By weakness (CWE)

CWE-287: related vulnerabilities

CVEs classified under CWE-287. Understanding the weakness class helps prioritize systemic fixes over one-off patches.

106 published vulnerabilities · page 1 of 2

  • CVE-2026-46827HIGH 8.8

    CVE-2026-46827 is a high-severity vulnerability in Oracle E-Business Suite's Payroll module that allows a low-privileged network attacker to gain full control over the payroll system. An authenticated user with minimal permissions can exploit this flaw remotely via HTTP to read sensitive data, modify payroll records, or disrupt service availability. This represents a complete compromise of the affected payroll component.

  • CVE-2026-46903HIGH 8.8

    A vulnerability in Oracle JD Edwards EnterpriseOne Tools allows a user with basic network access and low-level system privileges to gain complete control over the application. The flaw resides in the business logic security layer and can be exploited without user interaction or complex attack setup. An attacker leveraging this vulnerability could read sensitive financial data, modify business records, or disrupt operations.

  • CVE-2026-46916HIGH 8.8

    A high-severity flaw in Oracle's Process Manufacturing Product Development component (part of E-Business Suite) allows authenticated users with low-level network access to gain full control over the affected system. An attacker who has obtained basic credentials can exploit this over the network to read sensitive data, modify critical information, and disrupt operations without requiring user interaction. Versions 12.2.3 through 12.2.15 are vulnerable.

  • CVE-2026-46921HIGH 8.8

    A high-severity vulnerability exists in Oracle Siebel CRM Cloud Manager that allows a low-privileged attacker with network access to take over the entire application. The flaw affects Siebel CRM versions 17.0 through 26.5 and requires only standard HTTP access—no user interaction or elevated privileges needed beyond basic network authentication. Attackers exploiting this could gain full control over confidentiality, integrity, and availability of the system.

  • CVE-2026-46928HIGH 8.8

    A vulnerability in Oracle Spares Management, part of Oracle E-Business Suite, allows users with standard network access and basic system credentials to gain complete control over the application. An attacker with low-level privileges can exploit this flaw remotely via HTTPS to read sensitive data, modify records, and disrupt operations. The vulnerability affects versions 12.2.3 through 12.2.15.

  • CVE-2026-46929HIGH 8.8

    CVE-2026-46929 is a high-severity vulnerability in Oracle's Cost Management component within Oracle E-Business Suite (versions 12.2.3 through 12.2.15). An attacker with a low-level user account and network access can exploit this flaw via HTTP to gain complete control over the Cost Management system. The vulnerability requires no user interaction, making it straightforward to exploit. Successful exploitation allows attackers to read sensitive data, modify cost planning information, and disrupt system availability.

  • CVE-2026-46937HIGH 8.8

    A vulnerability in Oracle iSetup (a configuration and setup component of Oracle E-Business Suite) allows an authenticated user with basic network access to take control of the iSetup application. The flaw affects versions 12.2.3 through 12.2.15. Because the vulnerability requires low-level credentials but no user interaction, it presents significant risk in environments where contractor, vendor, or junior staff accounts exist—anyone with a valid login can trigger the compromise without special tools or social engineering.

  • CVE-2026-46940HIGH 8.8

    CVE-2026-46940 is a critical vulnerability in Oracle Cost Management, a component of Oracle E-Business Suite. An attacker with a low-level user account and network access can exploit this flaw to take over the entire Cost Management system. The vulnerability is network-accessible, does not require user interaction, and can compromise confidentiality, integrity, and availability of the affected system. Organizations running Oracle E-Business Suite versions 12.2.3 through 12.2.15 should treat this as an urgent security matter.

  • CVE-2026-46942HIGH 8.8

    A vulnerability in Oracle's Process Manufacturing Process Planning component allows attackers with low-level network access to take over the system. The flaw affects versions 12.2.3 through 12.2.15 of the Oracle E-Business Suite module and requires an attacker to have valid user credentials, but no special privileges or user interaction. Once exploited, an attacker gains complete control over the affected application, compromising all data confidentiality, system integrity, and availability.

  • CVE-2026-46951HIGH 8.8

    A vulnerability in Oracle Quality, part of Oracle E-Business Suite, allows an authenticated attacker to gain complete control over the Oracle Quality system. The attacker only needs basic user-level network access via HTTP to trigger the flaw. Once exploited, an attacker can read, modify, or delete sensitive data and disrupt quality operations. The vulnerability affects Oracle Quality versions 12.2.3 through 12.2.15.

  • CVE-2026-46952HIGH 8.8

    A vulnerability in Oracle Quality, part of Oracle E-Business Suite, allows users with basic system access to take complete control of the application via network requests. The flaw affects Oracle Quality versions 12.2.3 through 12.2.15 and requires only low-level credentials to exploit—no special tricks or user interaction needed. Successful exploitation grants an attacker the ability to read, modify, and delete data, or disable the system entirely.

  • CVE-2026-46961HIGH 8.8

    A critical vulnerability in Oracle Project Portfolio Analysis allows authenticated users with basic network access to gain full control over the application. An attacker with a low-privilege account can exploit this flaw to read, modify, or delete sensitive project data and disrupt service availability. The vulnerability affects multiple versions of the product (12.2.3 through 12.2.15) and requires only HTTP connectivity—no special conditions or user interaction needed once the attacker gains initial access credentials.

  • CVE-2026-46962HIGH 8.8

    A vulnerability in Oracle Project Portfolio Analysis (part of Oracle E-Business Suite) allows someone with basic network access and low-level user credentials to take complete control of the system. The flaw affects versions 12.2.3 through 12.2.15 and requires only a standard user account and HTTP access—no special techniques needed. Once exploited, an attacker gains the ability to read sensitive data, modify information, and disrupt operations.

