CWE-287 · 4,533 records
Improper authentication
Why does it happen?
Authentication is added route by route instead of being enforced in one place. When a route added later bypasses the shared middleware, the session check never runs for it.
Vulnerable and fixed code
A representative teaching example. Highlighted lines mark where the bug and the fix are.
Vulnerable
app.use("/admin", requireSession, adminRouter);
// Route added later skips the middlewareapp.post("/admin-api/config", updateConfig);Fixed
const admin = express.Router();admin.use(requireSession, requireRole("admin"));
admin.post("/config", updateConfig);app.use("/admin", admin);How to prevent it
- 01Enforce authentication at the router level, in a single middleware.
- 02Deny by default: define public endpoints in an allowlist.
- 03In tests, call every admin route without a session and verify it returns 401.
CVEs in this class
4,538 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
99Now | CVE-2024-7593Weaponized | Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remote unauthenticated aivanti · virtual traffic manager · CWE-287 | Critical9.8 | KEV | 100.0% | Aug 13, 2024 |
99Now | CVE-2023-35078Weaponized | An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or resources of the appliivanti · endpoint manager mobile · CWE-287 | Critical9.8 | KEV | 100.0% | Jul 25, 2023 |
99Now | CVE-2023-35082Weaponized | An authentication bypass vulnerability in Ivanti EPMM 11.10 and older, allows unauthorized users to access restricted functionality or resouivanti · endpoint manager mobile · CWE-287 | Critical9.8 | KEV | 100.0% | Aug 15, 2023 |
99Now | CVE-2017-7921Weaponized | An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 160530, DS-2CD2xx0F-I hikvision · ds-2cd2032-i firmware · CWE-287 | Critical9.8 | KEV | 100.0% | May 5, 2017 |
99Now | CVE-2021-33044Weaponized | The identity authentication bypass vulnerability found in some Dahua products during the login process.dahuasecurity · ipc-hum7xxx firmware · CWE-287 | Critical9.8 | KEV | 100.0% | Sep 15, 2021 |
99Now | CVE-2022-40684Weaponized | An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.fortinet · fortiproxy · CWE-287 | Critical9.8 | KEV | 100.0% | Oct 18, 2022 |
99Now | CVE-2025-61882Weaponized | Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integration).oracle · concurrent processing · CWE-287 | Critical9.8 | KEV | 99.7% | Oct 5, 2025 |
99Now | CVE-2021-33045Weaponized | The identity authentication bypass vulnerability found in some Dahua products during the login process.dahuasecurity · ipc-hum7xxx firmware · CWE-287 | Critical9.8 | KEV | 99.6% | Sep 15, 2021 |
99Now | CVE-2021-32030Weaponized | The administrator application on ASUS GT-AC2900 devices before 3.0.0.4.386.42643 and Lyra Mini before 3.0.0.4_384_46630 allows authenticatioasus · lyra mini firmware · CWE-287 | Critical9.8 | KEV | 99.4% | May 6, 2021 |
98Now | CVE-2024-53704Weaponized | An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication.sonicwall · sonicos · CWE-287 | Critical9.8 | KEV | 95.1% | Jan 9, 2025 |
97Now | CVE-2013-0625Weaponized | Adobe ColdFusion 9.0, 9.0.1, and 9.0.2, when a password is not configured, allows remote attackers to bypass authentication and possibly exeadobe · coldfusion · CWE-287 | Critical9.8 | KEV | 93.8% | Jan 8, 2013 |
97Now | CVE-2018-10561Weaponized | An issue was discovered on Dasan GPON home routers.dasannetworks · gpon router firmware · CWE-287 | Critical9.8 | KEV | 92.9% | May 3, 2018 |
97Now | CVE-2026-20182Weaponized | Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerabilitycisco · catalyst sd-wan manager · CWE-287 | Critical10.0 | KEV | 91.5% | May 14, 2026 |
