Cyber Resilience

CWE · MITRE source

CWE-287Improper Authentication

Abstraction: Class · CVEs in our corpus: 4,704

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Last updated: 22 August 2026 07:11 UTC

Cumulative inbound coverage

How completely the frameworks we cross-walk collectively cover this — the verdict is the strongest single mapping (overlapping partials are not summed); breadth shows the corroboration behind it.

Collective: mostly · 25 mapping(s) from 8 framework(s): CAPEC 9 (partial) · CSF 2.0 6 (mostly) · STIG rhel 7 3 (mostly) · STIG ubuntu 24 04 2 (mostly) · ATT&CK 2 (partial) · STIG ubuntu 22 04 1 (mostly) · STIG oracle linux 8 1 (mostly) · STIG rhel 8 1 (mostly)

See the full cumulative-coverage rollup →

OWASP Top 10 for Web (2025)

This weakness contributes to A07:2025 Authentication Failures.

Control responseHuman-reviewed

Answering this weakness across the control lifecycle, from our framework cross-walks.

Prevent
Stop it (NIST 800-53 / CSF Protect)
  • IA-1 Policy and Procedures
  • IA-10 Adaptive Authentication
  • IA-12 Identity Proofing
  • IA-13 Identity Providers and Authorization Servers
Detect
Catch it (CSF Detect / Respond)

Harden
Shrink the surface (DISA STIG)
  • 8 hardening rules · 5 OS baselines
Validate
Prove the fix (OWASP ASVS)
  • V6.4.4
  • V6.5.4
  • V6.5.5
  • V6.5.7

NIST 800-53 r5 controls that address this weakness (40)AI-assisted

Showing the 15 most specific. Generic controls that address many weakness types are collapsed below.

Control Title Family Why it addresses this CWE
IA-1Policy and ProceduresIADocumented IA policy and procedures require proper authentication mechanisms to be defined and followed, reducing improper authentication.
IA-10Adaptive AuthenticationIARequires adaptive authentication under specific conditions, directly strengthening authentication mechanisms against improper or insufficient authentication.
IA-12Identity ProofingIAIdentity proofing requires collecting, validating, and verifying evidence to resolve claims to unique individuals, directly preventing insufficient proof of identity during account establishment.
AT-1Policy and ProceduresATDocumented procedures ensure personnel are trained on authentication mechanisms, tangibly lowering the risk of improper authentication being exploited.
AT-2Literacy Training and AwarenessATSecurity awareness training instructs users on secure authentication practices and avoiding credential compromise.
AT-3Role-based TrainingATTraining on authentication mechanisms and best practices decreases the occurrence of improper authentication.
AU-10Non-repudiationAUNon-repudiation requires strong authentication mechanisms to irrefutably attribute performed actions to specific individuals or processes.
AU-14Session AuditAUSession content review can reveal authentication bypasses or failures in session establishment.
AU-6Audit Record Review, Analysis, and ReportingAUReview of authentication-related audit records can detect improper authentication mechanisms or bypasses.
CA-2Control AssessmentsCAAssessments check authentication mechanisms for correct implementation and effectiveness, reducing successful authentication bypass attempts.
CA-3Information ExchangeCAMandating documentation of security requirements for exchanges includes specifying and enforcing authentication mechanisms between systems.
CA-8Penetration TestingCAPenetration testing probes authentication mechanisms for bypasses, allowing identification and fixing of improper authentication issues.
PM-13Security and Privacy WorkforcePMDevelopment programs cover authentication best practices, making weak or missing authentication less likely.
PM-14Testing, Training, and MonitoringPMAuthentication testing and monitoring activities ensure mechanisms are implemented, maintained, and resistant to bypass.
PM-7Enterprise ArchitecturePMSecurity-conscious enterprise architecture mandates authentication mechanisms and identity management at scale, mitigating improper authentication.
Show 25 more broadly-applicable controls
IA-13Identity Providers and Authorization ServersIAIdentity providers centralize and enforce authentication mechanisms, reducing improper authentication.
IA-2Identification and Authentication (Organizational Users)IARequires unique identification and authentication of organizational users, directly preventing improper authentication.
IA-3Device Identification and AuthenticationIAEnforces unique device identification and authentication before any connection is established, directly mitigating improper authentication weaknesses.
IA-4Identifier ManagementIAProvides unique, authorized identifiers that are foundational to preventing authentication weaknesses.
IA-7Cryptographic Module AuthenticationIADirectly requires implementation of compliant authentication mechanisms to cryptographic modules, preventing improper authentication.
IA-8Identification and Authentication (Non-organizational Users)IAMandates unique identification and authentication of non-organizational users, directly mitigating improper authentication.
IA-9Service Identification and AuthenticationIARequires unique identification and authentication of services before any communications, directly mitigating improper authentication.
SA-11Developer Testing and EvaluationSAAuthentication mechanism testing and evaluation during development identifies bypass or weakness conditions, with mandatory correction prior to system delivery.
SA-16Developer-provided TrainingSADeveloper-provided instruction on authentication controls improves correct implementation and ongoing operation of authentication.
SA-3System Development Life CycleSARequiring explicit security roles and risk integration in the SDLC forces authentication mechanisms to be planned, documented, and validated instead of omitted or weakly implemented.
SC-19Voice Over Internet ProtocolSCImplementation guidance and monitoring requirements force proper authentication mechanisms for VoIP endpoints and sessions.
SC-26DecoysSCDecoy authentication surfaces detect bypass attempts and deflect real credential attacks through observable malicious interactions.
SC-40Wireless Link ProtectionSCRequires authentication mechanisms on the wireless link, making improper authentication weaknesses harder to exploit.
CP-10System Recovery and ReconstitutionCPSystem recovery re-establishes trusted authentication processes following a compromise.
CP-13Alternative Security MechanismsCPDelivers alternative authentication approaches to verify identity when the primary authentication mechanism is unavailable or compromised.
PL-8Security and Privacy ArchitecturesPLSecurity architectures must specify authentication requirements and approaches, making systemic authentication weaknesses harder to introduce.
PL-9Central ManagementPLCentralized authentication mechanisms and policy enforcement reduce the chance of missing or weak authentication on individual components.
PS-1Policy and ProceduresPSPersonnel screening, identity verification, and access-agreement requirements support reliable authentication and reduce authentication bypass opportunities.
PS-4Personnel TerminationPSRevoking authenticators and credentials eliminates the ability of terminated individuals to authenticate using prior mechanisms.
RA-10Threat HuntingRAHunting detects anomalous authentication patterns or successful bypasses that allow persistent unauthorized entry.
RA-3Risk AssessmentRAAssessment of authentication-related threats and vulnerabilities leads to remediation of missing or weak authentication controls.
AC-9Previous Logon NotificationACDetects unauthorized successful logons resulting from improper authentication implementations.
IR-10Integrated Information Security Analysis TeamIRIntegrated incident analysis improves detection and mitigation of authentication bypasses and failures during security events.
MA-4Nonlocal MaintenanceMARequiring strong authentication for establishing nonlocal maintenance sessions directly mitigates improper authentication.
SI-4System MonitoringSIDetects unauthorized use and connections stemming from authentication bypass or failure.

