CWE-287

High likelihood

Improper Authentication

Parent: CWE-284 - Improper Access Control

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

4,570 vulnerabilities with CWE-287
CVE-2026-11717 CRITICAL
Mcp Toolbox For Databases (googleapis/mcp-toolbox) < 1.3.0 - Improper Authentication
CVE-2026-48991 MEDIUM
XianYuLauncher: Legacy Microsoft account OAuth sign-in flow lacks PKCE and state validation
CVSS 5.5
CVE-2026-49502 HIGH
Dell PowerFlex - Improper Authentication
CVSS 7.4
CVE-2026-48117 MEDIUM
DroneAware's Improper Account Activation in Registration and SSO Flows Leads to Account Takeover
CVSS 6.8
CVE-2026-32804 HIGH
Dell PowerFlex - Improper Authentication
CVSS 8.1
CVE-2026-48929 HIGH
Rocket.Chat - Improper Authentication
CVSS 7.5
CVE-2026-46973 HIGH
Oracle Outsourced Mfg for Discrete Industries 12.2.3-12.2.15 - Authenticated Remote Code Execution via HTTP
CVSS 8.8
CVE-2026-46972 HIGH
Oracle Outsourced Mfg for Discrete Industries 12.2.3-12.2.15 - Remote Code Execution via HTTP
CVSS 8.8
CVE-2026-46962 HIGH
Oracle Project Portfolio Analysis 12.2.3-12.2.15 - Authenticated Remote Code Execution
CVSS 8.8
CVE-2026-46961 HIGH
Oracle Project Portfolio Analysis 12.2.3-12.2.15 - Authenticated Remote Code Execution
CVSS 8.8
CVE-2026-46952 HIGH
Oracle Quality 12.2.3-12.2.15 - Authenticated Remote Code Execution via HTTP
CVSS 8.8
CVE-2026-46951 HIGH
Oracle Quality 12.2.3-12.2.15 - Authenticated Remote Code Execution via HTTP
CVSS 8.8
CVE-2026-46942 HIGH
Oracle Process Manufacturing Process Planning 12.2.3-12.2.15 - Authenticated Remote Code Execution via HTTP
CVSS 8.8
CVE-2026-46940 HIGH
Oracle Cost Management 12.2.3-12.2.15 - Authenticated Remote Code Execution in Cost Planning
CVSS 8.8
CVE-2026-46937 HIGH
Oracle iSetup 12.2.3-12.2.15 - Authenticated Remote Code Execution in General Ledger Update Transform
CVSS 8.8
CVE-2026-46929 HIGH
Oracle Cost Management 12.2.3-12.2.15 - Authenticated Remote Code Execution in Cost Planning
CVSS 8.8
CVE-2026-46928 HIGH
Oracle Spares Management 12.2.3-12.2.15 - Authenticated Remote Code Execution via HTTPS
CVSS 8.8
CVE-2026-46921 HIGH
Siebel CRM Cloud Applications 17.0-26.5 - Authenticated Remote Code Execution in Siebel Cloud Manager
CVSS 8.8
CVE-2026-46919 CRITICAL
Oracle Siebel CRM Cloud Applications 17.0-26.5 - Unauthenticated Remote Code Execution via HTTP
CVSS 9.8
CVE-2026-46916 HIGH
Oracle Process Manufacturing 12.2.3-12.2.15 - Authenticated RCE in Quality Management
CVSS 8.8
CVE-2026-46903 HIGH
JD Edwards EnterpriseOne Tools 9.2.0.0-9.2.26.2 - Authenticated Remote Code Execution
CVSS 8.8
CVE-2026-46890 CRITICAL
Oracle Siebel Apps - Marketing 17.0-26.5 - Unauthenticated Remote Code Execution
CVSS 9.8
CVE-2026-46859 CRITICAL
Oracle Agile PLM 9.3.6 - Unauthenticated Remote Code Execution via HTTP
CVSS 9.8
CVE-2026-35261 MEDIUM
Oracle Access Manager 12.2.1.4.0 and 14.1.2.1.0 - Unauthenticated Data Manipulation and Information Disclosure via HTTP
CVSS 6.5
CVE-2026-48780 HIGH
Forem vulnerable to bypass of email address domain restrictions
CVSS 8.2
Details
Vulnerabilities 4,570
Exploit Likelihood High