SiteShadow
Back to vulnerability library
Detected byCWE-aware static analysis

CWE-287 Improper Authentication

Coverage: 14 rules in the SiteShadow rule registry target this CWE (registry v2.0.0). Regex 12Other-pattern 2 Also: Taint and heuristic analyzers may also detect related flows (see coverage for the authoritative list) Registry tagging shows intent, for sample-level behaviour and benchmarked gaps see known gaps.

What this means

SiteShadow flagged an authentication pattern that can be bypassed or behaves incorrectly (missing checks, "trust the client" auth, weak token validation, or inconsistent auth across endpoints).

Why it matters

Improper authentication can allow unauthorized access.

Safer examples

1) Centralize auth middleware and make it default

Prefer "authenticated unless explicitly public."

2) Validate tokens/credentials robustly

3) Test auth boundaries

Add integration tests that assert 401/403 for unauthenticated requests to sensitive endpoints.

How SiteShadow detects it (high level)

References

---

← Back to Vulnerability Library

Catch this in your code with SiteShadow.

Every released SiteShadow scanner is free, including full project analysis, reports, patterns, dashboard access, and configured organization SSO.