  • CVE-2026-46972HIGH 8.8

    A flaw in Oracle's Outsourced Manufacturing for Discrete Industries module (versions 12.2.3 through 12.2.15) allows attackers who have basic user-level network access to fully compromise the system. An attacker with low-privilege credentials can exploit this vulnerability over HTTP to gain complete control over the application, potentially reading, modifying, or destroying sensitive manufacturing data. The vulnerability requires only standard network connectivity and user credentials to trigger—no social engineering or complex exploitation steps are needed.

  • CVE-2026-46973HIGH 8.8

    A vulnerability in Oracle's Outsourced Manufacturing for Discrete Industries (part of E-Business Suite) allows attackers with basic user credentials to gain complete control over the system via the network. The flaw affects all versions from 12.2.3 through 12.2.15 and poses a severe risk because an attacker with low-level access can bypass controls to read, modify, or delete critical manufacturing data.

  • CVE-2026-49194HIGH 8.8

    A debugging function called SCREEN_CLICK(5053) in certain Acer Connect M6E 5G devices allows an authenticated user to bypass the normal login process and gain direct access to an interactive shell. This circumvents device security controls and could enable an attacker with valid credentials to take full control of the device without standard authentication checks.

  • CVE-2026-49443HIGH 8.8

    A critical authentication flaw in authentik—an open-source identity provider—allows attackers to hijack user accounts across the platform. If an attacker has the ability to modify a source connection (such as an external authentication provider) and controls an account in one of those sources, they can log in as any other user in the system. This is a privilege escalation vulnerability requiring two preconditions: administrative access to source configuration and an existing account in a connected source. The flaw affects authentik versions prior to 2025.12.6, 2026.2.4, and 2026.5.1.

  • CVE-2026-58253HIGH 8.8

    NATS Server, a messaging platform used in cloud and edge computing environments, contains an authentication bypass vulnerability in versions prior to 2.14.0, 2.12.7, and 2.11.16. When a fallback authentication user (no_auth_user) is configured, the server incorrectly applies a performance optimization meant for regular client connections to inter-server routes and leaf node connections. This allows an unauthenticated attacker on the network to connect as a privileged peer and potentially read data, modify configurations, or disrupt services. Organizations running vulnerable NATS deployments should prioritize upgrades to patched versions.

  • CVE-2026-56223HIGH 8.7

    Capgo versions before 12.128.2 have a critical account takeover flaw in their user provisioning system. An attacker with admin access to an enterprise organization can trick the system into merging victim accounts by forging identity provider assertions. This happens because the system doesn't properly verify that the identity provider making the request is authorized to provision users for the victim's domain. Once merged, the attacker gains complete control of the victim's account, organization, and all associated data.

  • CVE-2026-49202HIGH 8.6

    Acer Connect M6E 5G devices store multimedia session archives (recordings, transcripts, or similar session data) in a way that allows anyone on the internet to access them without logging in. The problem is made worse by overly permissive CORS settings, which let attackers retrieve these files from a victim's browser during a cross-site attack—turning a confidentiality leak into an active theft vector. An attacker doesn't need special tools or credentials; they can pull sensitive multimedia data remotely.

  • CVE-2026-44810HIGH 8.4

    A flaw in Windows Cryptographic Services fails to properly authenticate certain operations, allowing an attacker with local access to bypass security controls and gain elevated system privileges. The vulnerability affects multiple versions of Windows 11 and Windows Server 2022/2025. An attacker with standard user access could exploit this to run code with administrative rights, potentially compromising the entire system.

  • CVE-2026-54320HIGH 8.4

    Daytona, an infrastructure runtime for AI code execution, contains a flaw in how it validates organization invitations. Before version 0.184.0, a user could accept an organization invitation—potentially gaining Owner-level access—without verifying their email address, as long as the email matched the invitation target. This circumvents a security control that normally requires email verification before granting organization membership. The vulnerability requires an attacker to have registered an account and received a session from their identity provider, but does not require prior authorization within Daytona itself.

  • CVE-2026-45567HIGH 8.3

    Roxy-WI, a popular web management interface for load balancers and web servers (HAProxy, Nginx, Apache, and Keepalived), contains an authentication bypass flaw in version 8.2.6.4 and earlier. An attacker can reach the unauthenticated /api/gpt endpoint by crafting a URL containing the 'api' substring, bypassing login requirements. This allows unauthorized access to administrative functions without valid credentials.

  • CVE-2026-49203HIGH 8.3

    CVE-2026-49203 is a critical authorization flaw in Acer Connect M6E 5G cellular management APIs. The vulnerability allows an attacker with network access to remotely rewrite or delete eSIM profiles without authentication. Because the affected endpoints lack proper caller verification, an unauthenticated adversary on the same network can manipulate cellular configurations, potentially disconnecting devices or provisioning unauthorized SIM profiles. The flaw exposes organizations relying on these devices for cellular connectivity to profile tampering and service disruption.

  • CVE-2026-56675HIGH 8.3

    9Router, an AI-powered router designed to optimize token usage and costs, contains a critical authentication bypass flaw in versions before 0.5.2. The vulnerability stems from the application trusting all loopback traffic (127.0.0.1) as local, which allows a reverse proxy running on the same host to forward external requests through localhost. This causes the dashboard guard to incorrectly classify remote requests as trusted, granting unauthenticated access to API endpoints that should require authentication. An attacker can exploit this to discover available models, access credentials, and abuse upstream provider integrations.

