CWE-287

High likelihood

Improper Authentication

Parent: CWE-284 - Improper Access Control

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

4,567 vulnerabilities with CWE-287
CVE-2026-14541 HIGH
Authentication Bypass and Audience Confusion in MCP Toolbox OAuth Provider
CVE-2026-28323 CRITICAL
SolarWinds Web Help Desk SAML Authentication Bypass Vulnerability
CVSS 9.8
CVE-2026-58066 CRITICAL
Rocket.Chat - Improper Authentication
CVSS 9.8
CVE-2026-56850 MEDIUM
Node - Improper Authentication
CVSS 4.1
CVE-2026-15240 HIGH
Customer Switching for WooCommerce < 2.1.3 - Customer+ Privilege Escalation to Administrator via Insecure Operator Resolution
CVSS 7.5
CVE-2026-14305 MEDIUM
WP Delicious < 1.10.2 - Unauthenticated Arbitrary Post Meta Update via recipe_likes
CVSS 5.3
CVE-2026-63238 MEDIUM
Three Learning Koollab Lms < 5.3.2 - Authentication Bypass
CVSS 6.5
CVE-2026-14300 HIGH
miniOrange Social Login and Register < 7.8.0 - Unauthenticated Account Takeover
CVSS 8.1
CVE-2026-13690 HIGH
UsersWP < 1.2.67 - Two-Factor Authentication Bypass
CVSS 7.4
CVE-2026-49447 MEDIUM
Cosmos-Server's constellation public-devices endpoint accepts arbitrary bearer tokens
CVSS 5.3
CVE-2026-54635 HIGH
nessshon tonapi - Pytonapi Has a Webhook Custom Path Authentication Bypass
CVSS 7.5
CVE-2026-64745 LOW
macOS <15.7.8 and <26.6 - Unprotected User Data Exposure via Lock Screen Bypass
CVSS 2.4
CVE-2026-43766 MEDIUM
macOS < 14.8.8, < 15.7.8, < 26.6 - Unprotected User Data Exposure via Physical Access to Locked Device
CVSS 4.6
CVE-2026-66014 HIGH
Potential authentication bypass leading to privilege escalation in Artifactory
CVSS 8.8
CVE-2026-9830 HIGH
BookingPress Pro < 5.7.3 - Unauthenticated Customer PII Disclosure and Booking Tampering via Permission Callback Bug
CVSS 8.2
CVE-2026-14568 MEDIUM
WP User Frontend < 4.3.8 - Unauthenticated Author-less Attachment Deletion
CVSS 6.5
CVE-2026-13597 CRITICAL
QRcode Login for WeChat <= 1.3 - Unauthenticated Account Takeover
CVSS 9.1
CVE-2026-13332 CRITICAL
Masteriyo LMS < 2.3.1 - Unauthenticated Arbitrary User Session Termination (Denial of Service)
CVSS 9.1
CVE-2026-12493 HIGH
Clover Payment Gateway by Zaytech for WooCommerce < 1.3.6 - Unauthenticated Payment Bypass via check_order
CVSS 7.5
CVE-2026-12255 HIGH
MainWP Child < 6.1.2 - Unauthenticated Administrator Authentication Bypass via Passwordless Site Registration
CVSS 8.1
CVE-2026-12504 HIGH
Loytec LINX firmware: Improper Authentication in PAM configuration
CVE-2026-12877 CRITICAL
Software Issue Manager < 5.1.0 - Unauthenticated SQL Injection via Search Parameter
CVSS 9.1
CVE-2026-62825 CRITICAL
Azure Key Vault Elevation of Privilege Vulnerability
CVSS 10.0
CVE-2026-56191 CRITICAL
Microsoft Exchange Online Tampering Vulnerability
CVSS 10.0
CVE-2026-15981 CRITICAL
SAML Single Sign On <= 5.4.4 - Unauthenticated Authentication Bypass via SAMLResponse Parameter
CVSS 9.8
Details
Vulnerabilities 4,567
Exploit Likelihood High