CWE-287: Improper Authentication

What is CWE-287?

The product does not adequately verify that an actor claiming a particular identity is genuinely that actor.

Data statistics

OWASP TOP 10:2025 RANK7 — A07:2025 — Authentication Failures
RELATED CVES (365 DAYS)482
ABSTRACTIONClass
LIKELIHOOD OF EXPLOITHigh

Vulnerabilities mapped to CWE-287

482 vulnerabilities372.5% increase year over year

Vulnerabilities in CISA KEV for CWE-287

8 vulnerabilities300% increase year over year

Official definition

ByMitre CWE

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Detailed description

This weakness occurs when authentication controls accept an identity claim without sufficiently proving it. It can result from missing authentication, incomplete validation, incorrect authentication logic, weak configuration, or an authentication mechanism that can be bypassed. The weakness concerns establishing identity and is distinct from authorization, which determines what an already identified actor is allowed to do.

Characteristics

The weakness may be introduced during architecture and design, or during implementation of a security design. It is not specific to a programming language, operating system, or technology, although the record identifies web-based systems and ICS/OT environments as applicable contexts. Typical manifestations include endpoints or services that accept unauthenticated requests, incorrectly validate credentials or tokens, omit an authentication factor, trust client-side checks, or implement authentication logic with faulty conditions.

Common consequences

An attacker may access data or functionality intended for another identity, disclose application data, gain privileges or assume another user's identity, and execute unauthorized code or commands. Depending on the affected system, the weakness can impact confidentiality, integrity, availability, and access control.

ImpactScopeExplanation
Read Application Data, Gain Privileges or Assume Identity, Execute Unauthorized Code or CommandsIntegrity, Confidentiality, Availability, Access ControlThis weakness can lead to the exposure of resources or functionality to unintended actors, possibly providing attackers with sensitive information or even execute arbitrary code.

Risk mitigations

During architecture and design, use a dedicated authentication framework or library rather than implementing authentication controls ad hoc. The record specifically recommends an authentication feature such as the OWASP ESAPI Authentication feature.

  1. Libraries or Frameworks · Architecture and DesignUse an authentication framework or library such as the OWASP ESAPI Authentication feature.

Detection methods

Use multiple complementary approaches because automated analysis has limited coverage, especially for custom authentication and design or business-rule flaws. Static tools can inspect authentication-related configuration such as Apache .htaccess files and identify common authentication libraries, but they may miss custom schemes and may report false positives where functionality is intentionally public. Manual analysis, including penetration testing, threat modeling, interactive session testing, and review of custom authentication logic, is highly effective. Additional partial-coverage techniques include binary or bytecode disassembly with manual analysis, web application, web services, and database scanners, fuzzing and framework-based fuzzing, manual source-code review, source-code weakness analyzers, context-configured source-code weakness analyzers, and configuration checkers. Architecture and design review is highly cost effective when it uses IEEE 1028 inspections or formal methods and correct-by-construction techniques.

MethodApproachEffectiveness
Automated Static AnalysisAutomated static analysis is useful for detecting certain types of authentication. A tool may be able to analyze related configuration files, such as .htaccess in Apache web servers, or detect the usage of commonly-used authentication libraries. Generally, automated static analysis tools have difficulty detecting custom authentication schemes. In addition, the software's design may include some functionality that is accessible to any user and does not require an established identity; an automated technique that detects the absence of authentication may report false positives.Limited
Manual Static AnalysisThis weakness can be detected using tools and techniques that require manual (human) analysis, such as penetration testing, threat modeling, and interactive tools that allow the tester to record and modify an active session. Manual static analysis is useful for evaluating the correctness of custom authentication mechanisms.These may be more effective than strictly automated techniques. This is especially the case with weaknesses that are related to design and business rules.High
Manual Static Analysis - Binary or BytecodeAccording to SOAR [REF-1479], the following detection techniques may be useful: ``` Cost effective for partial coverage: ``` Binary / Bytecode disassembler - then use manual analysis for vulnerabilities & anomaliesSOAR Partial
Dynamic Analysis with Automated Results InterpretationAccording to SOAR [REF-1479], the following detection techniques may be useful: ``` Cost effective for partial coverage: ``` Web Application Scanner Web Services Scanner Database ScannersSOAR Partial
Dynamic Analysis with Manual Results InterpretationAccording to SOAR [REF-1479], the following detection techniques may be useful: ``` Cost effective for partial coverage: ``` Fuzz Tester Framework-based FuzzerSOAR Partial
Manual Static Analysis - Source CodeAccording to SOAR [REF-1479], the following detection techniques may be useful: ``` Cost effective for partial coverage: ``` Manual Source Code Review (not inspections)SOAR Partial
Automated Static Analysis - Source CodeAccording to SOAR [REF-1479], the following detection techniques may be useful: ``` Cost effective for partial coverage: ``` Source code Weakness Analyzer Context-configured Source Code Weakness AnalyzerSOAR Partial
Automated Static AnalysisAccording to SOAR [REF-1479], the following detection techniques may be useful: ``` Cost effective for partial coverage: ``` Configuration CheckerSOAR Partial
Architecture or Design ReviewAccording to SOAR [REF-1479], the following detection techniques may be useful: ``` Highly cost effective: ``` Inspection (IEEE 1028 standard) (can apply to requirements, design, source code, etc.) Formal Methods / Correct-By-ConstructionHigh

Representative vulnerabilities

The official record provides the following representative examples, not an exhaustive list. They include unauthenticated file or API requests, missing or bypassed second-factor checks, acceptance of a None authentication type or empty credentials, client-side-only authentication, flawed comparisons and validation, default or hard-coded credentials, insecure cookies or parameters, protocol services without authentication, and predictable or replayable authentication values. Examples span file-sharing, chat, proxy, PLC, SCADA, DCS, cloud, router, Bluetooth, mail, LDAP, VoIP, and other products, including cases where authentication bypass enabled code execution, root-shell access, privileged access, or unauthorized command execution.

Below are representative vulnerabilities related to this CWE, prioritized by severity.

Sources (8)

CWE™ Program, operated by The MITRE Corporation. Copyright © 2006–2026, The MITRE Corporation. The MITRE Corporation hereby grants you a non-exclusive, royalty-free license to use CWE for research, development, and commercial purposes. CWE Terms of Use.

Learn more

Run an in-depth assessment with complete web risk management

CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.

Explore CyStack VulnScan