CWE-287: Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

782
Total CVEs
346
Critical
320
High
8.4
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
67
2025
217
2024
134
2023
115
2022
70

Top Affected Vendors

1 Apache 15
2 Huawei 12
3 Qualcomm 12
4 Microsoft 11
5 Debian 10
6 Dlink 10
7 Cisco 10
8 Dell 9
9 Google 8
10 Fedoraproject 8

All Improper Authentication CVEs (782)

CVE-2022-48494
7.5

This vulnerability allows malicious apps to bypass identity verification during pre-authorization, potentially gaining unauthorized access to system r...

Jun 19, 2023
CVE-2022-48496
7.5

This vulnerability allows malicious applications to bypass proper identity verification during pre-authorization processes. Attackers can exploit this...

Jun 19, 2023
CVE-2023-30063
7.5

This vulnerability allows attackers to bypass authentication on D-Link DIR-890L routers running firmware version 1.10 A1. Attackers can gain unauthori...

May 1, 2023
CVE-2023-21027
7.5

This CVE describes an authentication misconfiguration vulnerability in Android's PasspointXmlUtils.java that could allow remote information disclosure...

Mar 24, 2023
CVE-2022-47508
7.5

This vulnerability in SolarWinds SAM occurs when polling via IP address forces NTLM authentication instead of the expected Kerberos, potentially expos...

Feb 15, 2023
CVE-2016-0796
7.5

CVE-2016-0796 affects WordPress mb.miniAudioPlayer plugin versions up to 1.7.6, allowing attackers to bypass security controls and download arbitrary ...

Jul 28, 2022
CVE-2022-31164
7.5

CVE-2022-31164 is an authentication bypass vulnerability in Tovy, a Roblox group staff management system. It allows any user to log in as other users,...

Jul 22, 2022
CVE-2022-32276
7.5

CVE-2022-32276 allows unauthenticated access to Grafana dashboard snapshots via specific URLs, bypassing authentication requirements. This affects Gra...

Jun 17, 2022
CVE-2018-18907
7.5

This vulnerability allows attackers to bypass WPA2 encryption on D-Link DIR-850L routers by exploiting an incomplete WPA handshake. Attackers can send...

Jun 16, 2022
CVE-2022-29865
7.5

CVE-2022-29865 is an authentication bypass vulnerability in the OPC UA .NET Standard Stack that allows remote attackers to bypass application authenti...

Jun 16, 2022
CVE-2022-26975
7.5

Barco Control Room Management Suite web application exposes log files without requiring authentication. This allows attackers to read sensitive system...

Jun 2, 2022
CVE-2022-24901
7.5

This vulnerability allows attackers to bypass authentication in Parse Server's Apple Game Center adapter by exploiting improper URL validation of Appl...

May 4, 2022
CVE-2022-29534
7.5

This vulnerability allows attackers to bypass password confirmation requirements in MISP by sending requests with an 'Accept: application/json' header...

Apr 20, 2022
CVE-2021-46740
7.5

CVE-2021-46740 is an authentication bypass vulnerability in Huawei/HarmonyOS device authentication service modules. It allows attackers to bypass auth...

Apr 11, 2022
CVE-2021-26620
7.5

This vulnerability in iptime NAS2dual devices allows remote attackers to bypass authentication mechanisms and access shared folders or change user pas...

Mar 25, 2022
CVE-2022-23317
7.5

CVE-2022-23317 is an improper authentication vulnerability in Cobalt Strike's HTTP(S) listener that allows attackers to bypass authentication by sendi...

Feb 15, 2022
CVE-2022-23320
7.5

XMPie uStore 12.3.7244.0 contains a vulnerability where administrators can execute raw SQL queries through report generation functionality. Since the ...

Feb 7, 2022
CVE-2021-41311
7.5

This vulnerability allows attackers with revoked administrator accounts to modify project Users & Roles settings in Atlassian Jira Server and Data Cen...

Dec 8, 2021
CVE-2021-37043
7.5

CVE-2021-37043 is a stack-based buffer overflow vulnerability in Huawei smartphones running HarmonyOS. Successful exploitation could allow malicious a...

Dec 7, 2021
CVE-2021-43203
7.5

This vulnerability in JetBrains Ktor allows improper nonce verification during OAuth2 authentication, potentially enabling attackers to bypass authent...

Nov 9, 2021
CVE-2021-37624
7.5

FreeSWITCH versions before 1.10.7 do not authenticate SIP MESSAGE requests by default, allowing attackers to send spoofed chat messages to registered ...

Oct 25, 2021
CVE-2021-30302
7.5

This vulnerability allows improper authentication of EAP WAPI EAPOL frames from unauthenticated users, potentially leading to information disclosure. ...

Oct 20, 2021
CVE-2021-39215
7.5

This vulnerability in Jitsi Meet allows attackers to forge JSON Web Tokens using symmetric algorithms to gain unauthorized access to protected video c...

Sep 15, 2021
CVE-2021-36370
7.5

This vulnerability in Midnight Commander's SFTP implementation fails to verify server fingerprints during connection establishment. This allows man-in...

Aug 30, 2021
CVE-2021-22025
7.5

CVE-2021-22025 is a broken access control vulnerability in VMware vRealize Operations Manager API that allows unauthenticated attackers to add new nod...

