CWE-287
Improper Authentication
Description
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94
CVEs mapped to this weakness (5,054)
page 8 of 253| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-76657 | Cri | 0.65 | 10.0 | 0.00 | Sep 1, 2026 | Vulnerabilities have been identified in the API of HPE Networking Fabric Composer that could potentially allow an unauthenticated remote attacker to circumvent existing authentication controls. Successful exploitation could allow an attacker to gain administrative privileges… | ||
| CVE-2026-82695 | Cri | 0.65 | 10.0 | 0.01 | Aug 31, 2026 | A security flaw has been discovered in Tenda AC18 15.03.05.19. Impacted is an unknown function of the file /goform/telnet of the component Telnet Handler. The manipulation results in missing authentication. The attack can be launched remotely. The exploit has been released to… | ||
| CVE-2026-82694 | Cri | 0.65 | 10.0 | 0.01 | Aug 31, 2026 | A vulnerability was identified in Tenda AC1206 15.03.06.23. This issue affects the function R7WebsSecurityHandler of the file /goform/ate of the component Web UI. The manipulation leads to missing authentication. The attack can be initiated remotely. The exploit is publicly… | ||
| CVE-2026-82693 | Cri | 0.65 | 10.0 | 0.01 | Aug 31, 2026 | A vulnerability was determined in Tenda AC1206 15.03.06.23. This vulnerability affects the function TendaTelnet of the file /goform/telnet of the component Web UI. Executing a manipulation can lead to missing authentication. It is possible to launch the attack remotely. The… | ||
| CVE-2026-78167 | Cri | 0.65 | 10.0 | 0.01 | Aug 24, 2026 | A weakness has been identified in EFM ipTIME T16000M 14.20.2. The impacted element is the function httpcon_check_session_url of the component Session Validation Handler. This manipulation causes improper authentication. Remote exploitation of the attack is possible. The exploit… | ||
| CVE-2026-20317 | Cri | 0.65 | 10.0 | 0.00 | Aug 19, 2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered… | ||
| CVE-2026-19977 | Cri | 0.65 | 10.0 | 0.01 | Aug 17, 2026 | A vulnerability was detected in EFM ipTIME A3004T 14.19.0. The affected element is the function httpcon_check_session_url of the component Session Validation. Performing a manipulation results in improper authentication. Remote exploitation of the attack is possible. The exploit… | ||
| CVE-2026-59500 | Cri | 0.65 | 10.0 | 0.00 | Aug 13, 2026 | : Improper Authentication vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions). This issue affects Portal Generator addon to Priority ERP (developed by Soft Solutions): All versions without Priwall v3. | ||
| CVE-2024-27253 | Cri | 0.65 | 10.0 | 0.00 | Aug 12, 2026 | IBM DOORS Next 7.0.3 through 7.0.3 Interim Fix 018 could allow an authenticated user to bypass security logic to perform unauthorized activities. | ||
| CVE-2026-56162 | Cri | 0.65 | 10.0 | 0.01 | Aug 7, 2026 | Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2026-62825 | Cri | 0.65 | 10.0 | 0.01 | Jul 24, 2026 | Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2026-45480 | Cri | 0.65 | 10.0 | 0.01 | Jun 19, 2026 | Improper authentication in Azure Active Directory allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2026-46389 | Cri | 0.65 | 10.0 | 0.00 | Jun 5, 2026 | UDS Identity Config builds the Keycloak configuration image (realm, plugins, theme, truststore, JARs) consumed by UDS Core's Identity deployment. In versions 0.11.0 through 0.26.0, a logic error in the `client-kubernetes-secret` Keycloak client authenticator (shipped by… | ||
| CVE-2026-46840 | Cri | 0.65 | 10.0 | 0.01 | May 28, 2026 | Vulnerability in Oracle REST Data Services (component: Backend-as-a-Service). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle REST Data Services. While… | ||
| CVE-2026-47280 | Cri | 0.65 | 10.0 | 0.00 | May 22, 2026 | Improper authentication in Azure Resource Manager (ARM) allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2026-45434 | Cri | 0.65 | 9.8 | 0.22 | May 19, 2026 | Improper Authentication vulnerability in Apache OFBiz via Password-Change Logic Flaw Leading to Remote Code Execution This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue. | ||
| CVE-2026-42822 | Cri | 0.65 | 10.0 | 0.00 | May 18, 2026 | Improper authentication in Azure Local Disconnected Operations allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2026-8181 | Cri | 0.65 | 9.8 | 0.15 | May 14, 2026 | The Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative) plugin for WordPress is vulnerable to Authentication Bypass in versions 3.4.0 to 3.4.1.1. This is due to incorrect return-value handling in the `is_mainwp_authenticated()` function when… | ||
| CVE-2025-70841 | Cri | 0.65 | 10.0 | 0.00 | Feb 3, 2026 | Dokans Multi-Tenancy Based eCommerce Platform SaaS 3.9.2 allows unauthenticated remote attackers to obtain sensitive application configuration data via direct request to /script/.env file. The exposed file contains Laravel application encryption key (APP_KEY), database… | ||
