← Back
CWE-287

4,510 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

JSON object

Loading...

CVEs (4,510)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Airspan
5A5x Firmware
C5c FirmwareC5x Firmware+2 more
Jun 17, 2026
Feb 18, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x: Device versions prior to v2.5.4.1 does not perform proper authorization and authentication checks on multiple...Show more
MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x: Device versions prior to v2.5.4.1 does not perform proper authorization and authentication checks on multiple API routes. An attacker may gain access to these API routes and achieve remote code execution, create a denial-of-service condition, and obtain sensitive information.Show less
5Canonical
DebianFedoraproject+2 more
17Debian Linux
Enterprise LinuxEnterprise Linux Desktop+14 more
Jun 17, 2026
Feb 18, 2022
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
A flaw was found in the way Samba, as an Active Directory Domain Controller, implemented Kerberos name-based authentication. The Samba AD DC, could become confused about the user a ticket represents if it did not strictl...Show more
A flaw was found in the way Samba, as an Active Directory Domain Controller, implemented Kerberos name-based authentication. The Samba AD DC, could become confused about the user a ticket represents if it did not strictly require a Kerberos PAC and always use the SIDs found within. The result could include total domain compromise.Show less
5Canonical
DebianFedoraproject+2 more
24Codeready Linux Builder
Debian LinuxEnterprise Linux+21 more
Nov 21, 2024
Feb 18, 2022
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
A flaw was found in the way samba implemented SMB1 authentication. An attacker could use this flaw to retrieve the plaintext password sent over the wire even if Kerberos authentication was required.
1Helpsystems
1Cobalt Strike
Jun 17, 2026
Feb 15, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
CobaltStrike <=4.5 HTTP(S) listener does not determine whether the request URL begins with "/", and attackers can obtain relevant information by specifying the URL.
1Forgerock
1Access Management
Jun 17, 2026
Feb 14, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Missing access control in ForgeRock Access Management 7.1.0 and earlier versions on all platforms allows remote unauthenticated attackers to hijack sessions, including potentially admin-level sessions. This issue affects...Show more
Missing access control in ForgeRock Access Management 7.1.0 and earlier versions on all platforms allows remote unauthenticated attackers to hijack sessions, including potentially admin-level sessions. This issue affects: ForgeRock Access Management 7.1 versions prior to 7.1.1; 6.5 versions prior to 6.5.4; all previous versions.Show less
1Zzcms
1Zzcms
Jun 17, 2026
Feb 14, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An Incorrect Access Control vulnerability exists in zzcms 8.2, which lets a malicious user bypass authentication by changing the user name in the cookie to use any password.
1Atheme
1Atheme
Jun 17, 2026
Feb 14, 2022
N/A· v4
9.1 CRITICAL· v3
5.8 MEDIUM· v2
Atheme IRC Services before 7.2.12, when used in conjunction with InspIRCd, allows authentication bypass by ending an IRC handshake at a certain point during a challenge-response login sequence.
1Schneider Electric
1C Gate Server
Jun 17, 2026
Feb 11, 2022
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A CWE-287: Improper Authentication vulnerability exists that could allow remote code execution when a malicious file is uploaded. Affected Product: C-Bus Toolkit (V1.15.9 and prior), C-Gate Server (V2.11.7 and prior)
1Qnap
1Kazoo Server
Jun 17, 2026
Feb 11, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An improper authentication vulnerability has been reported to affect QNAP NAS running Kazoo Server. If exploited, this vulnerability allows attackers to compromise the security of the system. We have already fixed this v...Show more
An improper authentication vulnerability has been reported to affect QNAP NAS running Kazoo Server. If exploited, this vulnerability allows attackers to compromise the security of the system. We have already fixed this vulnerability in the following versions of Kazoo Server: Kazoo Server 4.11.22 and laterShow less
1Qualcomm
114Aqt1000 Firmware
Ar8031 FirmwareAr8035 Firmware+111 more
Jun 17, 2026
Feb 11, 2022
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Improper validation of program headers containing ELF metadata can lead to image verification bypass in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdrag...Show more
Improper validation of program headers containing ELF metadata can lead to image verification bypass in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and NetworkingShow less
1Gitea
1Gitea
Jun 17, 2026
Feb 9, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An Authentication Bypass vulnerability exists in Gitea before 1.5.0, which could let a malicious user gain privileges. If captured, the TOTP code for the 2FA can be submitted correctly more than once.