97Now | CVE-2026-20127Weaponized | Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerabilitycisco · catalyst sd-wan manager · CWE-287 | Critical10.0 | KEV | 88.5% | Feb 25, 2026 |
95Now | CVE-2020-0688Weaponized | A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, akmicrosoft · exchange server · CWE-287 | High8.8 | KEV | 100.0% | Feb 11, 2020 |
94Now | CVE-2015-1187Weaponized | The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to execute arbitrary code via the ping_addr parameter to ping.ctrendnet · tew-731br firmware · CWE-287 | Critical9.8 | KEV | 82.9% | Sep 21, 2017 |
93Now | CVE-2021-32648Weaponized | Account Takeover in Octobercmsoctobercms · october · CWE-287 | Critical9.1 | KEV | 90.4% | Aug 26, 2021 |
92Now | CVE-2023-46805Weaponized | An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to accivanti · connect secure · CWE-287 | High8.2 | KEV | 100.0% | Jan 12, 2024 |
90Now | CVE-2026-16232Weaponized | Authentication Bypass in the SmartConsole Login Process Using an Application Tokencheckpoint · multi-domain security management · CWE-287 | Critical9.3 | KEV | 78.0% | Jul 22, 2026 |
90Now | CVE-2020-4427Weaponized | IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 could allow a remote attacker to bypass security restrictions when configibm · data risk manager · CWE-287 | Critical9.8 | KEV | 70.0% | May 7, 2020 |
89Now | CVE-2021-39226Weaponized | Snapshot authentication bypass in grafanagrafana · grafana · CWE-287 | High7.3 | KEV | 99.9% | Oct 5, 2021 |
89Now | CVE-2023-28461Weaponized | Array Networks Array AG Series and vxAG (9.4.0.481 and earlier) allow remote code execution.arraynetworks · arrayos ag · CWE-287 | Critical9.8 | KEV | 68.1% | Mar 15, 2023 |
87Now | CVE-2015-7755Weaponized | Juniper ScreenOS 6.2.0r15 through 6.2.0r18, 6.3.0r12 before 6.3.0r12b, 6.3.0r13 before 6.3.0r13b, 6.3.0r14 before 6.3.0r14b, 6.3.0r15 beforejuniper · screenos · CWE-287 | Critical9.8 | KEV | 61.1% | Dec 19, 2015 |
86Now | CVE-2025-49706Weaponized | Microsoft SharePoint Server Spoofing Vulnerabilitymicrosoft · sharepoint enterprise server · CWE-287 | Medium6.5 | KEV | 99.1% | Jul 8, 2025 |
86Now | CVE-2019-19006Weaponized | Sangoma FreePBX 115.0.16.26 and below, 14.0.13.11 and below, 13.0.197.13 and below have Incorrect Access Control.sangoma · freepbx · CWE-287 | Critical9.8 | KEV | 55.9% | Nov 21, 2019 |
- CVE-2024-759399Now
Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remote unauthenticated a
CriticalCVSS 9.8KEVWeaponizedEPSS 100%ivanti · virtual traffic managerAug 13, 2024
- CVE-2023-3507899Now
An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or resources of the appli
CriticalCVSS 9.8KEVWeaponizedEPSS 100%ivanti · endpoint manager mobileJul 25, 2023
- CVE-2023-3508299Now
An authentication bypass vulnerability in Ivanti EPMM 11.10 and older, allows unauthorized users to access restricted functionality or resou
CriticalCVSS 9.8KEVWeaponizedEPSS 100%ivanti · endpoint manager mobileAug 15, 2023
- CVE-2017-792199Now
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 160530, DS-2CD2xx0F-I
CriticalCVSS 9.8KEVWeaponizedEPSS 100%hikvision · ds-2cd2032-i firmwareMay 5, 2017
- CVE-2021-3304499Now
The identity authentication bypass vulnerability found in some Dahua products during the login process.
CriticalCVSS 9.8KEVWeaponizedEPSS 100%dahuasecurity · ipc-hum7xxx firmwareSep 15, 2021
- CVE-2022-4068499Now
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.
CriticalCVSS 9.8KEVWeaponizedEPSS 100%fortinet · fortiproxyOct 18, 2022
- CVE-2025-6188299Now
Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integration).
CriticalCVSS 9.8KEVWeaponizedEPSS 100%oracle · concurrent processingOct 5, 2025
- CVE-2021-3304599Now
The identity authentication bypass vulnerability found in some Dahua products during the login process.