  • CVE-2026-10560HIGH 8.2

    IBM Langflow OSS versions 1.0.0 through 1.9.6 have a flaw that allows anyone on the internet to access job build information and stop running jobs without needing a password or authentication token. An attacker only needs a valid job identifier to read sensitive build event data or cancel active jobs, leading to information leakage and service disruption.

  • CVE-2026-48780HIGH 8.2

    Forem, an open-source community platform, contains a flaw in how it validates email addresses when enforcing domain-level access controls. An attacker can craft a specially formatted email address that bypasses the allowlist or denylist rules protecting invite-only deployments, potentially gaining unauthorized access to restricted communities. The vulnerability has been fixed in the codebase as of commit a2ab6d4.

  • CVE-2026-59822HIGH 8.2

    LiteLLM, an AI Gateway proxy for unified LLM API access, contained an authentication bypass in its MCP Streamable HTTP endpoint. Attackers could craft a fake Authorization header to trigger a fallback mechanism that replaced proper API key validation with an empty authentication object, allowing unauthorized access to MCP tooling. This issue affects versions prior to 1.84.0 and has been patched.

  • CVE-2026-12595HIGH 8.1

    LoginPress Pro, a WordPress authentication plugin, contains a critical flaw in its Discord login integration. When users sign in via Discord OAuth, the plugin fails to verify that the email address returned by Discord has been confirmed by the user. An attacker can register a Discord account with someone else's email address (without Discord verifying it) and use Discord's standard login flow to hijack that person's WordPress account. This works for any account, including administrator accounts, and requires no special access or social engineering—only knowledge of a target's email address.

  • CVE-2026-12597HIGH 8.1

    LoginPress Pro, a popular WordPress authentication plugin, contains a flaw in its GitHub login integration that allows attackers to log into any user account—including admin accounts—without knowing their password. The vulnerability stems from the plugin accepting unverified email addresses from GitHub as proof of identity. An attacker can add someone else's email address to their GitHub profile (as an unverified email) and use that to trick the plugin into granting access to the corresponding WordPress account. While exploitation requires specific conditions around how GitHub orders email addresses in its response, the underlying design flaw is severe: the plugin never checks whether an email is actually verified before trusting it for account binding.

  • CVE-2026-12598HIGH 8.1

    The LoginPress Pro WordPress plugin contains a critical flaw in its Spotify social login feature that allows attackers to hijack any WordPress account, including administrator accounts. The vulnerability stems from the plugin accepting an unverified email address from Spotify without confirming that the attacker actually owns that email or the target WordPress account. An attacker simply needs to create a Spotify account using someone else's email address and then use Spotify's login feature on the vulnerable WordPress site to gain full access to that person's account.

  • CVE-2026-32804HIGH 8.1

    Dell PowerFlex Manager versions before 5.1.0.1 contain an authentication flaw that allows an attacker on the same network segment to gain unauthorized access without credentials. The vulnerability does not require any user interaction and can be exploited by someone already positioned on an adjacent network—making it particularly risky in environments where trust in lateral network access may be assumed. An attacker exploiting this could modify storage configurations, disable services, or access sensitive data.

  • CVE-2026-40138HIGH 8.1

    BeyondTrust Remote Support and Privileged Remote Access contain a critical flaw in how they validate authentication credentials before a user logs in. An attacker on the network can exploit this weakness to bypass normal login protections and gain unauthorized access to the appliance, potentially including high-privilege accounts. The vulnerability only affects systems where a specific authentication configuration is enabled, which limits but does not eliminate the risk footprint.

  • CVE-2026-45156HIGH 8.1

    Nextcloud's User OIDC (OpenID Connect) authentication system fails to verify signatures from ID4me identity authorities. An attacker controlling a malicious ID4me authority can forge authentication tokens to impersonate any user on an affected Nextcloud instance. This is a high-severity authentication bypass that requires user interaction—typically a user clicking a login link or being redirected to a compromised identity provider. The vulnerability spans multiple version branches and has been patched across supported releases.

  • CVE-2026-49872HIGH 8.1

    Apache APISIX versions 3.0.0 through 3.16.0 contain an authentication bypass flaw in the CAS authentication plugin. An attacker with valid credentials to one system can potentially use those credentials to authenticate as a different user or gain unauthorized access through the misconfigured authentication logic. This is a significant issue because CAS (Central Authentication Service) is commonly deployed in enterprise environments where authentication decisions directly gate access to sensitive APIs and services.

  • CVE-2026-52845HIGH 8.1

    Caddy, a modern web server platform, contains a header-handling vulnerability that allows authenticated attackers to inject fake identity or group information into requests sent to PHP applications. The issue stems from a mismatch in how Caddy processes headers during authentication checks versus how it later converts those headers for PHP/FastCGI backends. An attacker can exploit this by sending a specially crafted header variant that bypasses Caddy's security controls, potentially allowing privilege escalation or impersonation within downstream applications. The flaw affects versions before 2.11.4 and is corrected in that release.

  • CVE-2026-56345HIGH 8.1

    AVideo versions through 29.0 contain a critical flaw in the Meet plugin that allows attackers to impersonate any user, including administrators, without knowing their passwords. The vulnerability stems from the uploadRecordedVideo.json.php endpoint accepting user IDs directly from filenames without validation. An attacker who obtains the Meet shared secret—obtainable through separate path-traversal or timing attacks—can upload a specially crafted video file with a filename like '1-anything.mp4' to hijack any account. This is a complete authentication bypass that grants full system access.

  • CVE-2026-59224HIGH 8.0

    Open WebUI, a self-hosted AI platform, contains an authentication bypass vulnerability in versions before 0.10.0. When a user accesses the terminal feature, the system constructs a backend connection using an unencoded session ID, allowing an attacker to inject query parameters and impersonate another user. Additionally, the system trusts an HTTP header (X-User-Id) without verifying it, making it possible for an authenticated attacker to escalate privileges or access other users' terminal sessions. The vulnerability requires the attacker to be already logged in and relies on social engineering or user interaction to succeed.

