CWE-287: Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

732
Total CVEs
321
Critical
295
High
8.3
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
65
2025
217
2024
134
2023
115
2022
70

Top Affected Vendors

1 Apache 15
2 Qualcomm 12
3 Microsoft 11
4 Huawei 10
5 Debian 10
6 Dlink 9
7 Dell 9
8 Fedoraproject 8
9 Adobe 8
10 Redhat 7

All Improper Authentication CVEs (732)

CVE-2026-24898
10.0

OpenEMR versions before 8.0.0 contain an unauthenticated token disclosure vulnerability in the MedEx callback endpoint. Any unauthenticated visitor ca...

Mar 3, 2026
CVE-2026-20127
10.0

This critical authentication bypass vulnerability in Cisco Catalyst SD-WAN Controller and Manager allows unauthenticated remote attackers to gain admi...

Feb 25, 2026
CVE-2025-70841
10.0

CVE-2025-70841 allows unauthenticated attackers to access the .env configuration file in Dokans Multi-Tenancy eCommerce Platform, exposing sensitive c...

Feb 3, 2026
CVE-2025-44005
10.0

This critical vulnerability in Step CA allows attackers to bypass authorization checks in ACME or SCEP provisioners, enabling unauthorized certificate...

Dec 17, 2025
CVE-2025-63224
10.0

This vulnerability allows attackers to bypass authentication on Itel DAB Encoder devices by reusing a valid JWT token from one device to gain administ...

Nov 19, 2025
CVE-2025-63216
10.0

This vulnerability allows attackers to bypass authentication on Itel DAB Gateway devices by reusing a valid JWT token from one device to gain administ...

Nov 18, 2025
CVE-2025-55241
10.0

This critical vulnerability in Azure Entra ID (formerly Azure Active Directory) allows attackers to elevate privileges to Global Administrator level. ...

Sep 4, 2025
CVE-2025-54419
10.0

CVE-2025-54419 is a critical authentication bypass vulnerability in Node-SAML library versions 5.0.1 and earlier. It allows attackers to modify authen...

Jul 28, 2025
CVE-2025-32975
10.0

This CVE describes an authentication bypass vulnerability in Quest KACE Systems Management Appliance that allows attackers to impersonate legitimate u...

Jun 24, 2025
CVE-2024-11186
10.0

This vulnerability allows authenticated users with limited permissions in Arista CloudVision Portal to perform unauthorized actions on managed EOS dev...

May 8, 2025
CVE-2025-46348
10.0

CVE-2025-46348 is an authentication bypass vulnerability in YesWiki that allows unauthenticated attackers to trigger and download site backups. The pr...

Apr 29, 2025
CVE-2024-30299
10.0

Adobe Framemaker Publishing Server versions 2020.3, 2022.2 and earlier contain an improper authentication vulnerability that allows attackers to bypas...

Jun 13, 2024
CVE-2024-27767
10.0

CVE-2024-27767 is an authentication bypass vulnerability that allows attackers to gain unauthorized access to systems without valid credentials. This ...

Mar 18, 2024
CVE-2023-2024
10.0

This vulnerability allows unauthorized users to bypass authentication in OpenBlue Enterprise Manager Data Collector under certain circumstances. It af...

May 18, 2023
CVE-2023-1778
10.0

This vulnerability allows remote attackers to gain superuser access to GajShield Data Security Firewall devices using default credentials. Attackers c...

Apr 27, 2023
CVE-2023-27482
10.0

This vulnerability allows unauthenticated remote attackers to bypass authentication and access the Supervisor API in Home Assistant, potentially gaini...

Mar 8, 2023
CVE-2022-31125
10.0

CVE-2022-31125 is an authentication bypass vulnerability in Roxy-wi web interface that allows unauthenticated remote attackers to access administrativ...

Jul 6, 2022
CVE-2021-32637
10.0

CVE-2021-32637 is an authentication bypass vulnerability in Authelia that allows attackers to bypass SSO authentication by sending malformed HTTP requ...

May 28, 2021
CVE-2021-22893
10.0

CVE-2021-22893 is an authentication bypass vulnerability in Pulse Connect Secure that allows unauthenticated attackers to execute arbitrary code on th...

Apr 23, 2021
CVE-2025-0070
9.9

CVE-2025-0070 is an authentication bypass vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Platform that allows authenticated attac...

Jan 14, 2025
CVE-2023-51482
9.9

This vulnerability in Eazy Plugin Manager for WordPress allows attackers with subscriber-level access to bypass authentication and update arbitrary pl...

Apr 25, 2024
CVE-2023-40020
9.9

CVE-2023-40020 is an authentication bypass vulnerability in PrivateUploader that allows non-admin users to execute admin-only API endpoints. The vulne...

Aug 14, 2023
CVE-2023-33190
9.9

CVE-2023-33190 is a critical RBAC misconfiguration vulnerability in Sealos that allows attackers to gain full cluster control permissions. This enable...

Jun 29, 2023
CVE-2023-23857
9.9

CVE-2023-23857 is an authentication bypass vulnerability in SAP NetWeaver AS for Java that allows unauthenticated attackers to access sensitive naming...

Mar 14, 2023
CVE-2026-20129
9.8

This critical authentication bypass vulnerability in Cisco Catalyst SD-WAN Manager allows unauthenticated remote attackers to gain netadmin privileges...

