By weakness (CWE)
CWE-1390: related vulnerabilities
CVEs classified under CWE-1390. Understanding the weakness class helps prioritize systemic fixes over one-off patches.
4 published vulnerabilities
- CVE-2026-44237HIGH 8.1
FreePBX versions before 17.0.8 contain a flaw in their OAuth2 implementation that allows an attacker to bypass credential verification. If an attacker discovers or guesses a valid client application ID, they can request OAuth2 access tokens without needing the corresponding secret passphrase. This grants them the ability to authenticate and interact with the FreePBX API as if they were a legitimate application, potentially enabling unauthorized access to voice, data, and configuration controls.
- CVE-2026-57352MEDIUM 4.8
A vulnerability exists in the ALD – Dropshipping and Fulfillment plugin for WooCommerce (versions 2.2.0 and earlier) that allows attackers to bypass authentication controls without credentials. The flaw stems from improper validation of authentication mechanisms, creating an opening for unauthorized access. An attacker would need to perform specific actions or supply particular input to exploit this—it's not trivial, but it is accessible over the network without user interaction.
- CVE-2026-49322MEDIUM 4.3
The 2025 Indian Motorcycle Scout Bobber + Tech model contains a flaw in its wireless control system that allows someone with access to the motorcycle's internal network to steal the owner's PIN unlock code by observing just a single authentication attempt. Instead of using proper cryptographic security, the system performs simple mathematical operations that can be reversed to recover the PIN, completely bypassing the bike's primary security lock.
- CVE-2026-49323MEDIUM 4.3
The 2025 Indian Motorcycle Scout Bobber + Tech model contains a flaw in how its wireless control module authenticates with the engine control module. An attacker positioned on the vehicle's internal network can intercept a single authentication exchange and reverse-engineer the motorcycle's immobilizer secret—the cryptographic key that prevents unauthorized engine starts. Once recovered, the attacker can bypass the immobilizer entirely and start the engine without the key fob.