Skip to main content

About CWE-287

Weak or missing proof of identity can expose resources or functions to unintended actors. Results include disclosure of sensitive information and, in some cases, arbitrary code execution.

MITRE marks CWE-287 as DISCOURAGED for mapping real-world vulnerabilities; consider children such as CWE-1390 or CWE-306.

MITRE name
Improper Authentication
Abstraction
Class: a very abstract weakness, typically independent of language or technology
Status
Draft
Also known as
authentification, AuthN, AuthC

Mitigations

  • +Use an established authentication framework or library rather than building a custom scheme.
  • +Choose a more specific child entry, such as Weak Authentication (CWE-1390) or Missing Authentication for Critical Function (CWE-306), to guide the fix.
  • +Review custom authentication logic manually, since automated tools often miss flaws in bespoke schemes.

Detection
Manual static analysis is rated highly effective for custom authentication mechanisms. Automated static analysis has limited effectiveness because it struggles with custom schemes.

CWE-287 Vulnerabilities

18 CVEs
CVETitleVendorCVSSEPSSKEVPublished
CVE-2026-42018
Anonymous user token generation exposure in JFrog Artifactory
jfrog7.59.8%KEV2026-08-12
CVE-2026-82329
Potential authentication bypass leading to administrative access in Artifactory
jfrog9.814.1%KEV2026-08-28
CVE-2026-49869
Kestra: Unauthenticated Remote Code Execution via Authentication Bypass in `AuthenticationFilter`
kestra-io10.02.1%KEV2026-06-26
CVE-2026-59822
LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback
BerriAI8.80.8%KEV2026-07-08
CVE-2026-16232
Authentication Bypass in the SmartConsole Login Process Using an Application Token
checkpoint9.378.0%KEV2026-07-22
CVE-2026-50751
User Authentication Bypass in VPN Remote Access and Mobile Access
checkpoint9.385.3%KEV2026-06-08
CVE-2022-0492
Linux Kernel Improper Authentication Vulnerability
-7.85.5%KEV2022-03-03
CVE-2023-27351
PaperCut NG/MF Improper Authentication Vulnerability
PaperCut8.278.1%KEV2023-04-20
CVE-2017-7921
Hikvision Multiple Products Improper Authentication Vulnerability
-9.8100.0%KEV2017-05-06
CVE-2025-49706
Microsoft SharePoint Server Spoofing Vulnerability
Microsoft6.599.1%KEV2025-07-08
CVE-2024-53704
SonicWall SonicOS SSLVPN Improper Authentication Vulnerability
SonicWall8.295.1%KEV2025-01-09
CVE-2024-49039
Windows Task Scheduler Elevation of Privilege Vulnerability
Microsoft8.814.2%KEV2024-11-12
CVE-2024-7593
Ivanti Virtual Traffic Manager Authentication Bypass Vulnerability
Ivanti9.8100.0%KEV2024-08-13
CVE-2024-21410
Microsoft Exchange Server Elevation of Privilege Vulnerability
Microsoft9.812.6%KEV2024-02-13
CVE-2023-20867
VMware Tools Authentication Bypass Vulnerability
VMware3.913.5%KEV2023-06-13
CVE-2021-39226
Snapshot authentication bypass in grafana
grafana9.899.9%KEV2021-10-05
CVE-2021-32648
Account Takeover in Octobercms
octobercms8.290.4%KEV2021-08-26
CVE-2021-22893
Ivanti Pulse Connect Secure Use-After-Free Vulnerability
-10.047.2%KEV2021-04-23

Frequently Asked Questions

What is CWE-287?→

CWE-287 is MITRE's Class for improper authentication: an actor claims an identity and the product does not adequately verify that claim.

Is CWE-287 acceptable for CVE root cause mapping?→

MITRE marks it as discouraged because lower-level entries are usually applicable. It lists CWE-1390 and CWE-306 as suggestions.

How many exploited vulnerabilities are classified as CWE-287?→

This database lists 18 CVE records mapped to CWE-287 by their CVE Numbering Authority. 18 of them are in the CISA Known Exploited Vulnerabilities catalog, and CISA links 6 to known ransomware campaigns. Examples include CVE-2026-42018, CVE-2026-82329, CVE-2026-49869.

Sources

Weakness definitions summarized from the CWE List, © The MITRE Corporation, used under the CWE Terms of Use. CWE mappings come from each CVE record's CNA. Exploited-in-the-wild data from the CISA KEV catalog (CC0). This site is not endorsed or certified by MITRE or CISA.