CriticalCVSS 9.8KEVWeaponizedEPSS 100%dahuasecurity · ipc-hum7xxx firmwareSep 15, 2021
- CVE-2021-3203099Now
The administrator application on ASUS GT-AC2900 devices before 3.0.0.4.386.42643 and Lyra Mini before 3.0.0.4_384_46630 allows authenticatio
CriticalCVSS 9.8KEVWeaponizedEPSS 99%asus · lyra mini firmwareMay 6, 2021
- CVE-2024-5370498Now
An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication.
CriticalCVSS 9.8KEVWeaponizedEPSS 95%sonicwall · sonicosJan 9, 2025
- CVE-2013-062597Now
Adobe ColdFusion 9.0, 9.0.1, and 9.0.2, when a password is not configured, allows remote attackers to bypass authentication and possibly exe
CriticalCVSS 9.8KEVWeaponizedEPSS 94%adobe · coldfusionJan 8, 2013
- CVE-2018-1056197Now
An issue was discovered on Dasan GPON home routers.
CriticalCVSS 9.8KEVWeaponizedEPSS 93%dasannetworks · gpon router firmwareMay 3, 2018
- CVE-2026-2018297Now
Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability
CriticalCVSS 10.0KEVWeaponizedEPSS 92%cisco · catalyst sd-wan managerMay 14, 2026
- CVE-2026-2012797Now
Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability
CriticalCVSS 10.0KEVWeaponizedEPSS 88%cisco · catalyst sd-wan managerFeb 25, 2026
- CVE-2020-068895Now
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, ak
HighCVSS 8.8KEVWeaponizedEPSS 100%microsoft · exchange serverFeb 11, 2020
- CVE-2015-118794Now
The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to execute arbitrary code via the ping_addr parameter to ping.c
CriticalCVSS 9.8KEVWeaponizedEPSS 83%trendnet · tew-731br firmwareSep 21, 2017
- CVE-2021-3264893Now
Account Takeover in Octobercms
CriticalCVSS 9.1KEVWeaponizedEPSS 90%octobercms · octoberAug 26, 2021
- CVE-2023-4680592Now
An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to acc
HighCVSS 8.2KEVWeaponizedEPSS 100%ivanti · connect secureJan 12, 2024
- CVE-2026-1623290Now
Authentication Bypass in the SmartConsole Login Process Using an Application Token
CriticalCVSS 9.3KEVWeaponizedEPSS 78%checkpoint · multi-domain security managementJul 22, 2026
- CVE-2020-442790Now
IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 could allow a remote attacker to bypass security restrictions when config
CriticalCVSS 9.8KEVWeaponizedEPSS 70%ibm · data risk managerMay 7, 2020
- CVE-2021-3922689Now
Snapshot authentication bypass in grafana
HighCVSS 7.3KEVWeaponizedEPSS 100%grafana · grafanaOct 5, 2021
- CVE-2023-2846189Now
Array Networks Array AG Series and vxAG (9.4.0.481 and earlier) allow remote code execution.
CriticalCVSS 9.8KEVWeaponizedEPSS 68%arraynetworks · arrayos agMar 15, 2023
- CVE-2015-775587Now
Juniper ScreenOS 6.2.0r15 through 6.2.0r18, 6.3.0r12 before 6.3.0r12b, 6.3.0r13 before 6.3.0r13b, 6.3.0r14 before 6.3.0r14b, 6.3.0r15 before
CriticalCVSS 9.8KEVWeaponizedEPSS 61%juniper · screenosDec 19, 2015
- CVE-2025-4970686Now
Microsoft SharePoint Server Spoofing Vulnerability
MediumCVSS 6.5KEVWeaponizedEPSS 99%microsoft · sharepoint enterprise serverJul 8, 2025
- CVE-2019-1900686Now
Sangoma FreePBX 115.0.16.26 and below, 14.0.13.11 and below, 13.0.197.13 and below have Incorrect Access Control.
CriticalCVSS 9.8KEVWeaponizedEPSS 56%sangoma · freepbxNov 21, 2019