CWE-287

High likelihood

Improper Authentication

Parent: CWE-284 - Improper Access Control

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

4,568 vulnerabilities with CWE-287
CVE-2026-53516 HIGH
Better Auth: Account takeover via OAuth auto-link to unverified pre-registered email
CVSS 8.3
CVE-2026-53514 HIGH
Better Auth: Unauthorized invitation acceptance via unverified email match in organization plugin
CVSS 7.7
CVE-2026-53512 CRITICAL
Better Auth: OAuth refresh-token replay via missing client authentication on oidc-provider and mcp plugins
CVSS 9.1
CVE-2026-59955 HIGH
Apollo ConfigService access key authentication bypass via raw config file appId parsing
CVSS 7.5
CVE-2026-59954 HIGH
Apollo ConfigService access key authentication bypass via appId parsing and non-canonical matching
CVSS 7.5
CVE-2026-47159 MEDIUM
Vaultwarden < 1.36.0 SSO Discovery - Organization Enumeration
CVE-2026-44986 CRITICAL
Penpot: Pre-authenticated account takeover via team-invitation token + prepare-register-profile
CVSS 9.9
CVE-2026-61740 CRITICAL
LightRAG: Authentication bypass: hardcoded DEFAULT_TOKEN_SECRET and public /auth-status defeat LIGHTRAG_API_KEY protection
CVE-2026-61436 HIGH
PraisonAI before 4.6.78 Missing Webhook Signature Verification
CVSS 8.6
CVE-2026-61435 HIGH
PraisonAI before 4.6.78 Authentication Bypass via Host Header Spoofing
CVSS 8.2
CVE-2026-56353 MEDIUM
n8n - Authentication Bypass in Chat Trigger Node
CVSS 4.8
CVE-2026-12281 HIGH
Shibboleth < 2.5.4 - Unauthenticated Administrator Account Creation via Identity Header Spoofing
CVSS 8.1
CVE-2026-5270 CRITICAL
Authentication Bypass in Navigator and Blue Planet Products
CVSS 9.8
CVE-2026-45363 CRITICAL
`jwt` (Ruby gem) - empty-key HMAC bypass
CVSS 9.1
CVE-2026-45754 MEDIUM
Symfony: Mailjet Mailer Webhook Parser Never Verifies the Configured Secret — Unauthenticated Webhook Event Injection
CVSS 5.3
CVE-2026-50365 HIGH
Remote Access Management service/API (RPC server) Elevation of Privilege Vulnerability
CVSS 8.0
CVE-2026-57107 HIGH
Windows Admin Center Elevation of Privilege Vulnerability
CVSS 7.8
CVE-2026-56185 MEDIUM
Windows Admin Center Information Disclosure Vulnerability
CVSS 6.5
CVE-2026-56169 HIGH
Windows Admin Center Elevation of Privilege Vulnerability
CVSS 8.1
CVE-2026-50338 HIGH
Azure Spring Apps Elevation of Privilege Vulnerability
CVSS 8.2
CVE-2026-22099 HIGH
EVbee DC-80 - Missing Authentication for Bluetooth Communication
CVE-2026-15557 HIGH
waooAI waoowaoo Internal Task Header api-auth.ts requireProjectAuthLight improper authentication
CVSS 7.3
CVE-2026-15542 HIGH
will-moss Isaiah Websocket Connection Authentication main.go improper authentication
CVSS 7.3
CVE-2026-15491 HIGH
RafyMrX TOKO-ONLINE-ROTI missing authentication
CVSS 7.3
CVE-2026-15089 CRITICAL
Commerce guest registration - Critical - Unsupported - SA-CONTRIB-2026-079
CVSS 9.1
Details
Vulnerabilities 4,568
Exploit Likelihood High