CWE-287: Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Yearly Trend
Top Affected Vendors
All Improper Authentication CVEs (782)
This vulnerability allows malicious apps to bypass identity verification during pre-authorization, potentially gaining unauthorized access to system r...
Jun 19, 2023This vulnerability allows malicious applications to bypass proper identity verification during pre-authorization processes. Attackers can exploit this...
Jun 19, 2023This vulnerability allows attackers to bypass authentication on D-Link DIR-890L routers running firmware version 1.10 A1. Attackers can gain unauthori...
May 1, 2023This CVE describes an authentication misconfiguration vulnerability in Android's PasspointXmlUtils.java that could allow remote information disclosure...
Mar 24, 2023This vulnerability in SolarWinds SAM occurs when polling via IP address forces NTLM authentication instead of the expected Kerberos, potentially expos...
Feb 15, 2023CVE-2016-0796 affects WordPress mb.miniAudioPlayer plugin versions up to 1.7.6, allowing attackers to bypass security controls and download arbitrary ...
Jul 28, 2022CVE-2022-31164 is an authentication bypass vulnerability in Tovy, a Roblox group staff management system. It allows any user to log in as other users,...
Jul 22, 2022CVE-2022-32276 allows unauthenticated access to Grafana dashboard snapshots via specific URLs, bypassing authentication requirements. This affects Gra...
Jun 17, 2022This vulnerability allows attackers to bypass WPA2 encryption on D-Link DIR-850L routers by exploiting an incomplete WPA handshake. Attackers can send...
Jun 16, 2022CVE-2022-29865 is an authentication bypass vulnerability in the OPC UA .NET Standard Stack that allows remote attackers to bypass application authenti...
Jun 16, 2022Barco Control Room Management Suite web application exposes log files without requiring authentication. This allows attackers to read sensitive system...
Jun 2, 2022This vulnerability allows attackers to bypass authentication in Parse Server's Apple Game Center adapter by exploiting improper URL validation of Appl...
May 4, 2022This vulnerability allows attackers to bypass password confirmation requirements in MISP by sending requests with an 'Accept: application/json' header...
Apr 20, 2022CVE-2021-46740 is an authentication bypass vulnerability in Huawei/HarmonyOS device authentication service modules. It allows attackers to bypass auth...
Apr 11, 2022This vulnerability in iptime NAS2dual devices allows remote attackers to bypass authentication mechanisms and access shared folders or change user pas...
Mar 25, 2022CVE-2022-23317 is an improper authentication vulnerability in Cobalt Strike's HTTP(S) listener that allows attackers to bypass authentication by sendi...
Feb 15, 2022XMPie uStore 12.3.7244.0 contains a vulnerability where administrators can execute raw SQL queries through report generation functionality. Since the ...
Feb 7, 2022This vulnerability allows attackers with revoked administrator accounts to modify project Users & Roles settings in Atlassian Jira Server and Data Cen...
Dec 8, 2021CVE-2021-37043 is a stack-based buffer overflow vulnerability in Huawei smartphones running HarmonyOS. Successful exploitation could allow malicious a...
Dec 7, 2021This vulnerability in JetBrains Ktor allows improper nonce verification during OAuth2 authentication, potentially enabling attackers to bypass authent...
Nov 9, 2021FreeSWITCH versions before 1.10.7 do not authenticate SIP MESSAGE requests by default, allowing attackers to send spoofed chat messages to registered ...
Oct 25, 2021This vulnerability allows improper authentication of EAP WAPI EAPOL frames from unauthenticated users, potentially leading to information disclosure. ...
Oct 20, 2021This vulnerability in Jitsi Meet allows attackers to forge JSON Web Tokens using symmetric algorithms to gain unauthorized access to protected video c...
Sep 15, 2021This vulnerability in Midnight Commander's SFTP implementation fails to verify server fingerprints during connection establishment. This allows man-in...
Aug 30, 2021CVE-2021-22025 is a broken access control vulnerability in VMware vRealize Operations Manager API that allows unauthenticated attackers to add new nod...
Aug 30, 2021This vulnerability allows attackers to bypass authentication on Siemens SIMATIC S7-1200 PLCs when provisioned with TIA Portal V13, enabling unauthoriz...
