Threats Tagged 'cwe-287'
View all threats tagged with 'cwe-287'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-287'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-40995: CWE-287: Improper Authentication in Spring Spring Web ServicesCVE-2026-40995 0 X509AuthenticationProvider could issue a fully authenticated X509AuthenticationToken when a presented certificate mapped to UserDetails, without applying Spring Security's standard account lifecycle checks (disabled, locked, expired, or credentials-expired accounts). Affected versions: Spring Web Services 5.0.0 through 5.0.1; 4.1.0 through 4.1.3; 4.0.0 through 4.0.18; 3.1.0 through 3.1.8. Join the discussion | CVE Database V5 | 06/11/2026, 05:04:01 UTC Added: 06/11/2026, 06:46:18 UTC |
CVE-2026-46705: CWE-287: Improper Authentication in Eugeny russhCVE-2026-46705 0 Russh is a Rust SSH client & server library. From version 0.34.0-beta.1 to before version 0.61.0, the russh server authentication path keeps internal userauth state across SSH_MSG_USERAUTH_REQUEST messages without separating that state when the request principal changes. RFC 4252 allows the user name and service name fields to change between authentication requests. The issue is not that such changes are invalid. The issue is that russh-owned authentication state, such as remaining methods, partial-success state, and in-progress method state, can remain associated with the connection and then influence a later request for a different (user, service). This is an internal library state mismatch. This issue has been patched in version 0.61.0. Join the discussion | CVE Database V5 | 06/10/2026, 20:21:35 UTC Added: 06/10/2026, 20:59:17 UTC |
CVE-2026-47838: CWE-287: Improper Authentication in Spring Spring SecurityCVE-2026-47838 0 SubjectDnX509PrincipalExtractor does not correctly handle certain malformed X.509 certificate CN values, which can lead to reading the wrong value for the username. In a carefully crafted certificate, this can lead to an attacker impersonating another user. Affected versions: Spring Security 5.7.0 through 5.7.24; 5.8.0 through 5.8.26; 6.3.0 through 6.3.17; 6.4.0 through 6.4.17; 6.5.0 through 6.5.10. Join the discussion | CVE Database V5 | 06/09/2026, 23:50:07 UTC Added: 06/09/2026, 23:55:56 UTC |
CVE-2024-38139: CWE-287: Improper Authentication in Microsoft Microsoft DataverseCVE-2024-38139 0 Improper authentication in Microsoft Dataverse allows an authorized attacker to elevate privileges over a network. Join the discussion | GCVE Database | 10/15/2024, 22:45:59 UTC Added: 06/09/2026, 19:19:01 UTC |
CVE-2024-38124: CWE-287: Improper Authentication in Microsoft Windows Server 2008 Service Pack 2CVE-2024-38124 0 Windows Netlogon Elevation of Privilege Vulnerability Join the discussion | GCVE Database | 10/08/2024, 17:35:42 UTC Added: 06/09/2026, 19:18:59 UTC |
CVE-2026-44810: CWE-287: Improper Authentication in Microsoft Windows 11 version 23H2CVE-2026-44810 0 Improper authentication in Windows Cryptographic Services allows an unauthorized attacker to elevate privileges locally. Join the discussion | CVE Database V5 | 06/09/2026, 17:06:17 UTC Added: 06/09/2026, 17:26:38 UTC |
CVE-2026-49848: CWE-287: Improper Authentication in signalwire freeswitchCVE-2026-49848 0 FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.11.1, mod_verto's check_auth userauth branch wrote request-supplied userVariables into the connection state before comparing the supplied password. The writes are append-only and the connection is not closed on a failed compare, so values declared on bad-password attempts persisted on the same WebSocket and carried into a subsequent successful login on that connection. This issue has been patched in version 1.11.1. Join the discussion | CVE Database V5 | 06/09/2026, 16:05:42 UTC Added: 06/09/2026, 16:26:03 UTC |
CVE-2026-49843: CWE-287: Improper Authentication in signalwire freeswitchCVE-2026-49843 0 FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.11.1, mod_verto's JSON-RPC handler bound the connection to the client-supplied sessid on the first frame, before the authentication gate. Binding inserts the connection into the global session hash and, on a key collision, drops the prior occupant of that slot — sending it a verto.punt, detaching its calls, and closing its socket. An unauthenticated network attacker who knows a target session UUID could therefore evict the legitimate client. This issue has been patched in version 1.11.1. Join the discussion | CVE Database V5 | 06/09/2026, 16:04:55 UTC Added: 06/09/2026, 16:26:03 UTC |
CVE-2026-41720: CWE-287: Improper Authentication in Spring Spring LDAPCVE-2026-41720 0 Spring LDAP's DirContextAuthenticationStrategy implementations do not reject a bind request where a non-empty username is paired with an empty or null password. Affected versions: Spring LDAP 2.4.0 through 2.4.4; 3.2.0 through 3.2.17; 3.3.0 through 3.3.7; 4.0.0 through 4.0.3. Join the discussion | CVE Database V5 | 06/09/2026, 03:48:56 UTC Added: 06/09/2026, 04:48:46 UTC |
CVE-2026-50751: CWE-287: Improper Authentication. in checkpoint Quantum Security GatewayCVE-2026-50751 0 A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password. Join the discussion | CVE Database V5 | 06/08/2026, 11:07:15 UTC Added: 06/08/2026, 11:33:51 UTC |
Showing 1 to 10 of 321 results