  • CVE-2026-12112HIGH 7.8

    A vulnerability in the foreman-mcp-server, used by Red Hat Satellite and The Foreman, allows attackers with local access to steal and reuse administrative session credentials. The flaw stems from the server caching authenticated connections without properly validating them later, and it logs session identifiers in plaintext to standard output—making them discoverable. An attacker who gains local system access can read these logs, hijack an active administrator's session, and execute commands with full administrative privileges.

  • CVE-2026-32174HIGH 7.7

    A flaw in Azure Bot Service's authentication system allows someone who already has legitimate access to the service to bypass normal permission controls and gain elevated privileges. The vulnerability is network-accessible, meaning an attacker doesn't need local system access, but they do need valid credentials to exploit it. The impact is primarily on the integrity of the system—an attacker could modify configurations, data, or access controls—rather than stealing data or causing downtime.

  • CVE-2026-58423HIGH 7.7

    A flaw in how LFS (Large File Storage) systems validate SSH authentication allows an authenticated user to bypass normal access controls and read files from private repositories they shouldn't be able to access. The vulnerability requires an attacker to already have valid credentials, but they can then craft a malformed SSH command to circumvent permission checks. This is a confidentiality risk—an attacker gains unauthorized visibility into sensitive code and data—but doesn't allow modification or deletion.

  • CVE-2026-11703HIGH 7.5

    A flaw in WolfSSL allows an attacker to reuse a cached TLS session in a different virtual-hosting context than the one where it was originally authenticated. When a client reconnects using a saved session, the library failed to verify that the server name (SNI) and protocol settings (ALPN) matched the original connection. If authentication requirements differ across virtual hosts, an attacker could bypass those checks by resuming a session meant for one host in the security context of another. The fix ensures all session resumptions now validate SNI and ALPN bindings, falling back to a full handshake if they don't match.

  • CVE-2026-40964HIGH 7.5

    A critical authentication flaw in Cloud Foundry's cf-auth-proxy component allows anyone on the internet to forge valid authentication tokens and read all application logs and system metrics without logging in. The vulnerability affects all versions of log-cache_release through v3.2.6, and Cloud Foundry Deployment installations bundling those versions. An attacker needs only network access to the affected component—no special credentials or user interaction required.

  • CVE-2026-41896HIGH 7.5

    Coolify, an open-source platform for managing servers and applications, contains a critical authentication bypass in its webhook validation system. When a Coolify application is first created, the webhook secret used to verify GitHub webhook requests is left null (empty). Due to how PHP handles null values in cryptographic functions, this null secret gets treated as an empty string, allowing attackers to calculate the expected signature themselves. By forging a valid webhook signature, an attacker can trigger unauthorized deployments without any authentication. This affects all Coolify versions before 4.0.0-beta.474.

  • CVE-2026-48929HIGH 7.5

    Rocket.Chat versions before 8.5.1 (and earlier branches) contain a flaw that allows anyone on the internet to permanently delete files that users have uploaded to the chat platform—without needing to log in. An attacker discovers the ID of a file from public messages or download links, then sends a single command via Rocket.Chat's WebSocket connection that deletes it from the server. The vulnerability stems from a missing authentication check in the file deletion function. Because file IDs are often visible in public channels, this poses a material risk to data integrity and availability for any Rocket.Chat deployment exposed to untrusted networks.

  • CVE-2026-50559HIGH 7.5

    Quarkus, a popular Java framework for cloud-native applications, has a security flaw in how it enforces access controls on HTTP paths. An attacker can bypass authorization policies by embedding encoded characters—specifically encoded semicolons (%3B), slashes (%2F), or backslashes (%5C)—in request URLs. This allows unauthorized access to protected resources and sensitive functionality that should be restricted. The vulnerability affects multiple Quarkus version branches; patched versions are available across the 3.20, 3.27, 3.33, and 3.36+ series.

  • CVE-2026-55727HIGH 7.5

    Genetec Security Center versions 5.14.0.0 through 5.14.178.17 contain a flaw in how they authenticate requests for live video streams. An attacker on the network can bypass this authentication and view live video feeds without credentials. This is a network-accessible vulnerability that requires no user interaction to exploit.

  • CVE-2026-56219HIGH 7.5

    Capgo versions before 12.128.2 suffer from an authentication bypass that leaks sensitive organizational data. An attacker can request organization membership details, role assignments, and member email addresses by exploiting improper NULL value handling in the authorization layer. The vulnerability requires only a public API key and network access—no valid user credentials needed—making it straightforward to discover and exploit at scale.

  • CVE-2026-8293HIGH 7.5

    A vulnerability in the Really Simple Security WordPress plugin allows attackers to bypass two-factor authentication (2FA) on two of its REST API endpoints. An attacker with a user's password can obtain a valid WordPress session without completing the required email one-time password (OTP) challenge, effectively circumventing a key security control. This affects plugin versions prior to 9.5.10.1.

  • CVE-2026-41720HIGH 7.4

    Spring LDAP, a widely-used library for LDAP authentication and directory operations, contains a flaw in how it validates user credentials during the authentication process. Specifically, the vulnerability allows attackers to successfully authenticate by providing a username with an empty or null password—credentials that should never be accepted. An attacker exploiting this could gain unauthorized access to systems relying on Spring LDAP for authentication, provided they can interact with the LDAP authentication flow.

