Improper Authentication (CWE-287)
CWE-287 is a Class for products that do not prove, or insufficiently prove, that an actor's claimed identity is correct. It sits one level below a Pillar. MITRE discourages mapping vulnerabilities to it and suggests children such as CWE-1390 or CWE-306.
About CWE-287
Weak or missing proof of identity can expose resources or functions to unintended actors. Results include disclosure of sensitive information and, in some cases, arbitrary code execution.
MITRE marks CWE-287 as DISCOURAGED for mapping real-world vulnerabilities; consider children such as CWE-1390 or CWE-306.
Mitigations
- +Use an established authentication framework or library rather than building a custom scheme.
- +Choose a more specific child entry, such as Weak Authentication (CWE-1390) or Missing Authentication for Critical Function (CWE-306), to guide the fix.
- +Review custom authentication logic manually, since automated tools often miss flaws in bespoke schemes.
Detection
Manual static analysis is rated highly effective for custom authentication mechanisms. Automated static analysis has limited effectiveness because it struggles with custom schemes.
CWE-287 Vulnerabilities
18 CVEs| CVE | Title | Vendor | CVSS | EPSS | KEV | Published |
|---|---|---|---|---|---|---|
| CVE-2026-42018 | Anonymous user token generation exposure in JFrog Artifactory | jfrog | 7.5 | 9.8% | KEV | 2026-08-12 |
| CVE-2026-82329 | Potential authentication bypass leading to administrative access in Artifactory | jfrog | 9.8 | 14.1% | KEV | 2026-08-28 |
| CVE-2026-49869 | Kestra: Unauthenticated Remote Code Execution via Authentication Bypass in `AuthenticationFilter` | kestra-io | 10.0 | 2.1% | KEV | 2026-06-26 |
| CVE-2026-59822 | LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback | BerriAI | 8.8 | 0.8% | KEV | 2026-07-08 |
| CVE-2026-16232 | Authentication Bypass in the SmartConsole Login Process Using an Application Token | checkpoint | 9.3 | 78.0% | KEV | 2026-07-22 |
| CVE-2026-50751 | User Authentication Bypass in VPN Remote Access and Mobile Access | checkpoint | 9.3 | 85.3% | KEV | 2026-06-08 |
| CVE-2022-0492 | Linux Kernel Improper Authentication Vulnerability | - | 7.8 | 5.5% | KEV | 2022-03-03 |
| CVE-2023-27351 | PaperCut NG/MF Improper Authentication Vulnerability | PaperCut | 8.2 | 78.1% | KEV | 2023-04-20 |
| CVE-2017-7921 | Hikvision Multiple Products Improper Authentication Vulnerability | - | 9.8 | 100.0% | KEV | 2017-05-06 |
| CVE-2025-49706 | Microsoft SharePoint Server Spoofing Vulnerability | Microsoft | 6.5 | 99.1% | KEV | 2025-07-08 |
| CVE-2024-53704 | SonicWall SonicOS SSLVPN Improper Authentication Vulnerability | SonicWall | 8.2 | 95.1% | KEV | 2025-01-09 |
| CVE-2024-49039 | Windows Task Scheduler Elevation of Privilege Vulnerability | Microsoft | 8.8 | 14.2% | KEV | 2024-11-12 |
| CVE-2024-7593 | Ivanti Virtual Traffic Manager Authentication Bypass Vulnerability | Ivanti | 9.8 | 100.0% | KEV | 2024-08-13 |
| CVE-2024-21410 | Microsoft Exchange Server Elevation of Privilege Vulnerability | Microsoft | 9.8 | 12.6% | KEV | 2024-02-13 |
| CVE-2023-20867 | VMware Tools Authentication Bypass Vulnerability | VMware | 3.9 | 13.5% | KEV | 2023-06-13 |
| CVE-2021-39226 | Snapshot authentication bypass in grafana | grafana | 9.8 | 99.9% | KEV | 2021-10-05 |
| CVE-2021-32648 | Account Takeover in Octobercms | octobercms | 8.2 | 90.4% | KEV | 2021-08-26 |
| CVE-2021-22893 | Ivanti Pulse Connect Secure Use-After-Free Vulnerability | - | 10.0 | 47.2% | KEV | 2021-04-23 |
Most Affected Vendors
Related Weaknesses
Tool Categories That Address This Weakness
Frequently Asked Questions
What is CWE-287?→
CWE-287 is MITRE's Class for improper authentication: an actor claims an identity and the product does not adequately verify that claim.
Is CWE-287 acceptable for CVE root cause mapping?→
MITRE marks it as discouraged because lower-level entries are usually applicable. It lists CWE-1390 and CWE-306 as suggestions.
How many exploited vulnerabilities are classified as CWE-287?→
This database lists 18 CVE records mapped to CWE-287 by their CVE Numbering Authority. 18 of them are in the CISA Known Exploited Vulnerabilities catalog, and CISA links 6 to known ransomware campaigns. Examples include CVE-2026-42018, CVE-2026-82329, CVE-2026-49869.
Weakness definitions summarized from the CWE List, © The MITRE Corporation, used under the CWE Terms of Use. CWE mappings come from each CVE record's CNA. Exploited-in-the-wild data from the CISA KEV catalog (CC0). This site is not endorsed or certified by MITRE or CISA.