CWE-287

High likelihood

Improper Authentication

Parent: CWE-284 - Improper Access Control

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

4,570 vulnerabilities with CWE-287
CVE-2026-54089 CRITICAL
File Browser: Authentication Bypass via Proxy Auth Header Forgery
CVSS 9.1
CVE-2026-55759 HIGH
Rocket.Chat: Apple Sign-In skips JWT claims validation, allowing expired and cross-audience token replay
CVSS 7.4
CVE-2026-55666 CRITICAL
Rocket.Chat: Email Parameter Fallback Leads To Account Takeover Within Apple OAuth
CVE-2026-13208 MEDIUM
Kubevirt: virt-handler-rhel9: kubevirt: virt-handler notify server trusts vmi identity from unauthenticated grpc request body
CVSS 6.5
CVE-2026-56237 CRITICAL
Capgo - Unauthenticated API Key Generation via Client-Side Parameter Manipulation
CVSS 9.1
CVE-2026-56223 HIGH
Capgo - Account Takeover via Cross-Domain SSO Email Assertion in provision-user
CVSS 8.7
CVE-2026-12112 HIGH
Foreman-mcp-server: mcp server: active session hijacking via insecure session state reuse
CVSS 7.8
CVE-2026-54320 HIGH
Daytona: Cross-tenant organization takeover via invitation acceptance with an unverified email
CVSS 8.4
CVE-2026-52845 HIGH
Caddy: FastCGI header normalization bypass in `forward_auth copy_headers`
CVSS 8.1
CVE-2026-44961 NONE
Revive Adserver < 6.0.6 - Improper Authentication
CVE-2026-34917 MEDIUM
Revive Adserver < 6.0.6 - Improper Authentication
CVSS 4.3
CVE-2026-11374 CRITICAL
zohocorp manageengine_adselfservice_plus - Account Takeover via Predictable SSO Ticket Generation
CVSS 9.0
CVE-2026-7664 CRITICAL
Unauthenticated Flow Execution via Webhook Endpoint in Langflow OSS
CVSS 9.8
CVE-2026-10845 HIGH
IBM WebSphere Application Server is affected by an authentication bypass vulnerability
CVSS 7.3
CVE-2026-12795 HIGH
BerriAI litellm SSO Debug Flow ui_sso.py json.dumps missing authentication
CVSS 7.3
CVE-2026-12773 HIGH
BerriAI litellm MCP Proxy user_api_key_auth_mcp.py UserAPIKeyAuth improper authentication
CVSS 7.3
CVE-2026-56345 HIGH
AVideo - Arbitrary User Session Hijacking via Meet Plugin uploadRecordedVideo Endpoint
CVSS 8.1
CVE-2026-56294 MEDIUM
capacitor-native-biometric - Authentication Bypass via Unvalidated CryptoObject in onAuthenticationSucceeded
CVSS 4.8
CVE-2026-56080 MEDIUM
Cap-go - Authentication Logic Flaw in Enforce Password Policy
CVSS 4.9
CVE-2026-50559 HIGH
Authentication/Authorization Bypass via Advanced Path Normalization Vulnerabilities
CVSS 7.5
CVE-2026-45480 CRITICAL
Azure Active Directory Elevation of Privilege Vulnerability
CVSS 10.0
CVE-2026-49872 HIGH
Apache APISIX: Improper authentication in cas-auth plugin
CVSS 8.1
CVE-2026-32174 HIGH
Azure Bot Service Elevation of Privilege Vulnerability
CVSS 7.7
CVE-2026-49454 CRITICAL
Relyra SAML SignatureValue not cryptographically verified -> authentication bypass
CVSS 9.1
CVE-2026-11718 CRITICAL
Mcp Toolbox For Databases (googleapis/mcp-toolbox) < 1.3.0 - Improper Authentication
Details
Vulnerabilities 4,570
Exploit Likelihood High