CWE-287: Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
How it's found
Improper Authentication describes a general pattern rather than a single fixed bug. Testers use a mix of static analysis and manual code review to find where a target's code matches this pattern, then confirm exploitability by hand.
Consequences
- Read Application Data, Gain Privileges or Assume Identity, Execute Unauthorized Code or Commands: This weakness can lead to the exposure of resources or functionality to unintended actors, possibly providing attackers with sensitive information or even execute arbitrary code.
Mitigations
- Architecture and Design: Use an authentication framework or library such as the OWASP ESAPI Authentication feature.
How TurboPentest tests for this
TurboPentest tests authentication dynamically, following the OWASP testing guides across login, session, and multi-factor flows to find bypasses and weak credential handling. Paladin AI chains findings across requests to surface multi-step authentication weaknesses. A manual IntegSec engagement applies deeper methodology.
Tools: Paladin AI, OWASP ZAP
Frequently asked questions
What is CWE-287?
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
How do you find Improper Authentication?
Improper Authentication describes a general pattern rather than a single fixed bug. Testers use a mix of static analysis and manual code review to find where a target's code matches this pattern, then confirm exploitability by hand.
What is the impact of CWE-287?
Read Application Data, Gain Privileges or Assume Identity, Execute Unauthorized Code or Commands: This weakness can lead to the exposure of resources or functionality to unintended actors, possibly providing attackers with sensitive information or even execute arbitrary code.
Does TurboPentest test for Improper Authentication?
TurboPentest tests authentication dynamically, following the OWASP testing guides across login, session, and multi-factor flows to find bypasses and weak credential handling. Paladin AI chains findings across requests to surface multi-step authentication weaknesses. A manual IntegSec engagement applies deeper methodology.
Related CWEs
- Pillar weaknessCWE-284: Improper Access Control
- Variant weaknessCWE-259: Use of Hard-coded Password
- Base weaknessCWE-301: Reflection Attack in an Authentication Protocol
- Base weaknessCWE-309: Use of Password System for Primary Authentication
- Class weaknessCWE-345: Insufficient Verification of Data Authenticity
- Compound weaknessCWE-384: Session Fixation
About this reference
These security references are maintained by IntegSec, an offensive-security firm whose team holds CISSP, OSCP, and OSCE certifications and has run thousands of penetration tests. Content is kept current as tools, standards, and attack techniques evolve.
Find these issues before an attacker does
TurboPentest runs an agentic AI pentest against your target and reports findings with proof, from $99 per target.
Start a pentest