CWE-287: Improper Authentication — known CVE vulnerabilities
CVEs classified under CWE-287 (Improper Authentication), ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (50)
CVE-2026-101077 — CVSS 10.0 (critical): A flaw has been found in Netcore NR289-GE 1.4.5102. This impacts the function process_request of the component boa_temp Handler. This…
CVE-2026-100886 — CVSS 10.0 (critical): A vulnerability was identified in Seetong T8108, T8108P, T8116 and T8232 4.6.1.4-build202604241011. The affected element is an unknown…
CVE-2026-77244 — CVSS 10.0 (critical): MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the HTTP transport…
CVE-2026-94493 — CVSS 10.0 (critical): A vulnerability was detected in Gigatech PDV5701 1.0.31_240305_112640. This issue affects some unknown processing of the file /index.html…
CVE-2026-83099 — CVSS 10.0 (critical): Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). Supported versions that…
CVE-2026-83059 — CVSS 10.0 (critical): Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Supported versions that…
CVE-2026-83021 — CVSS 10.0 (critical): Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). Supported versions that are…
CVE-2026-83020 — CVSS 10.0 (critical): Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars)…
CVE-2026-71133 — CVSS 10.0 (critical): Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that…
CVE-2026-76658 — CVSS 10.0 (critical): A vulnerability has been identified in the SSH daemon of HPE Networking Fabric Composer that could allow an unauthenticated remote attacker…
CVE-2026-76657 — CVSS 10.0 (critical): Vulnerabilities have been identified in the API of HPE Networking Fabric Composer that could potentially allow an unauthenticated remote…
CVE-2026-82695 — CVSS 10.0 (critical): A security flaw has been discovered in Tenda AC18 15.03.05.19. Impacted is an unknown function of the file /goform/telnet of the component…
CVE-2026-82694 — CVSS 10.0 (critical): A vulnerability was identified in Tenda AC1206 15.03.06.23. This issue affects the function R7WebsSecurityHandler of the file /goform/ate…
CVE-2026-82693 — CVSS 10.0 (critical): A vulnerability was determined in Tenda AC1206 15.03.06.23. This vulnerability affects the function TendaTelnet of the file /goform/telnet…
CVE-2026-78167 — CVSS 10.0 (critical): A weakness has been identified in EFM ipTIME T16000M 14.20.2. The impacted element is the function httpcon_check_session_url of the…
CVE-2026-20317 — CVSS 10.0 (critical): As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a…
CVE-2026-19977 — CVSS 10.0 (critical): A vulnerability was detected in EFM ipTIME A3004T 14.19.0. The affected element is the function httpcon_check_session_url of the component…
CVE-2026-59500 — CVSS 10.0 (critical): : Improper Authentication vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions). This issue…
CVE-2024-27253 — CVSS 10.0 (critical): IBM DOORS Next 7.0.3 through 7.0.3 Interim Fix 018 could allow an authenticated user to bypass security logic to perform unauthorized…
CVE-2026-56162 — CVSS 10.0 (critical): Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-62825 — CVSS 10.0 (critical): Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-56191 — CVSS 10.0 (critical): Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network.
CVE-2026-45480 — CVSS 10.0 (critical): Improper authentication in Azure Active Directory allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-10611 — CVSS 10.0 (critical): An authentication bypass vulnerability exists in MISP when LDAP mixed authentication is enabled with OTP enforcement. In deployments…
CVE-2026-47280 — CVSS 10.0 (critical): Improper authentication in Azure Resource Manager (ARM) allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-42822 — CVSS 10.0 (critical): Improper authentication in Azure Local Disconnected Operations allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-42869 — CVSS 10.0 (critical): SOCFortress CoPilot focuses on providing a single pane of glass for all your security operations needs. Prior to 0.1.57, SOCFortress…
CVE-2026-41070 — CVSS 10.0 (critical): openvpn-auth-oauth2 is a plugin/management interface client for OpenVPN server to handle an OIDC based single sign-on (SSO) auth flows…
CVE-2026-41679 — CVSS 10.0 (critical): Paperclip is a Node.js server and React UI that orchestrates a team of AI agents to run a business. Prior to version 2026.416.0, an…
CVE-2026-24898 — CVSS 10.0 (critical): OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0, an unauthenticated…
CVE-2025-15586: OGP-Website installs prior git commit 52f865a4fba763594453068acf8fa9e3fc38d663 are affected by a type juggling flaw which if exploited can…
CVE-2025-70841 — CVSS 10.0 (critical): Dokans Multi-Tenancy Based eCommerce Platform SaaS 3.9.2 allows unauthenticated remote attackers to obtain sensitive application…
CVE-2025-44005 — CVSS 10.0 (critical): An attacker can bypass authorization checks and force a Step CA ACME or SCEP provisioner to create certificates without completing certain…
CVE-2025-63224 — CVSS 10.0 (critical): The Itel DAB Encoder (IDEnc build 25aec8d) is vulnerable to Authentication Bypass due to improper JWT validation across devices. Attackers…
CVE-2025-63216 — CVSS 10.0 (critical): The Itel DAB Gateway (IDGat build c041640a) is vulnerable to Authentication Bypass due to improper JWT validation across devices. Attackers…
CVE-2025-9265: A broken authorization vulnerability in Kiloview NDI N30 allows a remote unauthenticated attacker to deactivate user verification, giving…
CVE-2025-54419 — CVSS 10.0 (critical): A SAML library not dependent on any frameworks that runs in Node. In version 5.0.1, Node-SAML loads the assertion from the (unsigned)…
CVE-2025-52572 — CVSS 10.0 (critical): Hikka, a Telegram userbot, has vulnerability affects all users on all versions of Hikka. Two scenarios are possible. 1. Web interface does…
CVE-2025-29813 — CVSS 10.0 (critical): Authentication bypass by assumed-immutable data in Azure DevOps allows an unauthorized attacker to elevate privileges over a network.
CVE-2024-11186 — CVSS 10.0 (critical): On affected versions of the CloudVision Portal, improper access controls could enable a malicious authenticated user to take broader…
CVE-2024-0002 — CVSS 10.0 (critical): A condition exists in FlashArray Purity whereby an attacker can employ a privileged account allowing remote access to the array.
CVE-2024-30299 — CVSS 10.0 (critical): Adobe Framemaker Publishing Server versions 2020.3, 2022.2 and earlier are affected by an Improper Authentication vulnerability that could…
CVE-2023-20238 — CVSS 10.0 (critical): A vulnerability in the single sign-on (SSO) implementation of Cisco BroadWorks Application Delivery Platform and Cisco BroadWorks Xtended…