CWE-287

High likelihood

Improper Authentication

Parent: CWE-284 - Improper Access Control

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

4,568 vulnerabilities with CWE-287
CVE-2026-15087 MEDIUM
Clean RESTful - Critical - Unsupported - SA-CONTRIB-2026-078
CVSS 5.9
CVE-2026-57216 MEDIUM
RabbitMQ PROXY Protocol Path - Remote Guest Session Authentication Bypass
CVSS 6.8
CVE-2026-12761 CRITICAL
miniOrange Social Login And Register < 7.7.0 - Authentication Bypass
CVSS 9.8
CVE-2026-55377 HIGH
Logto: Account Center MFA management step-up bypass via WebAuthn registration verification
CVSS 8.1
CVE-2026-59151 CRITICAL
Prowler: SAML Domain Claiming Enables Cross-Tenant Account Takeover
CVSS 9.6
CVE-2026-56666 MEDIUM
ZITADEL: Auto-linking by email: IdP-side email verification is not checked
CVSS 4.8
CVE-2026-55672 HIGH
ZITADEL: Missing client_id binding in OIDC authorization code exchange and refresh token flows (RFC 6749 Section 4.1.3 violation)
CVSS 7.4
CVE-2026-56675 HIGH
9router: Reverse proxy locality collapse allows unauthenticated access to 9router /v1 APIs
CVSS 8.3
CVE-2026-56312 MEDIUM
Capgo - Account Creation Before CAPTCHA Validation in accept_invitation Endpoint
CVSS 6.5
CVE-2026-12598 HIGH
LoginPress Pro <= 6.2.3 - Unauthenticated Authentication Bypass via Unverified OAuth Email in Spotify OAuth Callback
CVSS 8.1
CVE-2026-12597 HIGH
LoginPress Pro <= 6.2.3 - Unauthenticated Authentication Bypass via Unverified OAuth Email via GitHub OAuth Callback
CVSS 8.1
CVE-2026-12595 HIGH
LoginPress Pro <= 6.2.3 - Unauthenticated Authentication Bypass via Unverified OAuth Email via Discord OAuth Callback
CVSS 8.1
CVE-2026-55689 MEDIUM
OpenFGA: OIDC audience validation skipped when --authn-oidc-audience is unset
CVSS 6.8
CVE-2026-59224 HIGH
Open WebUI: Terminal proxy forwards a spoofable, integrity-unbound user identity to the upstream (X-User-Id header and ws_terminal session_id query injection)
CVSS 8.0
CVE-2026-15192 MEDIUM
mettle sendportal APIv1 Webhooks mailjet missing authentication
CVSS 6.5
CVE-2026-59208 MEDIUM
n8n: Cross-Issuer Token Exchange Account Binding via Subject-Only Identity Resolution
CVSS 6.8
CVE-2026-54781 HIGH
CoreWCF: SAML SubjectConfirmation methods and holder-of-key proof keys are not enforced
CVSS 7.4
CVE-2026-59822 HIGH
LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback
CVSS 8.2
CVE-2026-58253 HIGH
NATS Server: Route API Auth Bypass
CVSS 8.8
CVE-2026-55761 MEDIUM
Portainer: Unauthenticated Restore Endpoint Allows Admin Takeover on Uninitialised Portainer Instances
CVSS 5.9
CVE-2026-9695 CRITICAL
Dassault DELMIA Apriso 2020-2026 - Improper Authentication Privilege Escalation
CVSS 9.8
CVE-2026-55076 HIGH
Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking
CVSS 7.4
CVE-2026-37271 CRITICAL
Fire-Boltt Smartwatch FB BGS001 MOY-JS14-2.0.4 - Unauthenticated BLE Command Replay via GATT Write Request
CVSS 9.8
CVE-2026-37270 CRITICAL
Trueview T18161-AF 4.9.60.0 - Unauthenticated Auth Bypass via Hardcoded Creds & Improper Validation
CVSS 9.8
CVE-2026-55075 HIGH
Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass
CVSS 7.4
Details
Vulnerabilities 4,568
Exploit Likelihood High