When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
4,568 vulnerabilities with CWE-287
CVE-2026-53516
HIGH
Better Auth: Account takeover via OAuth auto-link to unverified pre-registered email
CVSS 8.3
CVE-2026-53514
HIGH
Better Auth: Unauthorized invitation acceptance via unverified email match in organization plugin
CVSS 7.7
CVE-2026-53512
CRITICAL
Better Auth: OAuth refresh-token replay via missing client authentication on oidc-provider and mcp plugins
CVSS 9.1
CVE-2026-59955
HIGH
Apollo ConfigService access key authentication bypass via raw config file appId parsing
CVSS 7.5
CVE-2026-59954
HIGH
Apollo ConfigService access key authentication bypass via appId parsing and non-canonical matching
CVSS 7.5
CVE-2026-47159
MEDIUM
Vaultwarden < 1.36.0 SSO Discovery - Organization Enumeration
CVE-2026-44986
CRITICAL
Penpot: Pre-authenticated account takeover via team-invitation token + prepare-register-profile
CVSS 9.9
CVE-2026-61740
CRITICAL
LightRAG: Authentication bypass: hardcoded DEFAULT_TOKEN_SECRET and public /auth-status defeat LIGHTRAG_API_KEY protection
CVE-2026-61436
HIGH
PraisonAI before 4.6.78 Missing Webhook Signature Verification
CVSS 8.6
CVE-2026-61435
HIGH
PraisonAI before 4.6.78 Authentication Bypass via Host Header Spoofing
CVSS 8.2
CVE-2026-56353
MEDIUM
n8n - Authentication Bypass in Chat Trigger Node
CVSS 4.8
CVE-2026-12281
HIGH
Shibboleth < 2.5.4 - Unauthenticated Administrator Account Creation via Identity Header Spoofing
CVSS 8.1
CVE-2026-5270
CRITICAL
Authentication Bypass in Navigator and Blue Planet Products
CVSS 9.8
CVE-2026-45363
CRITICAL
`jwt` (Ruby gem) - empty-key HMAC bypass
CVSS 9.1
CVE-2026-45754
MEDIUM
Symfony: Mailjet Mailer Webhook Parser Never Verifies the Configured Secret — Unauthenticated Webhook Event Injection
CVSS 5.3
CVE-2026-50365
HIGH
Remote Access Management service/API (RPC server) Elevation of Privilege Vulnerability
CVSS 8.0
CVE-2026-57107
HIGH
Windows Admin Center Elevation of Privilege Vulnerability
CVSS 7.8
CVE-2026-56185
MEDIUM
Windows Admin Center Information Disclosure Vulnerability
CVSS 6.5
CVE-2026-56169
HIGH
Windows Admin Center Elevation of Privilege Vulnerability
CVSS 8.1
CVE-2026-50338
HIGH
Azure Spring Apps Elevation of Privilege Vulnerability
CVSS 8.2
CVE-2026-22099
HIGH
EVbee DC-80 - Missing Authentication for Bluetooth Communication
CVE-2026-15557
HIGH
waooAI waoowaoo Internal Task Header api-auth.ts requireProjectAuthLight improper authentication
CVSS 7.3
CVE-2026-15542
HIGH
will-moss Isaiah Websocket Connection Authentication main.go improper authentication
CVSS 7.3
CVE-2026-15491
HIGH
RafyMrX TOKO-ONLINE-ROTI missing authentication
CVSS 7.3
CVE-2026-15089
CRITICAL
Commerce guest registration - Critical - Unsupported - SA-CONTRIB-2026-079
CVSS 9.1
Details
Vulnerabilities
4,568
Exploit Likelihood
High