Skip to content
Noroxi

CWE-287 · 4,533 records

Improper authentication

Why does it happen?

Authentication is added route by route instead of being enforced in one place. When a route added later bypasses the shared middleware, the session check never runs for it.

Vulnerable and fixed code

A representative teaching example. Highlighted lines mark where the bug and the fix are.

Vulnerable

ts
app.use("/admin", requireSession, adminRouter);
// Route added later skips the middlewareapp.post("/admin-api/config", updateConfig);

Fixed

ts
const admin = express.Router();admin.use(requireSession, requireRole("admin"));
admin.post("/config", updateConfig);app.use("/admin", admin);

How to prevent it

  1. 01Enforce authentication at the router level, in a single middleware.
  2. 02Deny by default: define public endpoints in an allowlist.
  3. 03In tests, call every admin route without a session and verify it returns 401.

CVEs in this class

4,538 records

  • Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remote unauthenticated a

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    ivanti · virtual traffic managerAug 13, 2024

  • An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or resources of the appli

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    ivanti · endpoint manager mobileJul 25, 2023

  • An authentication bypass vulnerability in Ivanti EPMM 11.10 and older, allows unauthorized users to access restricted functionality or resou

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    ivanti · endpoint manager mobileAug 15, 2023

  • An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 160530, DS-2CD2xx0F-I

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    hikvision · ds-2cd2032-i firmwareMay 5, 2017

  • The identity authentication bypass vulnerability found in some Dahua products during the login process.

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    dahuasecurity · ipc-hum7xxx firmwareSep 15, 2021

  • An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    fortinet · fortiproxyOct 18, 2022

  • Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integration).

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    oracle · concurrent processingOct 5, 2025

  • The identity authentication bypass vulnerability found in some Dahua products during the login process.

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    dahuasecurity · ipc-hum7xxx firmwareSep 15, 2021

  • The administrator application on ASUS GT-AC2900 devices before 3.0.0.4.386.42643 and Lyra Mini before 3.0.0.4_384_46630 allows authenticatio

    CriticalCVSS 9.8KEVWeaponizedEPSS 99%

    asus · lyra mini firmwareMay 6, 2021

  • An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication.

    CriticalCVSS 9.8KEVWeaponizedEPSS 95%

    sonicwall · sonicosJan 9, 2025

  • Adobe ColdFusion 9.0, 9.0.1, and 9.0.2, when a password is not configured, allows remote attackers to bypass authentication and possibly exe

    CriticalCVSS 9.8KEVWeaponizedEPSS 94%

    adobe · coldfusionJan 8, 2013

  • An issue was discovered on Dasan GPON home routers.

    CriticalCVSS 9.8KEVWeaponizedEPSS 93%

    dasannetworks · gpon router firmwareMay 3, 2018

  • Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability

    CriticalCVSS 10.0KEVWeaponizedEPSS 92%

    cisco · catalyst sd-wan managerMay 14, 2026

  • Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability

    CriticalCVSS 10.0KEVWeaponizedEPSS 88%

    cisco · catalyst sd-wan managerFeb 25, 2026

  • A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, ak

    HighCVSS 8.8KEVWeaponizedEPSS 100%

    microsoft · exchange serverFeb 11, 2020

  • The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to execute arbitrary code via the ping_addr parameter to ping.c

    CriticalCVSS 9.8KEVWeaponizedEPSS 83%

    trendnet · tew-731br firmwareSep 21, 2017

  • Account Takeover in Octobercms

    CriticalCVSS 9.1KEVWeaponizedEPSS 90%

    octobercms · octoberAug 26, 2021

  • An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to acc

    HighCVSS 8.2KEVWeaponizedEPSS 100%

    ivanti · connect secureJan 12, 2024

  • Authentication Bypass in the SmartConsole Login Process Using an Application Token

    CriticalCVSS 9.3KEVWeaponizedEPSS 78%

    checkpoint · multi-domain security managementJul 22, 2026

  • IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 could allow a remote attacker to bypass security restrictions when config

    CriticalCVSS 9.8KEVWeaponizedEPSS 70%

    ibm · data risk managerMay 7, 2020

  • Snapshot authentication bypass in grafana

    HighCVSS 7.3KEVWeaponizedEPSS 100%

    grafana · grafanaOct 5, 2021

  • Array Networks Array AG Series and vxAG (9.4.0.481 and earlier) allow remote code execution.

    CriticalCVSS 9.8KEVWeaponizedEPSS 68%

    arraynetworks · arrayos agMar 15, 2023

  • Juniper ScreenOS 6.2.0r15 through 6.2.0r18, 6.3.0r12 before 6.3.0r12b, 6.3.0r13 before 6.3.0r13b, 6.3.0r14 before 6.3.0r14b, 6.3.0r15 before

    CriticalCVSS 9.8KEVWeaponizedEPSS 61%

    juniper · screenosDec 19, 2015

  • Microsoft SharePoint Server Spoofing Vulnerability

    MediumCVSS 6.5KEVWeaponizedEPSS 99%

    microsoft · sharepoint enterprise serverJul 8, 2025

  • Sangoma FreePBX 115.0.16.26 and below, 14.0.13.11 and below, 13.0.197.13 and below have Incorrect Access Control.

    CriticalCVSS 9.8KEVWeaponizedEPSS 56%

    sangoma · freepbxNov 21, 2019

All vulnerability classes