← Back
CWE-287

4,511 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

JSON object

Loading...

CVEs (4,511)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Google
1Android
Jun 17, 2026
Oct 6, 2021
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
Improper authentication in InputManagerService prior to SMR Oct-2021 Release 1 allows monitoring the touch event.
1Google
1Android
Jun 17, 2026
Oct 6, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
In lockAllProfileTasks of RootWindowContainer.java, there is a possible way to access the work profile without the profile PIN, after logging in. This could lead to local escalation of privilege with no additional execut...Show more
In lockAllProfileTasks of RootWindowContainer.java, there is a possible way to access the work profile without the profile PIN, after logging in. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10 Android-11 Android-8.1Android ID: A-177457096Show less
2Fedoraproject
Grafana
2Fedora
Grafana
Jun 17, 2026
Oct 5, 2021
N/A· v4
7.3 HIGH· v3
6.8 MEDIUM· v2
Grafana is an open source data visualization platform. In affected versions unauthenticated and authenticated users are able to view the snapshot with the lowest database key by accessing the literal paths: /dashboard/sn...Show more
Grafana is an open source data visualization platform. In affected versions unauthenticated and authenticated users are able to view the snapshot with the lowest database key by accessing the literal paths: /dashboard/snapshot/:key, or /api/snapshots/:key. If the snapshot "public_mode" configuration setting is set to true (vs default of false), unauthenticated users are able to delete the snapshot with the lowest database key by accessing the literal path: /api/snapshots-delete/:deleteKey. Regardless of the snapshot "public_mode" setting, authenticated users are able to delete the snapshot with the lowest database key by accessing the literal paths: /api/snapshots/:key, or /api/snapshots-delete/:deleteKey. The combination of deletion and viewing enables a complete walk through all snapshot data while resulting in complete snapshot data loss. This issue has been resolved in versions 8.1.6 and 7.5.11. If for some reason you cannot upgrade you can use a reverse proxy or similar to block access to the literal paths: /api/snapshots/:key, /api/snapshots-delete/:deleteKey, /dashboard/snapshot/:key, and /api/snapshots/:key. They have no normal function and can be disabled without side effects.Show less
1Omikron
1Multicash
Jun 17, 2026
Oct 5, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Omikron MultiCash Desktop 4.00.008.SP5 relies on a client-side authentication mechanism. When a user logs into the application, the validity of the password is checked locally. All communication to the database backend i...Show more
Omikron MultiCash Desktop 4.00.008.SP5 relies on a client-side authentication mechanism. When a user logs into the application, the validity of the password is checked locally. All communication to the database backend is made via the same technical account. Consequently, an attacker can attach a debugger to the process or create a patch that manipulates the behavior of the login function. When the function always returns the success value (corresponding to a correct password), an attacker can login with any desired account, such as the administrative account of the application.Show less
1Gitlab
1Gitlab
Jun 17, 2026
Oct 5, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
In all versions of GitLab CE/EE since version 14.1, an improper access control vulnerability allows users with expired password to still access GitLab through git and API through access tokens acquired before password ex...Show more
In all versions of GitLab CE/EE since version 14.1, an improper access control vulnerability allows users with expired password to still access GitLab through git and API through access tokens acquired before password expiration.Show less
1Bosch
12Rexroth Indramotion Mlc L20 Firmware
Rexroth Indramotion Mlc L25 FirmwareRexroth Indramotion Mlc L40 Firmware+9 more
Jun 17, 2026
Oct 4, 2021
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Login with hash: The login routine allows the client to log in to the system not by using the password, but by using the hash of the password. Combined with CVE-2021-23858, this allows an attacker to subsequently login t...Show more
Login with hash: The login routine allows the client to log in to the system not by using the password, but by using the hash of the password. Combined with CVE-2021-23858, this allows an attacker to subsequently login to the system.Show less
1Ptcl
1Hg150 Ub Firmware
Jun 17, 2026
Oct 4, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue in the administrator authentication panel of PTCL HG150-Ub v3.0 allows attackers to bypass authentication via modification of the cookie value and Response Path.
1Ibm
1Cloud Pak For Security
Jun 17, 2026
Sep 30, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
IBM Cloud Pak for Security (CP4S) 1.7.0.0, 1.7.1.0, 1.7.2.0, and 1.8.0.0 could allow an attacker to perform unauthorized actions due to improper or missing authentication controls. IBM X-Force ID: 199282.
1Fortinet
1Fortimanager
Jun 17, 2026
Sep 30, 2021
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
An improper authentication in Fortinet FortiManager version 6.4.3 and below, 6.2.6 and below allows attacker to assign arbitrary Policy and Object modules via crafted requests to the request handler.
1Ecoa
