CWE-287β€”Improper Authentication

PUBLISHEDweakness recordHigh
released 2006-07-19 Β· last modified 2026-04-30
CWE-287 - Improper Authentication - Diagram

Metadata

CWE ID:
CWE-287
Abstraction:
Class
Structure:
Simple
Status:
Draft
Release Date:
2006-07-19
Latest Modification Date:
2026-04-30

Weakness Name

Improper Authentication

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Common Consequences

Scope:
Integrity, Confidentiality, Availability, Access Control
Impact:
Read Application Data, Gain Privileges or Assume Identity, Execute Unauthorized Code or Commands
Notes:
This weakness can lead to the exposure of resources or functionality to unintended actors, possibly providing attackers with sensitive information or even execute arbitrary code.

Related Weaknesses

Related Alerts