| CVE-2025-63224 | Cri | 0.65 | 10.0 | 0.01 | Nov 19, 2025 | The Itel DAB Encoder (IDEnc build 25aec8d) is vulnerable to Authentication Bypass due to improper JWT validation across devices. Attackers can reuse a valid JWT token obtained from one device to authenticate and gain administrative access to any other device running the same… |
- risk 0.65cvss 10.0epss 0.00
Vulnerabilities have been identified in the API of HPE Networking Fabric Composer that could potentially allow an unauthenticated remote attacker to circumvent existing authentication controls. Successful exploitation could allow an attacker to gain administrative privileges…
- risk 0.65cvss 10.0epss 0.01
A security flaw has been discovered in Tenda AC18 15.03.05.19. Impacted is an unknown function of the file /goform/telnet of the component Telnet Handler. The manipulation results in missing authentication. The attack can be launched remotely. The exploit has been released to…
- risk 0.65cvss 10.0epss 0.01
A vulnerability was identified in Tenda AC1206 15.03.06.23. This issue affects the function R7WebsSecurityHandler of the file /goform/ate of the component Web UI. The manipulation leads to missing authentication. The attack can be initiated remotely. The exploit is publicly…
- risk 0.65cvss 10.0epss 0.01
A vulnerability was determined in Tenda AC1206 15.03.06.23. This vulnerability affects the function TendaTelnet of the file /goform/telnet of the component Web UI. Executing a manipulation can lead to missing authentication. It is possible to launch the attack remotely. The…
- risk 0.65cvss 10.0epss 0.01
A weakness has been identified in EFM ipTIME T16000M 14.20.2. The impacted element is the function httpcon_check_session_url of the component Session Validation Handler. This manipulation causes improper authentication. Remote exploitation of the attack is possible. The exploit…
- risk 0.65cvss 10.0epss 0.00
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered…
- risk 0.65cvss 10.0epss 0.01
A vulnerability was detected in EFM ipTIME A3004T 14.19.0. The affected element is the function httpcon_check_session_url of the component Session Validation. Performing a manipulation results in improper authentication. Remote exploitation of the attack is possible. The exploit…
- risk 0.65cvss 10.0epss 0.00
: Improper Authentication vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions). This issue affects Portal Generator addon to Priority ERP (developed by Soft Solutions): All versions without Priwall v3.
- risk 0.65cvss 10.0epss 0.00
IBM DOORS Next 7.0.3 through 7.0.3 Interim Fix 018 could allow an authenticated user to bypass security logic to perform unauthorized activities.
- risk 0.65cvss 10.0epss 0.01
Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.
- risk 0.65cvss 10.0epss 0.01
Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network.
- risk 0.65cvss 10.0epss 0.01
Improper authentication in Azure Active Directory allows an unauthorized attacker to elevate privileges over a network.
- risk 0.65cvss 10.0epss 0.00
UDS Identity Config builds the Keycloak configuration image (realm, plugins, theme, truststore, JARs) consumed by UDS Core's Identity deployment. In versions 0.11.0 through 0.26.0, a logic error in the `client-kubernetes-secret` Keycloak client authenticator (shipped by…
- risk 0.65cvss 10.0epss 0.01
Vulnerability in Oracle REST Data Services (component: Backend-as-a-Service). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle REST Data Services. While…
- risk 0.65cvss 10.0epss 0.00
Improper authentication in Azure Resource Manager (ARM) allows an unauthorized attacker to elevate privileges over a network.
- risk 0.65cvss 9.8epss 0.22
Improper Authentication vulnerability in Apache OFBiz via Password-Change Logic Flaw Leading to Remote Code Execution This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue.
- risk 0.65cvss 10.0epss 0.00
Improper authentication in Azure Local Disconnected Operations allows an unauthorized attacker to elevate privileges over a network.
- risk 0.65cvss 9.8epss 0.15
The Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative) plugin for WordPress is vulnerable to Authentication Bypass in versions 3.4.0 to 3.4.1.1. This is due to incorrect return-value handling in the `is_mainwp_authenticated()` function when…
- risk 0.65cvss 10.0epss 0.00
Dokans Multi-Tenancy Based eCommerce Platform SaaS 3.9.2 allows unauthenticated remote attackers to obtain sensitive application configuration data via direct request to /script/.env file. The exposed file contains Laravel application encryption key (APP_KEY), database…
- risk 0.65cvss 10.0epss 0.01
The Itel DAB Encoder (IDEnc build 25aec8d) is vulnerable to Authentication Bypass due to improper JWT validation across devices. Attackers can reuse a valid JWT token obtained from one device to authenticate and gain administrative access to any other device running the same…