Threats Tagged 'cwe-287'
View all threats tagged with 'cwe-287'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-287'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-54320: CWE-287: Improper Authentication in daytonaio daytonaCVE-2026-54320 0 Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows. Prior to 0.184.0, organization invitations could be accepted (and declined) by a user whose email matched the invitation but had not been verified. Daytona authenticates users via OIDC and matches an invitation's target email against the email in the caller's token, but the invitation accept and decline paths did not require that email to be verified, unlike organization creation, which already enforced verification. On identity providers that allow self-service signup and issue a session before the email is verified, an actor could register an address matching a pending invitation, leave it unverified, and accept the invitation, joining the target organization with the role the invitation carried (up to Owner). This vulnerability is fixed in 0.184.0. Join the discussion | CVE Database V5 | 06/23/2026, 18:11:19 UTC Added: 06/23/2026, 18:54:13 UTC |
CVE-2026-52845: CWE-287: Improper Authentication in caddyserver caddyCVE-2026-52845 0 Caddy is an extensible server platform that uses TLS by default. Prior to 2.11.4, forward_auth copy_headers deletes the exact client-supplied identity header before copying the trusted value from the auth gateway. But when the request later goes through php_fastcgi, Caddy normalizes HTTP headers into CGI variables by replacing - with _. This lets a client send an underscore alias that survives the forward_auth delete step but becomes the same PHP/FastCGI variable. Result: a remote client can inject or sometimes override identity/group headers trusted by PHP/FastCGI applications behind Caddy. This vulnerability is fixed in 2.11.4. Join the discussion | CVE Database V5 | 06/23/2026, 17:52:01 UTC Added: 06/23/2026, 18:09:40 UTC |
CVE-2026-34917: CWE-287 Improper Authentication - Generic in Revive AdserverCVE-2026-34917 0 Low‑privileged session IDs generated for the web admin console could be reused in the XML‑RPC API, whose authentication is normally restricted to admin users. An attacker could leverage this to gain unauthorised access and exploit API‑level vulnerabilities. The session context (web/API) is now recorded along with other session data, preventing session IDs from being used interchangeably. Join the discussion | CVE Database V5 | 06/23/2026, 16:14:38 UTC Added: 06/23/2026, 16:39:51 UTC |
CVE-2026-11374: CWE-340: Generation of Predictable Numbers or Identifiers in zohocorp manageengine_adselfservice_plusCVE-2026-11374 0 In ManageEngine ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and ADAudit Plus, the SSO tickets generated to authenticate that session could be predicted by an unauthenticated user, leading to account takeover. Join the discussion | CVE Database V5 | 06/23/2026, 08:19:30 UTC Added: 06/23/2026, 09:24:12 UTC |
CVE-2026-7664: CWE-287 Improper Authentication in IBM Langflow OSSCVE-2026-7664 0 IBM Langflow OSS 1.0.0 through 1.8.4 could allow unauthenticated attackers to access protected MCP project resources and execute MCP operations due to improper authorization enforcement in the Streamable MCP transport endpoint. Join the discussion | CVE Database V5 | 06/22/2026, 14:10:25 UTC Added: 06/22/2026, 15:39:22 UTC |
CVE-2026-10845: CWE-287 Improper Authentication in IBM WebSphere Application ServerCVE-2026-10845 0 IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to bypass authentication and gain unauthorized access to JAX-WS applications. Join the discussion | CVE Database V5 | 06/22/2026, 14:43:16 UTC Added: 06/22/2026, 15:39:21 UTC |
CVE-2026-45480: CWE-287: Improper Authentication in Microsoft Azure Active DirectoryCVE-2026-45480 0 Improper authentication in Azure Active Directory allows an unauthorized attacker to elevate privileges over a network. Join the discussion | GCVE Database | 06/19/2026, 20:27:46 UTC Added: 06/19/2026, 19:07:17 UTC |
CVE-2026-49872: CWE-287 Improper Authentication in Apache Software Foundation Apache APISIXCVE-2026-49872 0 Improper Authentication vulnerability in Apache APISIX. When the cas-auth plugin is used in a route, an attacker can possibly authenticate itself with credentials from a different source. This issue affects Apache APISIX: from 3.0.0 through 3.16.0. Users are recommended to upgrade to version 3.17.0, which fixes the issue. Join the discussion | CVE Database V5 | 06/19/2026, 13:19:34 UTC Added: 06/19/2026, 14:05:57 UTC |
CVE-2026-32174: CWE-287: Improper Authentication in Microsoft Azure AI Bot ServiceCVE-2026-32174 0 Improper authentication in Azure Bot Service allows an authorized attacker to elevate privileges over a network. Join the discussion | CVE Database V5 | 06/18/2026, 21:39:17 UTC Added: 06/18/2026, 22:06:01 UTC |
CVE-2026-49454: CWE-287: Improper Authentication in szTheory relyraCVE-2026-49454 0 Relyra is a strict-by-default SAML 2.0 Service Provider library for Elixir and Phoenix. Versions 1.0.0 and 1.1.0 accept forged SAML signatures because SignatureValue was not cryptographically verified before the library returned a successful authentication result. The XMLDSig trust boundary was incomplete as :public_key.verify over the exclusive-C14N canonicalized SignedInfo was not performed against the configured IdP certificate's public key, DigestValue was not recomputed over the canonicalized referenced element, and canonicalize/2 remained an unused passthrough in the signature-verification path. The result was a structure-only acceptance path where document shape and trust-source rejection could succeed without proving the signature bytes. A forged SignatureValue carrying an attacker-controlled NameID could be accepted as {:ok}. This issue has been fixed in version 1.2.0. Join the discussion | CVE Database V5 | 06/18/2026, 20:52:22 UTC Added: 06/18/2026, 21:20:21 UTC |
Showing 1 to 10 of 64 results