Aug 30, 2021
CVE-2021-37172
7.5

This vulnerability allows attackers to bypass authentication on Siemens SIMATIC S7-1200 PLCs when provisioned with TIA Portal V13, enabling unauthoriz...

Aug 10, 2021
CVE-2020-16839
7.5

This vulnerability allows unauthenticated attackers to change passwords on Crestron DM-NVX devices via WebSocket requests. It affects Crestron DM-NVX-...

Jul 30, 2021
CVE-2021-34675
7.5

CVE-2021-34675 is an authentication bypass vulnerability in Basix NEX-Forms WordPress plugin that allows unauthenticated attackers to access stored PD...

Jul 19, 2021
CVE-2020-22176
7.5

CVE-2020-22176 allows remote unauthenticated attackers to access sensitive user information in PHPGurukul Hospital Management System v4.0. This affect...

Jun 22, 2021
CVE-2020-14380
7.5

This vulnerability allows attackers with valid external authentication (SSO or OpenID) to impersonate existing local users in Red Hat Satellite, gaini...

Jun 2, 2021
CVE-2021-20092
7.5

This vulnerability allows unauthorized actors to access sensitive information through the web interfaces of affected Buffalo routers. It affects users...

Apr 29, 2021
CVE-2021-20590
7.5

This vulnerability allows remote unauthenticated attackers to bypass authentication in Mitsubishi Electric GOT2000 and GOT SIMPLE series HMI VNC serve...

Apr 22, 2021
CVE-2020-28973
7.5

The ABUS Secvest wireless alarm system FUAA50000 fails to properly authenticate requests to its HTTPS interface, allowing attackers to obtain sensitiv...

Apr 21, 2021
CVE-2021-27990
7.5

CVE-2021-27990 is an authentication bypass vulnerability in Appspace 6.2.4 that allows attackers to directly access sensitive pages like /medianet/mai...

Apr 14, 2021
CVE-2021-22496
7.5

CVE-2021-22496 is an authentication bypass vulnerability in Micro Focus Access Manager that allows attackers to bypass authentication mechanisms and p...

Mar 25, 2021
CVE-2021-3282
7.5

HashiCorp Vault Enterprise versions 1.6.0 and 1.6.1 allow unauthenticated execution of the 'remove-peer' raft operator command on DR (Disaster Recover...

Feb 1, 2021
CVE-2020-28874
7.5

CVE-2020-28874 is an authentication bypass vulnerability in ProjectSend's password reset functionality. Attackers can reset any user's password withou...

Jan 26, 2021
CVE-2020-24641
7.5

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in Aruba AirWave Glass versions before 1.3.3. Attackers can exploit an unauthent...

Jan 15, 2021
CVE-2020-5686
7.5

This vulnerability allows attackers to bypass authentication in NEC UNIVERGE SV9500 and SV8500 PBX systems by sending specially crafted requests to a ...

Jan 13, 2021
CVE-2020-36176
7.5

The iThemes Security plugin for WordPress before version 7.7.0 fails to enforce password changes immediately when required, allowing users to continue...

Jan 6, 2021
CVE-2020-27254
7.5

This vulnerability allows attackers to bypass authentication and access sensitive log and backup data on Emerson Rosemount X-STREAM gas analyzers. By ...

Dec 21, 2020
CVE-2020-27199
7.5

CVE-2020-27199 allows attackers to bypass authentication in the Magic Home Pro Android app by forging user tokens without valid credentials. This affe...

Dec 17, 2020
CVE-2020-0460
7.5

This vulnerability in Android's certificate installer allows improperly installed certificates due to a logic error, potentially enabling remote infor...

Dec 14, 2020
CVE-2020-27408
7.5

CVE-2020-27408 allows unauthenticated attackers to reset passwords for any user in OpenSIS Community Edition. This affects all OpenSIS Community Editi...

Dec 4, 2020
CVE-2021-29487
7.4

CVE-2021-29487 is an authentication bypass vulnerability in October CMS that allows unauthenticated attackers to take over user accounts. Attackers ne...

Aug 26, 2021
CVE-2026-3053
7.3

This CVE describes an authentication bypass vulnerability in DataLinkDC Dinky's OpenAPI endpoint. Attackers can remotely exploit this to access admini...

Feb 24, 2026
CVE-2025-10463
7.3

CVE-2025-10463 is an improper authentication vulnerability in Birtech Senseway that allows attackers to bypass authentication mechanisms and gain unau...

Feb 9, 2026
CVE-2026-2174
7.3

CVE-2026-2174 is an authentication bypass vulnerability in code-projects Contact Management System 1.0 that allows attackers to manipulate CRUD endpoi...

Feb 8, 2026
CVE-2026-2165
7.3

CVE-2026-2165 is an authentication bypass vulnerability in detronetdip E-commerce 1.0.0 that allows unauthenticated attackers to create admin accounts...

Feb 8, 2026
CVE-2026-1740
7.3

This vulnerability allows remote attackers to bypass authentication on EFM ipTIME A8004T routers via improper authentication in the Hidden Hiddenlogin...

Feb 2, 2026

About Improper Authentication (CWE-287)

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Our database tracks 782 CVEs classified as CWE-287, with 346 rated critical and 320 rated high severity. The average CVSS score for Improper Authentication vulnerabilities is 8.4.

External reference: View CWE-287 on MITRE CWE →

Monitor Improper Authentication Vulnerabilities

Get alerted when new Improper Authentication CVEs affect your infrastructure.

Start Monitoring Free