  • CVE-2026-46579HIGH 7.4

    OpenShift Router has a header-spoofing vulnerability that breaks mutual TLS authentication when routes are configured to allow unencrypted HTTP traffic. An attacker can send plain HTTP requests with forged client certificate headers, tricking backend services into accepting them as though they came from legitimate authenticated clients. This bypasses the certificate-based trust model that many organizations rely on for service-to-service security.

  • CVE-2026-48526HIGH 7.4

    PyJWT, a widely-used Python library for handling JSON Web Tokens (JWTs), contains an authentication bypass vulnerability in versions before 2.13.0. The flaw allows attackers to forge valid tokens by exploiting insufficient validation of cryptographic key usage. Specifically, when a library instance is configured to accept both asymmetric (public-key) and HMAC (shared-secret) algorithms, an attacker can take the issuer's public key—which is often publicly available—and use it as the HMAC secret to create forged tokens that the vulnerable library will accept as legitimate.

  • CVE-2026-49502HIGH 7.4

    Dell PowerFlex Manager versions before 5.1.0.1 contain a flaw that allows an attacker on the same network segment to bypass authentication controls and gain unauthorized access to the system. Without needing valid credentials, an adjacent network attacker could read sensitive data, modify information, or take unauthorized actions within PowerFlex Manager. This is particularly concerning for organizations that assume internal network access is inherently trusted.

  • CVE-2026-54781HIGH 7.4

    CoreWCF, a .NET Core implementation of Windows Communication Foundation, contains a flaw in how it validates SAML security tokens. Specifically, the vulnerability allows attackers to bypass authentication checks by either downgrading holder-of-key confirmations to weaker methods or injecting custom confirmation assertions without proving they actually control the token. An attacker could potentially use a stolen or forged SAML token to authenticate as a legitimate user without demonstrating proof of possession. This affects CoreWCF versions before 1.8.1 and 1.9.1.

  • CVE-2026-55075HIGH 7.4

    Coder, a platform for provisioning remote development environments via Terraform, contains two authentication bypass flaws in its OIDC (OpenID Connect) login flow that can chain together to enable account takeover. The vulnerabilities stem from overly permissive email-based user matching and improper handling of email verification claims. An attacker can exploit these weaknesses to gain unauthorized access to existing user accounts without knowing the victim's password. Affected versions are those prior to 2.29.7, 2.32.7, 2.33.8, and 2.34.2. The vendor has released patches that restrict email fallback linking and enforce stricter email verification defaults.

  • CVE-2026-55076HIGH 7.4

    Coder, a platform for provisioning remote development environments, contains an authentication bypass vulnerability in versions prior to 2.29.7, 2.32.7, 2.33.8, and 2.34.2. The flaw stems from improper validation of the `email_verified` claim returned by OpenID Connect (OIDC) identity providers. When an IdP returns this claim in an unexpected format (such as a string instead of a boolean) or omits it entirely, Coder's authentication logic fails in an unsafe way—treating the email as verified regardless. This, combined with a fallback mechanism that links accounts based on email alone, allows an attacker to take over existing user accounts by authenticating through an OIDC provider they control.

  • CVE-2026-55759HIGH 7.4

    Rocket.Chat's Apple Sign-In feature has a critical authentication bypass vulnerability. The application correctly verifies that an Apple identity token is cryptographically signed by Apple, but it fails to validate important claims within that token—such as the intended audience, expiration time, or nonce. This means an attacker who obtains a valid Apple identity token (whether from logs, network interception, or another application) can replay it indefinitely to log in as the victim user without any time limit. The vulnerability affects multiple versions of Rocket.Chat across several release branches and is resolved in patched versions released in mid-June 2026.

  • CVE-2026-10157HIGH 7.3

    Open5GS, an open-source 5G core network software stack, contains an authentication bypass vulnerability in its NGAP (NG Application Protocol) PathSwitchRequest message handler. An unauthenticated attacker can exploit this remotely to bypass authentication controls, potentially gaining unauthorized access to 5G network functions. The vulnerability affects Open5GS versions up to 2.7.6 and has been publicly disclosed with exploit code available, elevating the practical risk to deployed systems.

  • CVE-2026-10167HIGH 7.3

    A flaw in the OUSL-GROUP-BrinaryBrains School Student Management System allows attackers to bypass authentication by manipulating role parameters during login cookie creation. An attacker can remotely exploit this without requiring special privileges or user interaction, potentially gaining unauthorized access to the system. Proof-of-concept code has been publicly released, increasing the risk of real-world exploitation.

  • CVE-2026-10243HIGH 7.3

    A critical authentication flaw exists in code-projects Smart Parking System version 1.0 that allows unauthenticated remote attackers to bypass security controls on multiple administrative endpoints. An attacker can interact with these endpoints without valid credentials, potentially gaining unauthorized access to sensitive parking system functions. The vulnerability has been publicly disclosed and exploit code is available, elevating the risk of active exploitation.

  • CVE-2026-10281HIGH 7.3

    Enderfga's claw-orchestrator contains an authentication bypass in its API endpoint handler. Versions up to 3.5.5 fail to enforce authentication checks in the EmbeddedServer component, allowing unauthenticated remote attackers to access protected functionality. The flaw has been publicly disclosed and exploit code is available. Version 3.5.6 addresses the issue.

  • CVE-2026-10288HIGH 7.3

    A flaw in the Hotel and Tourism Reservation System version 1.0 allows attackers to bypass admin authentication. The vulnerability exists in the admin login page where the password verification function can be manipulated, enabling unauthorized access to the administrative interface without valid credentials. An attacker can exploit this remotely over the network, and proof-of-concept code has already been published publicly.

