CWE-287

High likelihood

Improper Authentication

Parent: CWE-284 - Improper Access Control

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

4,570 vulnerabilities with CWE-287
CVE-2026-37270 CRITICAL
Trueview T18161-AF 4.9.60.0 - Unauthenticated Auth Bypass via Hardcoded Creds & Improper Validation
CVSS 9.8
CVE-2026-55075 HIGH
Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass
CVSS 7.4
CVE-2026-53483 CRITICAL
Dell PowerProtect Data Domain - Improper Authentication
CVSS 9.8
CVE-2026-55727 HIGH
Genetec Security Center - Improper Authentication
CVSS 7.5
CVE-2026-40139 CRITICAL
BeyondTrust Remote Support - Unauthenticated Access Control Bypass
CVSS 9.8
CVE-2026-40138 HIGH
BeyondTrust Remote Support and PRA - Unauthenticated Access Control Bypass
CVSS 8.1
CVE-2026-53913 CRITICAL
Apache Camel Keycloak 4.18.3 and 4.21.0 - Remote Code Execution
CVSS 9.8
CVE-2026-14714 MEDIUM
zhayujie chatgpt-on-wechat CowAgent wx Endpoint common.py verify_server missing authentication
CVSS 6.5
CVE-2026-14627 MEDIUM
NousResearch hermes-agent Discord Platform Integration discord.py DiscordAdapter._is_allowed_user improper authentication
CVSS 5.6
CVE-2026-12196 HIGH
HestiaCP Admin Takeover
CVE-2026-14622 HIGH
jairiidriss restaurant-website-php-mysql AJAX Endpoint ajax_files missing authentication
CVSS 7.3
CVE-2026-58423 HIGH
Gitea 1.23.0-1.26.2 LFS - Unauthorized Repository Read via SSH Sub-Verb
CVSS 7.7
CVE-2026-52830 CRITICAL
fast-mcp-telegram: Bearer token path traversal bypasses reserved Telegram session protection
CVSS 9.4
CVE-2026-58029 MEDIUM
Full Account Takeover from BotPasswords and OAuth via action=changeauthenticationdata
CVSS 6.5
CVE-2026-58399 HIGH
@acastellon/auth has an authentication bypass via spoofable headers in validateToken()
CVE-2026-11387 CRITICAL
SMS Alert <= 3.9.5 - Unauthenticated Privilege Escalation via Arbitrary Password Reset
CVSS 9.8
CVE-2026-56219 HIGH
Capgo - Unauthenticated RBAC Bindings and Email Disclosure via get_org_user_access_rbac NULL-auth Bypass
CVSS 7.5
CVE-2026-10560 HIGH
Unauthenticated Access to Private Flow Build Events and Cancellation in Langflow OSS
CVSS 8.2
CVE-2026-55955 MEDIUM
Apache Tomcat: EncryptInterceptor not protected against replay attacks
CVSS 6.5
CVE-2026-41896 HIGH
Coolify: Unauthenticated Deployment Trigger via Webhook HMAC Bypass with Null Secret
CVSS 7.5
CVE-2026-13546 HIGH
Feehi CMS REST API Endpoint articles missing authentication
CVSS 7.3
CVE-2026-13543 MEDIUM
Documenso Google OAuth Login handle-oauth-callback-url.ts improper authentication
CVSS 5.6
CVE-2026-49869 CRITICAL
Kestra: Unauthenticated Remote Code Execution via Authentication Bypass in `AuthenticationFilter`
CVSS 10.0
CVE-2026-55962 MEDIUM
TLS 1.3 post-handshake authentication: server accepts Finished without client Certificate/CertificateVerify
CVSS 6.5
CVE-2026-11703 HIGH
Missing SNI/ALPN binding on stateful (session-ID) TLS session resumption
CVSS 7.5
Details
Vulnerabilities 4,570
Exploit Likelihood High