CWE-287
CVEs classified under CWE-287, newest first.
461 CVEsRSS
CVE-2026-56793High· 7.7Dell OpenManage Server Administrator, versions prior to 11.1.0.2, contains an Improper Authentication vulnerability
Dell OpenManage Server Administrator, versions prior to 11.1.0.2, contains an Improper Authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized acc…
CVE-2026-56162Critical· 10.0Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.
Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-48039Critical· 9.1Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads
Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads. Prior to version 1.0.109, `AuthInjectionMiddleware.dispatch()` at `http_auth_integration.py:272` unconditionally forwards unauthenticated Streama…
CVE-2026-48087Critical· 9.8OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, the registration handler at `POST /api/auth/register/{userId}` validates the relationship between the Web…
CVE-2026-62896Critical· 9.6Microsoft Teams Elevation of Privilege Vulnerability
Improper authentication in Microsoft Teams allows an authorized attacker to elevate privileges over a network.
CVE-2026-65400Critical· 9.8CISA KEVPoCAn authentication issue was addressed with improved state management
An authentication issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26.6.1, macOS Tahoe 26.7. An attacker on the network may be able to…
CVE-2026-64665High· 8.1Statamic is a Laravel and Git powered content management system (CMS)
Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, when OAuth login was enabled with a provider that does not guarantee verified email addresses, an unauthenticated attacker could sign in a…
CVE-2026-71326Low· 3.8Traefik is an open source HTTP reverse proxy and load balancer
Traefik is an open source HTTP reverse proxy and load balancer. From 3.6.11 until 3.6.25 and 3.7.10, Traefik's BasicAuth middleware in pkg/middlewares/auth/basic_auth.go deduplicates concurrent password checks with a singleflight key bui…
CVE-2026-45414High· 8.5Decidim is a participatory democracy framework
Decidim is a participatory democracy framework. Prior to 0.31.5 and in 0.32.0.rc1 before 0.32.0.rc2, JWT-backed API authentication is not bound to the organization selected by the current host, allowing a JWT issued for one tenant to be …
CVE-2026-9192Critical· 9.8An authentication bypass vulnerability in the ODBC App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass password verification and execute queries with the privileges of any …
An authentication bypass vulnerability in the ODBC App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass password verification and execute queries with the privileges of any …
CVE-2026-70482High· 8.1Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.0 until 0.11.0, when ENABLE_OAUTH_TOKEN_EXCHANGE=True, /oauth/{provider}/token/exchange accepts a raw provider access token and validates it b…
CVE-2026-18651Medium· 5.4A flaw was found in 389 Directory Server
A flaw was found in 389 Directory Server. During SASL PLAIN authentication, the server installs connection-level bind credentials before performing the account-lock check. If the account is subsequently found to be locked, the bind is re…
CVE-2026-67335Medium· 5.3better-auth versions before 1.6.2 fail to validate the OAuth state parameter against the stored nonce when using cookie-backed state storage without PKCE
better-auth versions before 1.6.2 fail to validate the OAuth state parameter against the stored nonce when using cookie-backed state storage without PKCE. Attackers can forge the state parameter and supply an attacker-controlled authoriz…
CVE-2026-67327High· 8.3better-auth versions >= 1.1.3 and < 1.6.22 (and pre-release versions >= 1.7.0-beta.0 and < 1.7.0-beta.10) are vulnerable to account takeover via pre-account hijacking on magic-link and email-OTP sign-in when open email/password registrat…
better-auth versions >= 1.1.3 and < 1.6.22 (and pre-release versions >= 1.7.0-beta.0 and < 1.7.0-beta.10) are vulnerable to account takeover via pre-account hijacking on magic-link and email-OTP sign-in when open email/password registrat…
CVE-2026-18215Medium· 6.8Keycloak provides a way to let users log in using Microsoft accounts while restricting access to a specific organization (tenant)
Keycloak provides a way to let users log in using Microsoft accounts while restricting access to a specific organization (tenant). A flaw was discovered where this restriction is ignored when using the token exchange feature. This means …
CVE-2026-14541High· 7.5An authentication bypass and audience confusion vulnerability exists in the Google OAuth provider component of Google mcp-toolbox version 1.4.0
An authentication bypass and audience confusion vulnerability exists in the Google OAuth provider component of Google mcp-toolbox version 1.4.0. When a Google authService is initialized with mcpEnabled: true but lacks an explicitly defin…
CVE-2026-49447Medium· 5.3Cosmos-Server's constellation public-devices endpoint accepts arbitrary bearer tokens
Cosmos-Server's constellation public-devices endpoint accepts arbitrary bearer tokens
CVE-2026-54635High· 7.5pytonapi has a Webhook Custom Path Authentication Bypass
pytonapi has a Webhook Custom Path Authentication Bypass
GHSA-hp74-gm6m-2qm5MediumPocket ID has a reauthentication bypass via one-time access token login — passkey step-up requirement defeated by JWT freshness check that accepts any login method
Pocket ID has a reauthentication bypass via one-time access token login — passkey step-up requirement defeated by JWT freshness check that accepts any login method
CVE-2026-66014High· 8.8JFrog Artifactory contains an authentication handling weakness in internal request processing that, under specific conditions, may allow an attacker to escalate privileges beyond the intended access level.
JFrog Artifactory contains an authentication handling weakness in internal request processing that, under specific conditions, may allow an attacker to escalate privileges beyond the intended access level.
CVE-2026-56191Critical· 10.0Microsoft Exchange Online Tampering Vulnerability
Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network.
CVE-2026-62825Critical· 10.0Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network.
Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network.
GHSA-cmwh-g2h8-c222High· 8.1Poweradmin: OIDC `sub` collation bypass in Poweradmin leading to account takeover
Poweradmin: OIDC `sub` collation bypass in Poweradmin leading to account takeover
CVE-2026-59224High· 8.0Open WebUI: Terminal proxy forwards a spoofable, integrity-unbound user identity to the upstream (X-User-Id header and ws_terminal session_id query injection)
Open WebUI: Terminal proxy forwards a spoofable, integrity-unbound user identity to the upstream (X-User-Id header and ws_terminal session_id query injection)
GHSA-hp6v-6jw7-gv2fCriticalBudibase: OIDC SSO account takeover: incoming identity linked by email without checking email_verified
Budibase: OIDC SSO account takeover: incoming identity linked by email without checking email_verified
GHSA-r277-6w6q-xmqwCritical· 9.1kin-openapi: ValidationHandler.Load() Fail-Open Authentication Bypass via NoopAuthenticationFunc Default
kin-openapi: ValidationHandler.Load() Fail-Open Authentication Bypass via NoopAuthenticationFunc Default
GHSA-qq9h-g4jm-xgf3High· 8.3Better Auth: Account takeover via pre-account hijacking on magic-link and email-OTP sign-in
Better Auth: Account takeover via pre-account hijacking on magic-link and email-OTP sign-in
CVE-2026-16232Critical· 9.1CISA KEV0dayPoCAn authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges
An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successfu…
CVE-2026-59208Highn8n: Cross-Issuer Token Exchange Account Binding via Subject-Only Identity Resolution
n8n: Cross-Issuer Token Exchange Account Binding via Subject-Only Identity Resolution
CVE-2026-60678High· 8.8Vulnerability in the Oracle General Ledger product of Oracle E-Business Suite (component: Internal Operations)
Vulnerability in the Oracle General Ledger product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker wit…