← Back
CWE-287

4,464 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

JSON object

Loading...

CVEs (4,464)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Gotenna
1Gotenna Pro
Jun 17, 2026
Sep 26, 2024
7.6 HIGH· v4
5.4 MEDIUM· v3
N/A· v2
The goTenna Pro App does not authenticate public keys which allows an unauthenticated attacker to manipulate messages. It is advised to update your app to the current release for enhanced encryption protocols.
-
-
Jun 17, 2026
Sep 26, 2024
N/A· v4
4.4 MEDIUM· v3
N/A· v2
Ory Kratos is an identity, user management and authentication system for cloud services. Prior to version 1.3.0, given a number of preconditions, the `highest_available` setting will incorrectly assume that the identity’...Show more
Ory Kratos is an identity, user management and authentication system for cloud services. Prior to version 1.3.0, given a number of preconditions, the `highest_available` setting will incorrectly assume that the identity’s highest available AAL is `aal1` even though it really is `aal2`. This means that the `highest_available` configuration will act as if the user has only one factor set up, for that particular user. This means that they can call the settings and whoami endpoint without a `aal2` session, even though that should be disallowed. An attacker would need to steal or guess a valid login OTP of a user who has only OTP for login enabled and who has an incorrect `available_aal` value stored, to exploit this vulnerability. All other aspects of the session (e.g. the session’s aal) are not impacted by this issue. On the Ory Network, only 0.00066% of registered users were affected by this issue, and most of those users appeared to be test users. Their respective AAL values have since been updated and they are no longer vulnerable to this attack. Version 1.3.0 is not affected by this issue. As a workaround, those who require MFA should disable the passwordless code login method. If that is not possible, check the sessions `aal` to identify if the user has `aal1` or `aal2`.Show less
-
-
Jun 17, 2026
Sep 25, 2024
N/A· v4
7.3 HIGH· v3
N/A· v2
An issue in TheGreenBow Windows Standard VPN Client 6.87.108 (and older), Windows Enterprise VPN Client 6.87.109 (and older), Windows Enterprise VPN Client 7.5.007 (and older), Android VPN Client 6.4.5 (and older) VPN Cl...Show more
An issue in TheGreenBow Windows Standard VPN Client 6.87.108 (and older), Windows Enterprise VPN Client 6.87.109 (and older), Windows Enterprise VPN Client 7.5.007 (and older), Android VPN Client 6.4.5 (and older) VPN Client Linux 3.4 (and older), VPN Client MacOS 2.4.10 (and older) allows a remote attacker to execute arbitrary code via the IKEv2 Authentication phase, it accepts malformed ECDSA signatures and establishes the tunnel.Show less
1Meshtastic
1Meshtastic Firmware
Jun 17, 2026
Sep 25, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Meshtastic is an open source, off-grid, decentralized, mesh network. Meshtastic uses MQTT to communicate over an internet connection to a shared or private MQTT Server. Nodes can communicate directly via an internet conn...Show more
Meshtastic is an open source, off-grid, decentralized, mesh network. Meshtastic uses MQTT to communicate over an internet connection to a shared or private MQTT Server. Nodes can communicate directly via an internet connection or proxied through a connected phone (i.e., via bluetooth). Prior to version 2.5.1, multiple weaknesses in the MQTT implementation allow for authentication and authorization bypasses resulting in unauthorized control of MQTT-connected nodes. Version 2.5.1 contains a patch.Show less
1Purestorage
1Purity//fa
Jun 17, 2026
Sep 23, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A condition exists in FlashArray Purity whereby an attacker can employ a privileged account allowing remote access to the array.
1Vesoft
1Nebulagraph Database
Jun 17, 2026
Sep 22, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue was discovered in vesoft NebulaGraph through 3.8.0. It allows bypassing authentication.
1Acquia
1Mautic
Jun 17, 2026
Sep 18, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
The logic in place to facilitate the update process via the user interface lacks access control to verify if permission exists to perform the tasks. Prior to this patch being applied it might be possible for an attacker...Show more
The logic in place to facilitate the update process via the user interface lacks access control to verify if permission exists to perform the tasks. Prior to this patch being applied it might be possible for an attacker to access the Mautic version number or to execute parts of the upgrade process without permission. As upgrading in the user interface is deprecated, this functionality is no longer required.Show less
1Bmc
1Remedy Mid Tier
Jun 17, 2026
Sep 18, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
**UNSUPPORTED WHEN ASSIGNED** An issue was discovered in BMC Remedy Mid Tier 7.6.04. An unauthenticated remote attacker is able to access any user account without using any password. NOTE: This vulnerability only affects...Show more
**UNSUPPORTED WHEN ASSIGNED** An issue was discovered in BMC Remedy Mid Tier 7.6.04. An unauthenticated remote attacker is able to access any user account without using any password. NOTE: This vulnerability only affects products that are no longer supported by the maintainer and the impacted version for this vulnerability is 7.6.04 only.Show less
-
-
Jun 17, 2026
