Improper Authentication

CWE-287 · 12 records · 4 with a public proof-of-concept

Records the NVD classes as Improper Authentication (CWE-287), highest CVSS first.

  1. CRITICAL 9.8CVE-2026-63456

    Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web authentication mechanisms and access system functions. Successful exploitation could allow an attacker to view

    AI risk analysis on Exploit-DB.ai →

  2. CRITICAL 9.1CVE-2026-71277public PoC

    rust-iot-platform's AuthToken request-guard implementation (api/src/main.rs) only checks whether the Authorization HTTP header is present, and never validates its value against any session, token store, or signature. Any request carrying an arbitrary non-empty

    AI risk analysis on Exploit-DB.ai →

  3. CRITICAL 9.1CVE-2026-15210

    The OTP Login With Phone Number, OTP Verification WordPress plugin before 1.8.71 does not limit the number of OTP verification attempts or invalidate a one-time login code after a wrong guess, and an unauthenticated user can request a login code for any accoun

    AI risk analysis on Exploit-DB.ai →

  4. HIGH 8.1CVE-2026-70482public PoC

    Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.0 until 0.11.0, when ENABLE_OAUTH_TOKEN_EXCHANGE=True, /oauth/{provider}/token/exchange accepts a raw provider access token and validates it by calling the provider

    AI risk analysis on Exploit-DB.ai →

  5. HIGH 7.5CVE-2026-16055

    The Contest Gallery WordPress plugin before 30.0.7 does not route its front-end login through the standard WordPress authentication flow, issuing an authentication cookie directly after the password check, which bypasses installed brute-force-protection and t

    AI risk analysis on Exploit-DB.ai →

  6. HIGH 7.5CVE-2026-16036

    The miniOrange 2FA WordPress plugin before 6.2.7 does not bind the second factor being configured during the pre-login two-factor challenge to the target account's existing factor, allowing an attacker who knows a user's password to rebind that user's second

    AI risk analysis on Exploit-DB.ai →

  7. HIGH 7.5CVE-2026-15372

    The WP 2FA WordPress plugin before 4.1.0 does not validate the second authentication factor when one of its supported methods is selected at login, allowing an attacker who already knows a user's password to bypass two-factor authentication and fully access t

    AI risk analysis on Exploit-DB.ai →

  8. HIGH 7.3CVE-2026-18810public PoC

    A security vulnerability has been detected in H3C NX15 V100R017. Impacted is an unknown function of the file /api/wizard/networkSetup. Such manipulation leads to missing authentication. The attack may be performed from remote. The vendor was contacted early ab

    AI risk analysis on Exploit-DB.ai →

  9. MEDIUM 5CVE-2026-18816public PoC

    A vulnerability was identified in Baserow up to 2.3.2. Affected by this vulnerability is the function verify of the file backend/src/baserow/api/two_factor_auth/views.py of the component 2FA Verify Endpoint. Such manipulation leads to improper authentication.

    AI risk analysis on Exploit-DB.ai →

  10. LOW 3.7CVE-2026-11366

    The MonsterInsights WordPress plugin before 11.1.0 does not correctly validate the signature on one of its unauthenticated AJAX actions: when the MonsterInsights WordPress plugin before 11.1.0 is not connected to Google Analytics the HMAC signing key is empt

    AI risk analysis on Exploit-DB.ai →

  11. UNSCOREDCVE-2026-58075

    A vulnerability allowing an unauthenticated attacker to read arbitrary files from the host, which can be further leveraged toescalate privileges locally.

    AI risk analysis on Exploit-DB.ai →

  12. UNSCOREDCVE-2026-18759

    The background service of ABP or AES runs as NT AUTHORITY\SYSTEM and implements a file-based inter-process communication (IPC) mechanism protected by AES encryption. Because the encryption key file is readable by standard users and protected using DPAPI. Any a

    AI risk analysis on Exploit-DB.ai →