  • CVE-2026-10617HIGH 7.3

    GoClaw, a component by nextlevelbuilder, contains a flaw in its webhook verification handler that allows attackers to bypass authentication checks. An unauthenticated remote attacker can exploit this weakness to gain unauthorized access to protected webhook endpoints. The vulnerability affects GoClaw versions up to and including 3.11.3, and exploit code has already been made public, increasing the practical risk.

  • CVE-2026-10619HIGH 7.3

    A remote authentication bypass vulnerability exists in the sayan365 student-management-system affecting commit 7f3c9ce7d410332335c2affac93a385485051800 and earlier versions. An unauthenticated attacker can bypass authentication controls on multiple endpoints without requiring any special privileges or user interaction. The vulnerability allows attackers to gain unauthorized access to the system with confidentiality, integrity, and availability impact. Public exploit code is now available, increasing immediate risk.

  • CVE-2026-10777HIGH 7.3

    A weakness in the administrative backend of ealpha072's Student-Management-System allows attackers to bypass authentication controls and gain unauthorized access to sensitive functions. The vulnerability exists in the admin/config.php file and can be exploited remotely without requiring any special privileges or user interaction. Because exploit code is publicly available, the risk of active abuse is elevated. The project uses a rolling release model, so specific patched versions have not been publicly disclosed.

  • CVE-2026-10845HIGH 7.3

    IBM WebSphere Application Server versions 8.5 and 9.0 contain an authentication bypass vulnerability in their JAX-WS (Java API for XML Web Services) implementations. An attacker on the network can exploit this flaw to bypass login controls and gain unauthorized access to affected applications without providing valid credentials. The vulnerability requires no user interaction and can be triggered remotely, making it a practical threat to organizations running these older WebSphere versions.

  • CVE-2026-11618HIGH 7.3

    DTStack Taier, a data integration platform, contains an authentication bypass vulnerability in its login interceptor component that allows remote attackers to circumvent authentication controls without any credentials or user interaction. The vulnerability affects all versions up to 1.4.0 and has been publicly disclosed, increasing immediate exploitation risk.

  • CVE-2026-12773HIGH 7.3

    BerriAI's litellm library contains an authentication bypass vulnerability in its MCP (Model Context Protocol) Proxy component. The UserAPIKeyAuth function fails to properly validate API keys, allowing remote attackers to bypass authentication controls without requiring credentials or special privileges. This affects litellm versions up to 1.59.8. Because the vulnerability is network-accessible and the exploit code is publicly available, organizations using affected versions face immediate risk of unauthorized access to their LLM proxy infrastructure.

  • CVE-2026-12795HIGH 7.3

    BerriAI's litellm, an open-source LLM proxy framework, contains an authentication bypass vulnerability in its Single Sign-On (SSO) debug flow. An unauthenticated remote attacker can manipulate the SSO debug endpoint to bypass authentication controls, gaining unauthorized access to the system. The vulnerability affects litellm versions up to and including 1.82.2, and exploit code has already been publicly disclosed.

  • CVE-2026-13546HIGH 7.3

    Feehi CMS versions up to 2.1.1 contain a critical flaw in the REST API endpoint for articles (/api/articles) that allows attackers to bypass authentication controls entirely. An attacker can remotely manipulate requests to this endpoint without providing valid credentials, gaining unauthorized access to article data and functionality. This weakness has already been disclosed publicly, increasing the urgency of remediation.

  • CVE-2026-14622HIGH 7.3

    An authentication bypass vulnerability exists in jairiidriss restaurant-website-php-mysql, a PHP/MySQL application for restaurant management. The flaw resides in the AJAX endpoint handler at /admin/ajax_files, where insufficient authentication checks allow unauthenticated attackers to manipulate functionality remotely. Because the project uses a rolling release model, traditional version tracking is unavailable; however, the vulnerability has been confirmed in commits up to 521428b5b612449df0cf4a5d15ee40cba67f3d35. Public exploit code is available, elevating practical risk.

  • CVE-2026-47838MEDIUM 6.8

    Spring Security contains a flaw in how it processes X.509 certificate subject names (the DN field used for authentication). When a certificate contains a specially crafted Common Name (CN) value, Spring Security may misread it and extract the wrong username. An authenticated attacker could exploit this by presenting a malformed certificate to impersonate another user. The vulnerability affects multiple Spring Security versions across the 5.7, 5.8, 6.3, 6.4, and 6.5 release lines.

  • CVE-2026-48117MEDIUM 6.8

    DroneAware, a drone detection platform accessible at droneaware.io, had a critical account security flaw that allowed attackers to hijack user accounts before legitimate owners completed setup. An attacker could register an account using someone else's email address with their own password, then when the real owner activated the account (either by email link or Google login), the attacker's password remained valid—giving the attacker persistent, silent access without alerting the victim. The vulnerability has already been fixed server-side as of May 20, 2025, and no action is required from users.

  • CVE-2026-55689MEDIUM 6.8

    OpenFGA, an authorization engine widely used by developers, has a flaw in how it validates authentication tokens when using OpenID Connect (OIDC). Before version 1.18.0, if a system administrator configured OIDC authentication without explicitly setting an audience parameter, the system would accept tokens meant for other services using the same identity provider. An attacker with valid credentials for a related service could potentially use their token to gain unauthorized access to OpenFGA instances. This is a configuration-dependent vulnerability that requires both OIDC enablement and a missing audience configuration to be exploitable.

  • CVE-2026-59208MEDIUM 6.8

    n8n workflow automation instances can be tricked into granting unauthorized access when they trust multiple token issuers for authentication. An attacker with a valid token from one trusted issuer can impersonate users from another trusted issuer if their token's subject identifier matches a victim's username. The flaw stems from n8n only checking the user's identifier in the token while ignoring which issuer provided it, creating a mismatch between authentication sources.

