CWE-287

High likelihood

Improper Authentication

Parent: CWE-284 - Improper Access Control

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

4,568 vulnerabilities with CWE-287
CVE-2026-60327 HIGH
Oracle Access Manager 12.2.1.4.0, 14.1.2.1.0 - Unauthenticated Unauthorized Data Access via Authentication Engine
CVSS 8.6
CVE-2026-60326 CRITICAL
Oracle Access Manager 12.2.1.4.0/14.1.2.1.0: Unauthenticated Critical Data Access & Modification
CVSS 9.1
CVE-2026-47037 HIGH
Oracle Access Manager 14.1.2.1.0 - Authenticated Remote Takeover via Authentication Engine
CVSS 8.8
CVE-2026-53595 CRITICAL
FreeScout vulnerable to anonymous account takeover via /user-setup empty invite_hash on MySQL
CVSS 9.4
CVE-2026-53591 HIGH
FreeScout Vulnerable to Unauthenticated Conversation Thread Injection via HMAC Length Bypass in FetchEmails
CVSS 8.6
CVE-2026-12341 HIGH
SailPoint IdentityIQ Improper Bearer Token Validation Vulnerability
CVSS 8.8
CVE-2026-55626 HIGH
xrdp: No authentication required with Xvnc backend on RHEL 9
CVSS 8.0
CVE-2026-48812 HIGH
FreeScout Allows Unauthenticated Access to Legacy Attachment Files
CVSS 7.5
CVE-2026-46715 MEDIUM
Flask-Security-Too OAuth reauthentication freshness bypass via cross- user OAuth identity acceptance
CVE-2026-42210 MEDIUM
Webmin 2FA requirement bypass
CVE-2026-16210 HIGH
newpanjing simpleui AjaxAdmin AJAX Endpoint admin.py self.get_action missing authentication
CVSS 7.3
CVE-2026-16209 HIGH
Gerapy Project Upload Endpoint views.py missing authentication
CVSS 7.3
CVE-2026-16198 MEDIUM
Sipeed PicoClaw First Run Setup access_control.go authentication bypass
CVSS 5.6
CVE-2026-47865 CRITICAL
VMware Avi Load Balancer Authentication Bypass Vulnerability
CVSS 9.8
CVE-2026-16083 MEDIUM
Sipeed PicoClaw LINE Webhook line.go webhook.ParseRequest authentication replay
CVSS 5.3
CVE-2026-16076 MEDIUM
AstrBotDevs AstrBot API open_api.py OpenApiRoute.chat_send authentication spoofing
CVSS 6.3
CVE-2026-49852 HIGH
joserfc: HS256/HS384/HS512 verify accepts empty/nil HMAC key (cross-language sibling of CVE-2026-45363)
CVE-2026-16015 MEDIUM
poco-ai poco-claw executor_manager API tasks.py create_task missing authentication
CVSS 6.3
CVE-2026-22752 CRITICAL
Spring Security Authorization Server Dynamic Client Registration endpoints perform insufficient validation of client metadata
CVSS 9.6
CVE-2026-12585 HIGH
Abandoned Cart Lite for WooCommerce < 6.8.2 - Unauthenticated Account Takeover via Malleable Recovery-Link Token
CVSS 8.1
CVE-2026-12492 CRITICAL
Happy Coders OTP Login for WooCommerce < 2.8 - Unauthenticated Account Takeover via hcotp_auto_login_user
CVSS 9.8
CVE-2026-55652 CRITICAL
Wekan < 9.46 Header Login - X-Forwarded-For Authentication Bypass
CVSS 9.8
CVE-2026-55445 CRITICAL
Qinglong: Incomplete fix for CVE-2026-3965: Improper Authentication
CVE-2026-52893 CRITICAL
Wekan: OIDC Account Takeover via Unconditional Email-Based Account Merge in onCreateUser hook
CVE-2026-46485 HIGH
Dash: Users can write to config despire permissions (OIDC tested)
CVSS 8.2
Details
Vulnerabilities 4,568
Exploit Likelihood High