When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
4,568 vulnerabilities with CWE-287
CVE-2026-60327
HIGH
Oracle Access Manager 12.2.1.4.0, 14.1.2.1.0 - Unauthenticated Unauthorized Data Access via Authentication Engine
CVSS 8.6
CVE-2026-60326
CRITICAL
Oracle Access Manager 12.2.1.4.0/14.1.2.1.0: Unauthenticated Critical Data Access & Modification
CVSS 9.1
CVE-2026-47037
HIGH
Oracle Access Manager 14.1.2.1.0 - Authenticated Remote Takeover via Authentication Engine
CVSS 8.8
CVE-2026-53595
CRITICAL
FreeScout vulnerable to anonymous account takeover via /user-setup empty invite_hash on MySQL
CVSS 9.4
CVE-2026-53591
HIGH
FreeScout Vulnerable to Unauthenticated Conversation Thread Injection via HMAC Length Bypass in FetchEmails
CVSS 8.6
CVE-2026-12341
HIGH
SailPoint IdentityIQ Improper Bearer Token Validation Vulnerability
CVSS 8.8
CVE-2026-55626
HIGH
xrdp: No authentication required with Xvnc backend on RHEL 9
CVSS 8.0
CVE-2026-48812
HIGH
FreeScout Allows Unauthenticated Access to Legacy Attachment Files
CVSS 7.5
CVE-2026-46715
MEDIUM
Flask-Security-Too OAuth reauthentication freshness bypass via cross- user OAuth identity acceptance
CVE-2026-42210
MEDIUM
Webmin 2FA requirement bypass
CVE-2026-16210
HIGH
newpanjing simpleui AjaxAdmin AJAX Endpoint admin.py self.get_action missing authentication
CVSS 7.3
CVE-2026-16209
HIGH
Gerapy Project Upload Endpoint views.py missing authentication
CVSS 7.3
CVE-2026-16198
MEDIUM
Sipeed PicoClaw First Run Setup access_control.go authentication bypass
CVSS 5.6
CVE-2026-47865
CRITICAL
VMware Avi Load Balancer Authentication Bypass Vulnerability
CVSS 9.8
CVE-2026-16083
MEDIUM
Sipeed PicoClaw LINE Webhook line.go webhook.ParseRequest authentication replay
CVSS 5.3
CVE-2026-16076
MEDIUM
AstrBotDevs AstrBot API open_api.py OpenApiRoute.chat_send authentication spoofing
CVSS 6.3
CVE-2026-49852
HIGH
joserfc: HS256/HS384/HS512 verify accepts empty/nil HMAC key (cross-language sibling of CVE-2026-45363)
CVE-2026-16015
MEDIUM
poco-ai poco-claw executor_manager API tasks.py create_task missing authentication
CVSS 6.3
CVE-2026-22752
CRITICAL
Spring Security Authorization Server Dynamic Client Registration endpoints perform insufficient validation of client metadata
CVSS 9.6
CVE-2026-12585
HIGH
Abandoned Cart Lite for WooCommerce < 6.8.2 - Unauthenticated Account Takeover via Malleable Recovery-Link Token
CVSS 8.1
CVE-2026-12492
CRITICAL
Happy Coders OTP Login for WooCommerce < 2.8 - Unauthenticated Account Takeover via hcotp_auto_login_user
CVSS 9.8
CVE-2026-55652
CRITICAL
Wekan < 9.46 Header Login - X-Forwarded-For Authentication Bypass
CVSS 9.8
CVE-2026-55445
CRITICAL
Qinglong: Incomplete fix for CVE-2026-3965: Improper Authentication
CVE-2026-52893
CRITICAL
Wekan: OIDC Account Takeover via Unconditional Email-Based Account Merge in onCreateUser hook
CVE-2026-46485
HIGH
Dash: Users can write to config despire permissions (OIDC tested)
CVSS 8.2
Details
Vulnerabilities
4,568
Exploit Likelihood
High