Aug 10, 2021This vulnerability allows unauthenticated attackers to change passwords on Crestron DM-NVX devices via WebSocket requests. It affects Crestron DM-NVX-...
Jul 30, 2021CVE-2021-34675 is an authentication bypass vulnerability in Basix NEX-Forms WordPress plugin that allows unauthenticated attackers to access stored PD...
Jul 19, 2021CVE-2020-22176 allows remote unauthenticated attackers to access sensitive user information in PHPGurukul Hospital Management System v4.0. This affect...
Jun 22, 2021This vulnerability allows attackers with valid external authentication (SSO or OpenID) to impersonate existing local users in Red Hat Satellite, gaini...
Jun 2, 2021This vulnerability allows unauthorized actors to access sensitive information through the web interfaces of affected Buffalo routers. It affects users...
Apr 29, 2021This vulnerability allows remote unauthenticated attackers to bypass authentication in Mitsubishi Electric GOT2000 and GOT SIMPLE series HMI VNC serve...
Apr 22, 2021The ABUS Secvest wireless alarm system FUAA50000 fails to properly authenticate requests to its HTTPS interface, allowing attackers to obtain sensitiv...
Apr 21, 2021CVE-2021-27990 is an authentication bypass vulnerability in Appspace 6.2.4 that allows attackers to directly access sensitive pages like /medianet/mai...
Apr 14, 2021CVE-2021-22496 is an authentication bypass vulnerability in Micro Focus Access Manager that allows attackers to bypass authentication mechanisms and p...
Mar 25, 2021HashiCorp Vault Enterprise versions 1.6.0 and 1.6.1 allow unauthenticated execution of the 'remove-peer' raft operator command on DR (Disaster Recover...
Feb 1, 2021CVE-2020-28874 is an authentication bypass vulnerability in ProjectSend's password reset functionality. Attackers can reset any user's password withou...
Jan 26, 2021This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in Aruba AirWave Glass versions before 1.3.3. Attackers can exploit an unauthent...
Jan 15, 2021This vulnerability allows attackers to bypass authentication in NEC UNIVERGE SV9500 and SV8500 PBX systems by sending specially crafted requests to a ...
Jan 13, 2021The iThemes Security plugin for WordPress before version 7.7.0 fails to enforce password changes immediately when required, allowing users to continue...
Jan 6, 2021This vulnerability allows attackers to bypass authentication and access sensitive log and backup data on Emerson Rosemount X-STREAM gas analyzers. By ...
Dec 21, 2020CVE-2020-27199 allows attackers to bypass authentication in the Magic Home Pro Android app by forging user tokens without valid credentials. This affe...
Dec 17, 2020This vulnerability in Android's certificate installer allows improperly installed certificates due to a logic error, potentially enabling remote infor...
Dec 14, 2020CVE-2020-27408 allows unauthenticated attackers to reset passwords for any user in OpenSIS Community Edition. This affects all OpenSIS Community Editi...
Dec 4, 2020CVE-2021-29487 is an authentication bypass vulnerability in October CMS that allows unauthenticated attackers to take over user accounts. Attackers ne...
Aug 26, 2021This CVE describes an authentication bypass vulnerability in DataLinkDC Dinky's OpenAPI endpoint. Attackers can remotely exploit this to access admini...
Feb 24, 2026CVE-2025-10463 is an improper authentication vulnerability in Birtech Senseway that allows attackers to bypass authentication mechanisms and gain unau...
Feb 9, 2026CVE-2026-2174 is an authentication bypass vulnerability in code-projects Contact Management System 1.0 that allows attackers to manipulate CRUD endpoi...
Feb 8, 2026CVE-2026-2165 is an authentication bypass vulnerability in detronetdip E-commerce 1.0.0 that allows unauthenticated attackers to create admin accounts...
Feb 8, 2026This vulnerability allows remote attackers to bypass authentication on EFM ipTIME A8004T routers via improper authentication in the Hidden Hiddenlogin...
Feb 2, 2026About Improper Authentication (CWE-287)
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Our database tracks 782 CVEs classified as CWE-287, with 346 rated critical and 320 rated high severity. The average CVSS score for Improper Authentication vulnerabilities is 8.4.
External reference: View CWE-287 on MITRE CWE →
Monitor Improper Authentication Vulnerabilities
Get alerted when new Improper Authentication CVEs affect your infrastructure.
Start Monitoring Free