  • CVE-2026-13208MEDIUM 6.5

    KubeVirt's virt-handler service has a flaw in how it validates incoming event messages from virt-launcher pods running on the same node. When a virt-launcher process sends updates about a virtual machine instance (VMI), the handler accepts the VMI identity directly from the message content without verifying that the sender is actually authorized to update that specific VMI. A compromised virt-launcher could exploit this to send fake lifecycle events for other VMIs on the same node, causing the handler to incorrectly update their state and disrupt normal operations.

  • CVE-2026-14714MEDIUM 6.5

    A flaw in chatgpt-on-wechat (CowAgent) version 2.1.0 allows attackers to bypass authentication on the WeChat endpoint by manipulating or omitting a required security token. The vulnerable code fails to validate whether the token is actually present before attempting signature verification, meaning an empty or missing token can pass authentication checks. An attacker can exploit this remotely without credentials to interfere with message integrity or system availability.

  • CVE-2026-15192MEDIUM 6.5

    A missing authentication vulnerability exists in Mettle Sendportal's API webhook handlers for email service integrations (Sendgrid, Postmark, Postal, Mailjet). An unauthenticated attacker can remotely manipulate webhook functions, potentially allowing unauthorized interception or modification of email delivery notifications. The vulnerability affects versions up to and including 3.0.1, and public exploitation details are available.

  • CVE-2026-35261MEDIUM 6.5

    Oracle Access Manager contains an authentication bypass vulnerability that allows attackers to gain unauthorized access to sensitive data without providing valid credentials. An attacker on a network can exploit this flaw through HTTP requests to read, modify, or delete data within the application. The vulnerability affects versions 12.2.1.4.0 and 14.1.2.1.0, and requires no special privileges or user interaction to exploit.

  • CVE-2026-55955MEDIUM 6.5

    Apache Tomcat contains an authentication weakness that allows attackers to replay encrypted cluster communications. When multiple Tomcat servers are configured to work together in a cluster, they use encryption to protect inter-server messages. This vulnerability lets an attacker capture and resend those encrypted messages without needing to know the encryption key, potentially gaining unauthorized access or making unauthorized changes. The flaw affects several versions of Tomcat across multiple release branches.

  • CVE-2026-55962MEDIUM 6.5

    A flaw in wolfSSL's TLS 1.3 implementation allows servers to incorrectly accept client authentication messages without verifying the client actually sent the required cryptographic proof of identity. This happens specifically when a server requests client authentication after the initial handshake is complete. The vulnerability only affects servers using wolfSSL's post-handshake authentication feature and does not impact typical clients or servers that perform all authentication during the initial connection setup.

  • CVE-2026-56312MEDIUM 6.5

    Capgo versions prior to 12.128.2 contain a flaw in their account invitation system that allows attackers to create unauthorized accounts by bypassing the captcha protection mechanism. When a user submits an invitation acceptance request, the system creates the account before validating the captcha token, meaning an attacker can send requests with invalid or missing captcha data and still successfully register accounts. This vulnerability enables account takeover of invite links and account enumeration attacks.

  • CVE-2026-58029MEDIUM 6.5

    A vulnerability in MediaWiki's authentication handling allows attackers to compromise user account security. The flaw resides in how the software processes authentication-related API calls and account linking operations. An attacker can exploit this without authentication or user interaction to gain unauthorized access to user accounts or modify account credentials, though the vulnerability does not enable full system compromise or data destruction.

  • CVE-2026-10283MEDIUM 6.3

    Bottelet DaybydayCRM contains an authentication bypass vulnerability in its Settings Handler component. An authenticated attacker can manipulate application settings to gain unauthorized access to functionality they should not have, potentially viewing sensitive data, modifying records, or disrupting service availability. The vulnerability affects versions up to 2.2.1 and requires an attacker to already have valid login credentials to exploit it.

  • CVE-2026-45283MEDIUM 6.3

    Nextcloud Server contains a file access control vulnerability in its files_lock app that allows authenticated users to manipulate file locks belonging to other users. By knowing the WebDAV paths of files owned by colleagues, an attacker could lock or unlock those files without authorization. Additionally, the vulnerability exposes lock tokens in error messages, enabling attackers to remove locks that other users' applications have legitimately placed. This requires an attacker to be a registered user with valid credentials, but does not require special privileges. The issue affects Nextcloud Server versions 32.0.0 through 32.0.1 and 33.0.0 through 33.0.0, with enterprise deployments on version 31 also at risk.

  • CVE-2023-5502MEDIUM 5.9

    Arista EOS devices configured with 802.1x authentication on network access ports have a weakness that allows a malicious user to bypass the authentication requirement under specific conditions. The vulnerability exists when 802.1x is enabled on access or trunk ports and routing is enabled on the access VLAN. An attacker could potentially gain network access without providing valid authentication credentials, though exploitation requires specific network configuration and circumstances to be in place.

  • CVE-2026-45690MEDIUM 5.9

    Nextcloud Server contains an authentication bypass flaw that lets attackers with a valid password defeat two-factor authentication (2FA). During login, the system temporarily grants a session token before asking for the second factor. An attacker who intercepts this token can replay it using HTTP Basic Authentication to access the account without providing the 2FA code. This affects Nextcloud Server versions 32.0.0 through 32.0.8 and 33.0.0 through 33.0.2, as well as older Enterprise Server branches. The vulnerability requires knowledge of the user's password, limiting opportunistic exploitation but creating a material risk for password-compromised accounts.