Sep 18, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Improper authentication vulnerability in multiple digital video recorders provided by TAKENAKA ENGINEERING CO., LTD. allows a remote authenticated attacker to execute an arbitrary OS command on the device or alter the de...Show more
Improper authentication vulnerability in multiple digital video recorders provided by TAKENAKA ENGINEERING CO., LTD. allows a remote authenticated attacker to execute an arbitrary OS command on the device or alter the device settings.Show less
1Ptzoptics
2Pt30x Ndi Xx G2 Firmware
Pt30x Sdi Firmware
Jun 17, 2026
Sep 17, 2024
N/A· v4
9.1 CRITICAL· v3
N/A· v2
PTZOptics PT30X-SDI/NDI-xx before firmware 6.3.40 is vulnerable to an insufficient authentication issue. The camera does not properly enforce authentication to /cgi-bin/param.cgi when requests are sent without an HTTP Au...Show more
PTZOptics PT30X-SDI/NDI-xx before firmware 6.3.40 is vulnerable to an insufficient authentication issue. The camera does not properly enforce authentication to /cgi-bin/param.cgi when requests are sent without an HTTP Authorization header. The result is a remote and unauthenticated attacker can leak sensitive data such as usernames, password hashes, and configurations details. Additionally, the attacker can update individual configuration values or overwrite the whole file.Show less
1Apple
2Ipados
Iphone Os
Jun 17, 2026
Sep 17, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
An authentication issue was addressed with improved state management. This issue is fixed in Safari 18, iOS 18 and iPadOS 18. Private Browsing tabs may be accessed without authentication.
1Apple
2Ipados
Iphone Os
Jun 17, 2026
Sep 17, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
This issue was addressed through improved state management. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18. Private Browsing tabs may be accessed without authentication.
1Adobe
1Coldfusion
Jun 17, 2026
Sep 13, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
ColdFusion versions 2023.6, 2021.12 and earlier are affected by an Improper Authentication vulnerability that could result in privilege escalation. An attacker could exploit this vulnerability to gain unauthorized access...Show more
ColdFusion versions 2023.6, 2021.12 and earlier are affected by an Improper Authentication vulnerability that could result in privilege escalation. An attacker could exploit this vulnerability to gain unauthorized access and affect the integrity of the application. Exploitation of this issue does not require user interaction.Show less
1Rockwellautomation
1Factorytalk Batch View
Jun 17, 2026
Sep 12, 2024
9.2 CRITICAL· v4
9.8 CRITICAL· v3
N/A· v2
CVE-2024-45823 IMPACT An authentication bypass vulnerability exists in the affected product. The vulnerability exists due to shared secrets across accounts and could allow a threat actor to impersonate a user if the t...Show more
CVE-2024-45823 IMPACT An authentication bypass vulnerability exists in the affected product. The vulnerability exists due to shared secrets across accounts and could allow a threat actor to impersonate a user if the threat actor is able to enumerate additional information required during authentication.Show less
1Eclipse
1Eclipse Dataspace Components
Jun 17, 2026
Sep 11, 2024
5.1 MEDIUM· v4
8.1 HIGH· v3
N/A· v2
In Eclipse Dataspace Components, from version 0.5.0 and before version 0.9.0, the ConsumerPullTransferTokenValidationApiController does not check for token validity (expiry, not-before, issuance date), which can allow an...Show more
In Eclipse Dataspace Components, from version 0.5.0 and before version 0.9.0, the ConsumerPullTransferTokenValidationApiController does not check for token validity (expiry, not-before, issuance date), which can allow an attacker to bypass the check for token expiration. The issue requires to have a dataplane configured to support http proxy consumer pull AND include the module "transfer-data-plane". The affected code was marked deprecated from the version 0.6.0 in favour of Dataplane Signaling. In 0.9.0 the vulnerable code has been removed.Show less
1Microsoft
1Dynamics 365 Business Central
Jun 17, 2026
Sep 10, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability
1Loftware
1Spectrum
Jun 17, 2026
Sep 10, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Loftware Spectrum before 4.6 HF14 has Missing Authentication for a Critical Function.
1Veeam
1Veeam Backup & Replication
Jun 17, 2026
Sep 7, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
A vulnerability that allows a user who has been assigned a low-privileged role within Veeam Backup & Replication to alter Multi-Factor Authentication (MFA) settings and bypass MFA.
1Qnap
1Music Station
Jun 17, 2026
Sep 6, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
An improper authentication vulnerability has been reported to affect Music Station. If exploited, the vulnerability could allow users to compromise the security of the system via a network. We have already fixed the vul...Show more
An improper authentication vulnerability has been reported to affect Music Station. If exploited, the vulnerability could allow users to compromise the security of the system via a network. We have already fixed the vulnerability in the following version: Music Station 5.4.0 and laterShow less
1Trellix
1Intrusion Prevention System Manager
Jun 17, 2026
Sep 5, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
This vulnerability allows unauthenticated remote attackers to bypass authentication and gain APIs access of the Manager.