When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
4,568 vulnerabilities with CWE-287
CVE-2026-15087
MEDIUM
Clean RESTful - Critical - Unsupported - SA-CONTRIB-2026-078
CVSS 5.9
CVE-2026-57216
MEDIUM
RabbitMQ PROXY Protocol Path - Remote Guest Session Authentication Bypass
CVSS 6.8
CVE-2026-12761
CRITICAL
miniOrange Social Login And Register < 7.7.0 - Authentication Bypass
CVSS 9.8
CVE-2026-55377
HIGH
Logto: Account Center MFA management step-up bypass via WebAuthn registration verification
CVSS 8.1
CVE-2026-59151
CRITICAL
Prowler: SAML Domain Claiming Enables Cross-Tenant Account Takeover
CVSS 9.6
CVE-2026-56666
MEDIUM
ZITADEL: Auto-linking by email: IdP-side email verification is not checked
CVSS 4.8
CVE-2026-55672
HIGH
ZITADEL: Missing client_id binding in OIDC authorization code exchange and refresh token flows (RFC 6749 Section 4.1.3 violation)
CVSS 7.4
CVE-2026-56675
HIGH
9router: Reverse proxy locality collapse allows unauthenticated access to 9router /v1 APIs
CVSS 8.3
CVE-2026-56312
MEDIUM
Capgo - Account Creation Before CAPTCHA Validation in accept_invitation Endpoint
CVSS 6.5
CVE-2026-12598
HIGH
LoginPress Pro <= 6.2.3 - Unauthenticated Authentication Bypass via Unverified OAuth Email in Spotify OAuth Callback
CVSS 8.1
CVE-2026-12597
HIGH
LoginPress Pro <= 6.2.3 - Unauthenticated Authentication Bypass via Unverified OAuth Email via GitHub OAuth Callback
CVSS 8.1
CVE-2026-12595
HIGH
LoginPress Pro <= 6.2.3 - Unauthenticated Authentication Bypass via Unverified OAuth Email via Discord OAuth Callback
CVSS 8.1
CVE-2026-55689
MEDIUM
OpenFGA: OIDC audience validation skipped when --authn-oidc-audience is unset
CVSS 6.8
CVE-2026-59224
HIGH
Open WebUI: Terminal proxy forwards a spoofable, integrity-unbound user identity to the upstream (X-User-Id header and ws_terminal session_id query injection)
CVSS 8.0
CVE-2026-15192
MEDIUM
mettle sendportal APIv1 Webhooks mailjet missing authentication
CVSS 6.5
CVE-2026-59208
MEDIUM
n8n: Cross-Issuer Token Exchange Account Binding via Subject-Only Identity Resolution
CVSS 6.8
CVE-2026-54781
HIGH
CoreWCF: SAML SubjectConfirmation methods and holder-of-key proof keys are not enforced
CVSS 7.4
CVE-2026-59822
HIGH
LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback
CVSS 8.2
CVE-2026-58253
HIGH
NATS Server: Route API Auth Bypass
CVSS 8.8
CVE-2026-55761
MEDIUM
Portainer: Unauthenticated Restore Endpoint Allows Admin Takeover on Uninitialised Portainer Instances
CVSS 5.9
CVE-2026-9695
CRITICAL
Dassault DELMIA Apriso 2020-2026 - Improper Authentication Privilege Escalation
CVSS 9.8
CVE-2026-55076
HIGH
Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking
CVSS 7.4
CVE-2026-37271
CRITICAL
Fire-Boltt Smartwatch FB BGS001 MOY-JS14-2.0.4 - Unauthenticated BLE Command Replay via GATT Write Request
CVSS 9.8
CVE-2026-37270
CRITICAL
Trueview T18161-AF 4.9.60.0 - Unauthenticated Auth Bypass via Hardcoded Creds & Improper Validation
CVSS 9.8
CVE-2026-55075
HIGH
Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass
CVSS 7.4
Details
Vulnerabilities
4,568
Exploit Likelihood
High