Feb 25, 2026
CVE-2026-2248
9.8

METIS WIC devices with firmware versions up to oscore 2.1.234-r18 expose an unauthenticated web-based shell at the /console endpoint. This allows remo...

Feb 11, 2026
CVE-2026-23906
9.8

This authentication bypass vulnerability in Apache Druid allows attackers to gain unauthorized access by exploiting LDAP anonymous bind configurations...

Feb 10, 2026
CVE-2022-25369
EPSS 70.4% 9.8

CVE-2022-25369 is an authentication bypass vulnerability in Dynamicweb CMS that allows unauthenticated attackers to create new administrator accounts....

Jan 23, 2026
CVE-2025-37184
9.8

This vulnerability allows unauthenticated remote attackers to bypass multi-factor authentication requirements in an Orchestrator service, enabling the...

Jan 14, 2026
CVE-2026-22236
9.8

This critical authentication bypass vulnerability in BLUVOYIX allows unauthenticated attackers to send crafted HTTP requests to backend APIs and gain ...

Jan 14, 2026
CVE-2026-21854
9.8

An authentication bypass vulnerability in Tarkov Data Manager allows unauthenticated attackers to gain full admin access by exploiting JavaScript prot...

Jan 7, 2026
CVE-2025-14942
9.8

A critical authentication bypass vulnerability in wolfSSH's key exchange state machine allows attackers to manipulate the authentication process. This...

Jan 6, 2026
CVE-2025-60534
9.8

Blue Access Cobalt v02.000.195 has an authentication bypass vulnerability that allows attackers to proxy requests and access web application functiona...

Jan 6, 2026
CVE-2025-68926
9.8

This vulnerability allows attackers to bypass authentication in RustFS by using a hardcoded static token that is publicly exposed in the source code. ...

Dec 30, 2025
CVE-2025-56333
9.8

A critical authentication bypass vulnerability in Fossorial Pangolin's 2FA component allows remote attackers to escalate privileges without proper aut...

Dec 29, 2025
CVE-2025-67791
9.8

An authentication misconfiguration in DriveLock Enterprise Service (DES) allows attackers to impersonate any DriveLock agent on the network. This affe...

Dec 17, 2025
CVE-2025-66039
EPSS 23.7% 9.8

FreePBX Endpoint Manager versions before 16.0.44 and 17.0.23 contain an authentication bypass vulnerability when using webserver authentication. Attac...

Dec 9, 2025
CVE-2025-64055
9.8

CVE-2025-64055 is an authentication bypass vulnerability in Fanvil x210 V2 IP phones that allows unauthenticated attackers on the local network to acc...

Dec 3, 2025
CVE-2025-63210
9.8

This vulnerability allows attackers to bypass authentication on Newtec Celox UHD satellite modems by forging responses during login. Attackers can gai...

Nov 19, 2025
CVE-2025-63207
9.8

This vulnerability allows unauthenticated attackers to change all user passwords (Admin, Operator, User) on R.V.R Elettronica TEX devices by sending a...

Nov 19, 2025
CVE-2025-64717
9.8

This vulnerability in ZITADEL identity management platform allows unauthenticated attackers to bypass organization security controls and perform accou...

Nov 13, 2025
CVE-2025-64103
9.8

This vulnerability allows attackers to bypass multi-factor authentication (MFA) in Zitadel by targeting only the TOTP code without requiring password ...

Oct 29, 2025
CVE-2025-43995
9.8

CVE-2025-43995 is an authentication bypass vulnerability in Dell Storage Manager that allows unauthenticated remote attackers to access protected APIs...

Oct 24, 2025
CVE-2025-56447
9.8

TM2 Monitoring v3.04 contains an authentication bypass vulnerability that allows attackers to access the system without valid credentials, combined wi...

Oct 22, 2025
CVE-2025-41108
9.8

CVE-2025-41108 allows attackers to gain full unauthorized control of Ghost Robotics Vision 60 robots by impersonating legitimate control stations. Thi...

Oct 22, 2025
CVE-2025-60772
9.8

CVE-2025-60772 is an authentication bypass vulnerability in NETLINK HG322G GPON ONT devices that allows unauthenticated attackers to gain administrati...

Oct 21, 2025
CVE-2025-11625
9.8

An improper host authentication vulnerability in wolfSSH clients up to version 1.4.20 allows attackers to bypass authentication and potentially leak c...

Oct 21, 2025
CVE-2025-9063
9.8

An authentication bypass vulnerability in FactoryTalk View Machine Edition's Web Browser ActiveX control allows attackers to gain unauthorized access ...

Oct 14, 2025
CVE-2025-61882
KEV EPSS 88.1% 9.8

This critical vulnerability in Oracle E-Business Suite's Concurrent Processing component allows unauthenticated attackers to remotely execute arbitrar...

Oct 5, 2025
CVE-2025-9994
9.8

The Amp'ed RF BT-AP 111 Bluetooth access point's HTTP admin interface lacks authentication, allowing anyone with network access to gain administrative...

Sep 9, 2025

About Improper Authentication (CWE-287)

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Our database tracks 732 CVEs classified as CWE-287, with 321 rated critical and 295 rated high severity. The average CVSS score for Improper Authentication vulnerabilities is 8.3.

External reference: View CWE-287 on MITRE CWE →

Monitor Improper Authentication Vulnerabilities

Get alerted when new Improper Authentication CVEs affect your infrastructure.

Start Monitoring Free