  • CVE-2026-45691MEDIUM 5.9

    Nextcloud Server contains a session management flaw that allows attackers to bypass two-factor authentication (2FA). When a user logs in with their password but hasn't completed TOTP verification yet, a temporary session cookie is created. An attacker with legitimate credentials can capture or reuse this intermediate cookie as a Bearer token to directly access file storage endpoints (DAV), gaining unauthorized read and write access while completely circumventing the mandatory 2FA requirement. This affects Nextcloud Server versions 32.0.0–32.0.8 and 33.0.0–33.0.2, as well as several Enterprise Server releases.

  • CVE-2026-55761MEDIUM 5.9

    Portainer Community Edition has a security gap that allows unauthenticated attackers to set up a malicious administrator account or restore a backup file during the initial five-minute setup window on fresh installations. An attacker with network access can exploit this window to gain full administrative control over containerized environments managed by the vulnerable Portainer instance.

  • CVE-2026-47166MEDIUM 5.7

    ImageMagick, a widely-used image editing tool, contains a memory safety flaw in its distributed caching service. An attacker with local access who can connect to the magick -distribute-cache service can trigger the server to read beyond allocated heap memory, potentially exposing sensitive data or causing a denial of service. The vulnerability affects versions before 6.9.13-48 (legacy branch) and 7.1.2-23 (current branch).

  • CVE-2026-13543MEDIUM 5.6

    Documenso versions up to 2.11.0 contain an authentication flaw in their Google OAuth login implementation that could allow an attacker to bypass or manipulate the authentication process. The vulnerability exists in the OAuth callback URL handling logic and requires specific technical conditions to exploit, making it moderately difficult to execute. While a public exploit exists, successful attacks would still demand significant effort and precision from an attacker.

  • CVE-2026-14627MEDIUM 5.6

    NousResearch's hermes-agent, a tool used for building agent applications, contains an authentication bypass vulnerability in its Discord platform integration. The flaw exists in code responsible for verifying whether a Discord user is allowed to interact with the agent. An attacker can exploit this remotely by manipulating the authentication check, gaining unauthorized access to agent functionality. While the technical difficulty is high and exploitation requires specific knowledge, the vendor has not provided patches or meaningful engagement on the issue since disclosure.

  • CVE-2026-48991MEDIUM 5.5

    XianYuLauncher, a popular Minecraft Java Edition launcher, has a flaw in versions before 1.5.5 that allows a local attacker to steal authentication credentials during the login process. The vulnerability exists because the launcher uses a simple, predictable method to handle login on your computer without adequate security checks. If someone else can access your device or monitor your network traffic locally, they could intercept the authentication tokens needed to access your Minecraft account. The risk is highest in shared or untrusted computing environments. Updating to version 1.5.5 or later closes this gap.

  • CVE-2026-40995MEDIUM 5.4

    Spring Web Services has a vulnerability in its X509 certificate authentication handler that bypasses Spring Security's standard account status checks. When a user presents a valid certificate that maps to a known user account, the system authenticates them without verifying whether that account is disabled, locked, expired, or has expired credentials. This means someone with a legitimate certificate could gain access even if their account should be inactive.

  • CVE-2026-10548MEDIUM 5.3

    NousResearch's hermes-agent contains a flaw in how it synchronizes Anthropic API credentials from local credential files. An attacker with local access can exploit this to bypass authentication controls, potentially gaining unauthorized access to Anthropic services or resources protected by those credentials. The vulnerability affects versions up to 2026.4.23, and exploit code has already been made public, increasing the practical risk.

  • CVE-2026-45289MEDIUM 5.3

    CloudburstMC Protocol, a library used in Minecraft Bedrock Edition servers, contained incomplete validation logic for a specific type of authentication token. This gap allowed attackers to potentially forge or manipulate authentication credentials without proper verification, compromising the integrity of server access control. The vulnerability affects publicly exposed servers running vulnerable versions of the library prior to the patched release.

  • CVE-2026-46705MEDIUM 5.3

    Russh, a popular Rust-based SSH library used by developers to build SSH servers, has a flaw in how it manages authentication state. When a client sends multiple authentication requests (which is allowed by the SSH protocol), the library fails to properly reset internal tracking information when the username or service name changes. This means authentication decisions—like which login methods remain available or whether partial success has been achieved—can leak from one user's authentication attempt to another's. An attacker could exploit this to bypass intended authentication restrictions or gain unauthorized access to accounts.

  • CVE-2026-49843MEDIUM 5.3

    FreeSWITCH versions before 1.11.1 contain a session hijacking vulnerability in the mod_verto JSON-RPC handler. An unauthenticated attacker with knowledge of a legitimate user's session ID can forcibly disconnect that user by claiming the same session identifier, causing the legitimate connection to be dropped and any active calls to be terminated. The vulnerability stems from the application binding incoming connections to user-supplied session IDs before verifying authentication credentials.

  • CVE-2026-56080MEDIUM 4.9

    Capgo versions before 12.128.2 have a bug in their password policy enforcement system. When a Super Admin enables the Enforce Password Policy feature and changes their password to meet the requirements, the system incorrectly continues to treat the account as non-compliant. This causes the backend to repeatedly force password reset prompts, effectively locking the Super Admin out of their organization—even though their credentials are valid. The result is a denial of service affecting administrative access.

  • CVE-2026-50623MEDIUM 4.8

    Apache CXF contains an authentication bypass flaw in its OAuth2 token introspection endpoint. A missing security check allows unauthenticated attackers to access the /services/oauth2/introspect endpoint if authentication has not been explicitly enabled on that service. While the vulnerability requires a pre-existing misconfiguration, it could expose token metadata or enable further attacks against OAuth2 flows. Patched versions 4.2.2 and 4.1.7 address the underlying code defect.