1Xerox
1Xmpie Ustore
Jul 9, 2026
Feb 7, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
XMPie uStore 12.3.7244.0 allows for administrators to generate reports based on raw SQL queries. Since the application ships with default administrative credentials, an attacker may authenticate into the application and...Show more
XMPie uStore 12.3.7244.0 allows for administrators to generate reports based on raw SQL queries. Since the application ships with default administrative credentials, an attacker may authenticate into the application and exfiltrate sensitive information from the database.Show less
1Starwindsoftware
2Nas
San
Jun 17, 2026
Feb 6, 2022
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
A flaw was found in StarWind Stack. The endpoint for setting a new password doesn’t check the current username and old password. An attacker could reset any local user password (including system/administrator user) using...Show more
A flaw was found in StarWind Stack. The endpoint for setting a new password doesn’t check the current username and old password. An attacker could reset any local user password (including system/administrator user) using any available user This affects StarWind SAN and NAS v0.2 build 1633.Show less
1Servisnet
1Tessa
Jun 17, 2026
Feb 6, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in Servisnet Tessa 0.0.2. An attacker can add a new sysadmin user via a manipulation of the Authorization HTTP header.
1Fleetdm
1Fleet
Jun 17, 2026
Feb 4, 2022
N/A· v4
6.5 MEDIUM· v3
3.5 LOW· v2
fleet is an open source device management, built on osquery. Versions prior to 4.9.1 expose a limited ability to spoof SAML authentication with missing audience verification. This impacts deployments using SAML SSO in tw...Show more
fleet is an open source device management, built on osquery. Versions prior to 4.9.1 expose a limited ability to spoof SAML authentication with missing audience verification. This impacts deployments using SAML SSO in two specific cases: 1. A malicious or compromised Service Provider (SP) could reuse the SAML response to log into Fleet as a user -- only if the user has an account with the same email in Fleet, _and_ the user signs into the malicious SP via SAML SSO from the same Identity Provider (IdP) configured with Fleet. 2. A user with an account in Fleet could reuse a SAML response intended for another SP to log into Fleet. This is only a concern if the user is blocked from Fleet in the IdP, but continues to have an account in Fleet. If the user is blocked from the IdP entirely, this cannot be exploited. Fleet 4.9.1 resolves this issue. Users unable to upgrade should: Reduce the length of sessions on your IdP to reduce the window for malicious re-use, Limit the amount of SAML Service Providers/Applications used by user accounts with access to Fleet, and When removing access to Fleet in the IdP, delete the Fleet user from Fleet as well.Show less
1Arista
1Eos
Jun 17, 2026
Feb 4, 2022
N/A· v4
9.8 CRITICAL· v3
6.8 MEDIUM· v2
The impact of this vulnerability is that Arista's EOS eAPI may skip re-evaluating user credentials when certificate based authentication is used, which allows remote attackers to access the device via eAPI.
1Sealevel
1Seaconnect 370w Firmware
Jun 17, 2026
Feb 4, 2022
N/A· v4
9.3 CRITICAL· v3
6.4 MEDIUM· v2
A denial of service vulnerability exists in the SeaMax remote configuration functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. Specially-crafted network packets can lead to denial of service. An attacker ca...Show more
A denial of service vulnerability exists in the SeaMax remote configuration functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. Specially-crafted network packets can lead to denial of service. An attacker can send a malicious packet to trigger this vulnerability.Show less
1Voipmonitor
1Voipmonitor
Jun 17, 2026
Feb 4, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An incorrect check in the component cdr.php of Voipmonitor GUI before v24.96 allows unauthenticated attackers to escalate privileges via a crafted request.
1Reolink
1Rlc 410w Firmware
Jun 17, 2026
Jan 28, 2022
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
An authentication bypass vulnerability exists in the cgiserver.cgi Login functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to authentication bypass. An attacker can send an...Show more
An authentication bypass vulnerability exists in the cgiserver.cgi Login functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to authentication bypass. An attacker can send an HTTP request to trigger this vulnerability.Show less
1Dell
1Integrated Dell Remote Access Controller 8 Firmware
Jun 17, 2026
Jan 25, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Dell iDRAC 8 prior to version 2.82.82.82 contain a denial of service vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability to deny access to the iDRAC webserver.