3Ecs Router Controller Ecs Firmware
Riskbuster FirmwareRiskterminator
Jun 17, 2026
Sep 30, 2021
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
ECOA BAS controller suffers from an authentication bypass vulnerability. An unauthenticated attacker through cookie poisoning can remotely bypass authentication and disclose sensitive information and circumvent physical...Show more
ECOA BAS controller suffers from an authentication bypass vulnerability. An unauthenticated attacker through cookie poisoning can remotely bypass authentication and disclose sensitive information and circumvent physical access controls in smart homes and buildings and manipulate HVAC.Show less
1Couchbase
1Couchbase Server
Jun 17, 2026
Sep 29, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Couchbase Server 6.5.x and 6.6.x through 6.6.2 has Incorrect Access Control. Externally managed users are not prevented from using an empty password, per RFC4513.
1Spomky Labs
1Webauthn Framwork
Jun 17, 2026
Sep 27, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Webauthn Framework 3.3.x before 3.3.4 has Incorrect Access Control. An attacker that controls a user's system is able to login to a vulnerable service using an attached FIDO2 authenticator without passing a check of the...Show more
Webauthn Framework 3.3.x before 3.3.4 has Incorrect Access Control. An attacker that controls a user's system is able to login to a vulnerable service using an attached FIDO2 authenticator without passing a check of the user presence.Show less
1Openvpn Monitor Project
1Openvpn Monitor
Jun 17, 2026
Sep 27, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
furlongm openvpn-monitor through 1.1.3 allows Authorization Bypass to disconnect arbitrary clients.
2D Link
Dlink
2Dcs 5000l Firmware
Dcs 932l Firmware
Jun 17, 2026
Sep 24, 2021
N/A· v4
8.0 HIGH· v3
5.2 MEDIUM· v2
DCS-5000L v1.05 and DCS-932L v2.17 and older are affecged by Incorrect Acess Control. The use of the basic authentication for the devices command interface allows attack vectors that may compromise the cameras configurat...Show more
DCS-5000L v1.05 and DCS-932L v2.17 and older are affecged by Incorrect Acess Control. The use of the basic authentication for the devices command interface allows attack vectors that may compromise the cameras configuration and allow malicious users on the LAN to access the device. NOTE: This vulnerability only affects products that are no longer supported by the maintainerShow less
1Github
1Enterprise Server
Jun 17, 2026
Sep 24, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An improper access control vulnerability in GitHub Enterprise Server allowed a workflow job to execute in a self-hosted runner group it should not have had access to. This affects customers using self-hosted runner group...Show more
An improper access control vulnerability in GitHub Enterprise Server allowed a workflow job to execute in a self-hosted runner group it should not have had access to. This affects customers using self-hosted runner groups for access control. A repository with access to one enterprise runner group could access all of the enterprise runner groups within the organization because of improper authentication checks during the request. This could cause code to be run unintentionally by the incorrect runner group. This vulnerability affected GitHub Enterprise Server versions from 3.0.0 to 3.0.15 and 3.1.0 to 3.1.7 and was fixed in 3.0.16 and 3.1.8 releases.Show less
2Infinispan
Redhat
2Data Grid
Infinispan Server Rest
Jun 17, 2026
Sep 21, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A flaw was found in Red Hat DataGrid 8.x (8.0.0, 8.0.1, 8.1.0 and 8.1.1) and Infinispan (10.0.0 through 12.0.0). An attacker could bypass authentication on all REST endpoints when DIGEST is used as the authentication met...Show more
A flaw was found in Red Hat DataGrid 8.x (8.0.0, 8.0.1, 8.1.0 and 8.1.1) and Infinispan (10.0.0 through 12.0.0). An attacker could bypass authentication on all REST endpoints when DIGEST is used as the authentication method. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.Show less
1Digi
1Portserver Ts 16 Firmware
Jun 17, 2026
Sep 17, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Properly formatted POST requests to multiple resources on the HTTP and HTTPS web servers of the Digi PortServer TS 16 Rack device do not require authentication or authentication tokens. This vulnerability could allow an...Show more
Properly formatted POST requests to multiple resources on the HTTP and HTTPS web servers of the Digi PortServer TS 16 Rack device do not require authentication or authentication tokens. This vulnerability could allow an attacker to enable the SNMP service and manipulate the community strings to achieve further control in.Show less
1Xss Hunter Express Project
1Xss Hunter Express
Jun 17, 2026
Sep 17, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
XSS Hunter Express before 2021-09-17 does not properly enforce authentication requirements for paths.
2Apache
Oracle
2Financial Services Crime And Compliance Management Studio
Shiro
Jun 17, 2026
Sep 17, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Apache Shiro before 1.8.0, when using Apache Shiro with Spring Boot, a specially crafted HTTP request may cause an authentication bypass. Users should update to Apache Shiro 1.8.0.
1Dahuasecurity
18Ipc Hum7xxx Firmware
Ipc Hx3xxx FirmwareIpc Hx5xxx Firmware+15 more
Jun 17, 2026
Sep 15, 2021
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing malicious data packets.