackers who obtain such a link to gain a session as any user on the…

  • CVE-2026-17000HigAug 20, 2026
    risk 0.53cvss 8.1epss 0.00

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to improper authentication.

  • CVE-2026-76338HigAug 19, 2026
    risk 0.53cvss 8.1epss 0.00

    In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who has access to a trusted distributed search private key could forge an administrative session token, access all relevant data, affect system integrity, and disrupt service…

  • CVE-2026-16857HigAug 19, 2026
    risk 0.53cvss 8.2epss 0.00

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to manipulate network traffic and DNS configuration due to improper authentication.

  • CVE-2026-16686HigAug 19, 2026
    risk 0.53cvss 8.2epss 0.00

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to access NFS-exported filesystems due to improper authentication.

  • CVE-2026-16867HigAug 13, 2026
    risk 0.53cvss 8.1epss 0.00

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to access server resources with the privileges of an authenticated user due to improper authentication during NTLM session negotiation.

  • CVE-2026-17197HigAug 13, 2026
    risk 0.53cvss 8.1epss 0.00

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to bypass security restrictions due to improper validation of client-asserted identity.

  • CVE-2026-12359HigAug 12, 2026
    risk 0.53cvss 8.1epss 0.00

    IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 could allow a remote attacker to access sensitive information due to an inconsistent interpretation of an HTTP request…

  • CVE-2026-18469HigAug 10, 2026
    risk 0.53cvss 8.1epss 0.00

    The Login & Register Forms WordPress plugin before 4.0.2 does not enforce its password reset attempt limit against a server-derived value, keying both the verification code and the per-source attempt counter on client-controlled data, allowing unauthenticated attackers to reset…

  • CVE-2026-18468HigAug 10, 2026
    risk 0.53cvss 8.1epss 0.00

    The Login & Register Forms WordPress plugin before 4.0.2 does not bind the password reset verification state to the account being reset or to the party that completed the verification, keying it instead on a value the client controls, allowing unauthenticated attackers to take…

  • CVE-2026-16257HigAug 10, 2026
    risk 0.53cvss 8.2epss 0.00

    The Arvow AI SEO Writer WordPress plugin before 1.5.4 does not properly restrict access to one of its REST endpoints, whose only access control can be bypassed by unauthenticated users through type juggling when the Arvow AI SEO Writer WordPress plugin before 1.5.4 has not been…

  • CVE-2026-13600HigAug 10, 2026
    risk 0.53cvss 8.1epss 0.00

    The AutoNetTV Relay WordPress plugin before 3.0.14 does not perform any capability or authentication check before setting a WordPress administrator authentication cookie during its scheduled content-synchronization task. On server configurations where the scheduled task executes…

  • CVE-2026-16030HigAug 7, 2026
    risk 0.53cvss 8.1epss 0.00

    The MStore API WordPress plugin before 4.21.0 does not correctly verify the cryptographic signature of the token used to authenticate its phone-based login, allowing unauthenticated attackers who know a registered user's phone number to forge a token and take over that user's…

  • CVE-2026-15459HigAug 6, 2026
    risk 0.53cvss 8.1epss 0.01

    The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.0.0. On sites not yet connected to the WPMU DEV Hub — the default state after installation — the site API key that keys the WDP-AUTH request signature…