CWE-287

High likelihood

Improper Authentication

Parent: CWE-284 - Improper Access Control

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

4,567 vulnerabilities with CWE-287
CVE-2026-10697 HIGH
MFA Bypass in MOVEit Transfer
CVSS 7.5
CVE-2026-15611 CRITICAL
Logto - Unverified Email-Based SSO Account Linking
CVSS 9.1
CVE-2026-15348 MEDIUM
Premium Packages <= 7.0.4 - Authentication Bypass to Non-Admin via 'wpdmppdl' Parameter
CVSS 6.3
CVE-2026-14291 HIGH
Security Ninja (Premium) < 5.290 - Two-Factor Authentication Bypass via secnin_skip_2fa
CVSS 7.5
CVE-2026-60367 CRITICAL
Oracle Platform Security for Java 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Remote Code Execution via HTTP
CVSS 9.8
CVE-2026-62144 CRITICAL
Checkpoint Quantum Security Management - Authentication Bypass
CVSS 9.1
CVE-2026-16232 CRITICAL KEV
Authentication Bypass in the SmartConsole Login Process Using an Application Token
CVSS 9.1
CVE-2026-62547 HIGH
Oracle Workflow 12.2.3-12.2.15 - Unauthenticated Remote Code Execution via SMTP
CVSS 8.1
CVE-2026-62534 HIGH
Oracle Applications Framework 12.2.11-12.2.15 - Authenticated Remote Code Execution via Web Utilities
CVSS 8.8
CVE-2026-62498 HIGH
Oracle Flow Manufacturing 12.2.7-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 8.8
CVE-2026-62496 HIGH
Oracle Yard Management 12.2.6-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 8.8
CVE-2026-62493 HIGH
Oracle Purchasing 12.2.11-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 7.5
CVE-2026-62478 HIGH
Oracle Public Sector Financials 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 8.8
CVE-2026-62476 HIGH
Oracle Public Sector Payroll 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 8.8
CVE-2026-62464 HIGH
Oracle Payroll 12.2.3-12.2.15 - Authenticated Remote Code Execution via Internal Operations Component
CVSS 8.8
CVE-2026-62447 HIGH
Oracle Trade Management 12.2.3-12.2.15 - Authenticated Remote Code Execution via Claim LOV Component
CVSS 8.8
CVE-2026-61322 HIGH
Oracle TeleSales 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 8.8
CVE-2026-61320 HIGH
Oracle Payables 12.2.8-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 8.8
CVE-2026-61311 HIGH
Oracle Product Hub 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 8.8
CVE-2026-61243 HIGH
PeopleSoft Enterprise FIN Common Objects Argentina 9.1 - Authenticated Remote Code Execution via Staffing Component
CVSS 8.8
CVE-2026-61233 CRITICAL
PeopleSoft Enterprise FIN Common Objects Brazil 9.1 - Unauthenticated Remote Code Execution via Integration Component
CVSS 9.8
CVE-2026-61225 HIGH
Oracle Communications Converged Application Server 8.2 and 8.3 - Unauthenticated Remote Takeover via TCP/IP
CVSS 8.1
CVE-2026-61188 HIGH
Oracle Agile Product Lifecycle Management for Process 6.2.4 - Authenticated Remote Takeover via Installation Component
CVSS 7.5
CVE-2026-61183 CRITICAL
Oracle Agile Product Lifecycle Management for Process 6.2.4 - Unauthenticated Remote Code Execution via HTTP
CVSS 9.8
CVE-2026-61180 HIGH
Oracle Agile PLM for Process 6.2.4: Auth RCE via Product Quality Management Component
CVSS 8.8
Details
Vulnerabilities 4,567
Exploit Likelihood High