MITRE ATT&CK techniques this weakness enables

Our own two-way CWE↔ATT&CK cross-walk — a direct mapping with no public source (the CWE→CAPEC→ATT&CK chain leaves most top weaknesses, incl. XSS and SQLi, mapped to nothing).

Direction: other covers this; this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2021-22893 KEV 10.010.00.47172021-04-23
CVE-2025-32975 KEV 10.010.00.02422025-06-24
CVE-2026-20127 KEV 10.010.00.88242026-02-25
CVE-2026-20182 KEV 10.010.00.91522026-05-14
CVE-2013-0625 KEV 9.99.80.93802013-01-09
CVE-2015-7755 KEV 9.99.80.61402015-12-19
CVE-2017-7921 KEV 9.99.81.00002017-05-06
CVE-2016-7836 KEV 9.99.80.19382017-06-09
CVE-2017-12478 9.99.80.78272017-08-07
CVE-2015-7871 9.99.80.81762017-08-07
CVE-2015-1187 KEV 9.99.80.82862017-09-21
CVE-2018-3810 9.99.80.91142018-01-01
CVE-2018-10561 KEV 9.99.80.93042018-05-04
CVE-2018-17153 9.99.80.86592018-09-18
CVE-2018-17431 9.99.80.83912019-01-30
CVE-2019-13372 9.99.80.82492019-07-06
CVE-2019-1937 9.99.80.75862019-08-21
CVE-2019-19006 KEV 9.99.80.36612019-11-21
CVE-2013-1359 9.99.80.89402020-02-11
CVE-2015-6922 9.99.80.82102020-02-17
CVE-2020-9294 9.99.80.77782020-04-27
CVE-2020-4427 KEV 9.99.80.70032020-05-07
CVE-2020-12812 KEV 9.99.80.49342020-07-24
CVE-2020-17523 9.99.80.85912021-02-03
CVE-2021-32030 KEV 9.99.80.99392021-05-06