CWE-287: Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
1,741 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-50751 — User Authentication Bypass in VPN Remote Access and Mobile Access
- CVE-2026-20182 — Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability
- CVE-2026-16232 — Authentication Bypass in the SmartConsole Login Process Using an Application Token
- CVE-2024-53704 — An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authe
- CVE-2026-82329 — Potential authentication bypass leading to administrative access in Artifactory
- CVE-2024-47533 — Cobbler allows anyone to connect to cobbler XML-RPC server with a known password and make changes
- CVE-2026-49869 — Kestra: Unauthenticated Remote Code Execution via Authentication Bypass in `AuthenticationFilter`
- CVE-2025-66039 — FreePBX Endpoint Manager Allows Unauthenticated Logins to Administrator Control Panel via Forged Basic Auth Header
- CVE-2024-0799 — Authentication Bypass via wizardLogin in Arcserve Unified Data Protection
- CVE-2026-59822 — LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback
- CVE-2024-37152 — Unauthenticated Access to sensitive settings in Argo CD
- CVE-2026-85595 — Traefik before v2.11.55 and v3.0.0 through v3.7.10 Authentication Bypass via digestAuth
- CVE-2026-4252 — Tenda AC8 IPv6 check_is_ipv6 ip address for authentication
- CVE-2026-30836 — Step CA: Unauthenticated Certificate Issuance via SCEP UpdateReq (MessageType=18)
- CVE-2026-25893 — FUXA Unauthenticated Remote Code Execution via Admin JWT Minting
- CVE-2026-24898 — OpenEMR has an Unauthenticated MedEx Token Disclosure
- CVE-2026-22236 — Improper Authentication Vulnerability in BLUVOYIX
- CVE-2025-9265 — API Authentication Bypass via Header Spoofing vulnerability in Kiloview NDI N30 Products
- CVE-2025-7574 — LB-LINK BL-WR9000 Web Interface lighttpd.cgi restore improper authentication
- CVE-2025-5597 — WF Steuerungstechnik GmbH - airleader MASTER - Authentication Bypass
Recently published
- CVE-2026-87806 — Parse Server 9.0.0 Authentication Bypass via LDAP Empty Password
- CVE-2026-79974 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains
- CVE-2026-80099 — Various Newfold Plugins Various Versions - Unauthenticated Authentication Bypass via Bearer Token Validation with Empty Secret
- CVE-2026-76009 — Next-Cart Store to WooCommerce Migration <= 3.9.8 - Unauthenticated Authentication Bypass via Default '__token__' Fallback in REST Migration Endpoint
- CVE-2026-78560 — Improper Authentication Validation in Okta Access Gateway Pass-Through Authentication Source
- CVE-2026-86810 — Open-Web-Analytics Controller Controller.php checkCapabilityAndAuthenticateUser improper authentication
- CVE-2026-86808 — moltis-org moltis vault.rs vault_recovery_handler missing authentication
- CVE-2026-86669 — aircheng-org iWebShop-5 systemseller.php login improper authentication
- CVE-2026-86723 — AVideo LoginControl PGP Authentication Bypass via verifyChallenge
- CVE-2026-86722 — AVideo Authentication Bypass via SQL Cache Invalidation
- CVE-2026-86721 — AVideo through c3edcc274c Authorization Bypass via Session Cookie
- CVE-2026-82758 — ash_authentication_oauth2_server treats an empty resolved secret as valid, opening the gated Dynamic Client Registration endpoint
- CVE-2026-18922 — 389-ds-base: 389-ds-base: sasl plain authentication allows privilege escalation to directory manager via stale identity in cyrus sasl auxiliary property
- CVE-2026-80128 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains
- CVE-2026-86306 — light0011 cms Cookie Helper UserModel.class.php improper authentication
- CVE-2026-86426 — LibreNMS before 26.8.0 Authentication Bypass via API Token Type Confusion
- CVE-2026-86300 — Tenda AC9 Web Management R7WebsSecurityHandler improper authentication
- CVE-2026-86293 — SourceCodester Simple Traffic Offense System Deletion Endpoint delete-user.php missing authentication
- CVE-2026-86292 — SourceCodester Simple Traffic Offense System User Creation saveuser.php missing authentication
- CVE-2026-86214 — Mstfakts College-Management-System login.php improper authentication