VulnSea

CWE-287

CVEs classified under CWE-287, newest first.

461 CVEsRSS

CVE-2026-56793High· 7.7
1mo ago

Dell OpenManage Server Administrator, versions prior to 11.1.0.2, contains an Improper Authentication vulnerability

Dell OpenManage Server Administrator, versions prior to 11.1.0.2, contains an Improper Authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized acc…

▾ Twilightdell · openmanage_server_administratorEPSS 0.53%via NVD
CVE-2026-56162Critical· 10.0
1mo ago

Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.

Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.

▾ Midnightmicrosoft · azure_sql_databaseEPSS 0.90%via NVD
CVE-2026-48039Critical· 9.1
1mo ago

Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads

Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads. Prior to version 1.0.109, `AuthInjectionMiddleware.dispatch()` at `http_auth_integration.py:272` unconditionally forwards unauthenticated Streama…

▾ Midnightmeta-ads-mcp · meta-ads-mcpEPSS 0.59%via NVD
CVE-2026-48087Critical· 9.8
1mo ago

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, the registration handler at `POST /api/auth/register/{userId}` validates the relationship between the Web…

▾ MidnightEPSS 0.57%via NVD
CVE-2026-62896Critical· 9.6
1mo ago

Microsoft Teams Elevation of Privilege Vulnerability

Improper authentication in Microsoft Teams allows an authorized attacker to elevate privileges over a network.

▾ MidnightMicrosoft · Microsoft TeamsEPSS 0.69%via CVEORG
CVE-2026-65400Critical· 9.8CISA KEVPoC
1mo ago

An authentication issue was addressed with improved state management

An authentication issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26.6.1, macOS Tahoe 26.7. An attacker on the network may be able to…

▾ Hadalapple · macosEPSS 1.2%via NVD
CVE-2026-64665High· 8.1
1mo ago

Statamic is a Laravel and Git powered content management system (CMS)

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, when OAuth login was enabled with a provider that does not guarantee verified email addresses, an unauthenticated attacker could sign in a…

▾ Twilightstatamic · statamic/cmsEPSS 0.54%via NVD
CVE-2026-71326Low· 3.8
1mo ago

Traefik is an open source HTTP reverse proxy and load balancer

Traefik is an open source HTTP reverse proxy and load balancer. From 3.6.11 until 3.6.25 and 3.7.10, Traefik's BasicAuth middleware in pkg/middlewares/auth/basic_auth.go deduplicates concurrent password checks with a singleflight key bui…

▾ Sunlittraefik · traefikEPSS 0.34%via NVD
CVE-2026-45414High· 8.5
1mo ago

Decidim is a participatory democracy framework

Decidim is a participatory democracy framework. Prior to 0.31.5 and in 0.32.0.rc1 before 0.32.0.rc2, JWT-backed API authentication is not bound to the organization selected by the current host, allowing a JWT issued for one tenant to be …

▾ Twilightdecidim · decidimEPSS 0.45%via NVD
CVE-2026-9192Critical· 9.8
1mo ago

An authentication bypass vulnerability in the ODBC App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass password verification and execute queries with the privileges of any …

An authentication bypass vulnerability in the ODBC App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass password verification and execute queries with the privileges of any …

▾ MidnightEPSS 0.83%via NVD
CVE-2026-70482High· 8.1
1mo ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.0 until 0.11.0, when ENABLE_OAUTH_TOKEN_EXCHANGE=True, /oauth/{provider}/token/exchange accepts a raw provider access token and validates it b…

▾ Twilightopenwebui · open_webuiEPSS 0.57%via NVD
CVE-2026-18651Medium· 5.4
1mo ago

A flaw was found in 389 Directory Server

A flaw was found in 389 Directory Server. During SASL PLAIN authentication, the server installs connection-level bind credentials before performing the account-lock check. If the account is subsequently found to be locked, the bind is re…

▾ Sunlitredhat · directory_serverEPSS 0.28%via NVD
CVE-2026-67335Medium· 5.3
1mo ago

better-auth versions before 1.6.2 fail to validate the OAuth state parameter against the stored nonce when using cookie-backed state storage without PKCE

better-auth versions before 1.6.2 fail to validate the OAuth state parameter against the stored nonce when using cookie-backed state storage without PKCE. Attackers can forge the state parameter and supply an attacker-controlled authoriz…

▾ SunlitEPSS 0.28%via NVD
CVE-2026-67327High· 8.3
1mo ago

better-auth versions >= 1.1.3 and < 1.6.22 (and pre-release versions >= 1.7.0-beta.0 and < 1.7.0-beta.10) are vulnerable to account takeover via pre-account hijacking on magic-link and email-OTP sign-in when open email/password registrat…

better-auth versions >= 1.1.3 and < 1.6.22 (and pre-release versions >= 1.7.0-beta.0 and < 1.7.0-beta.10) are vulnerable to account takeover via pre-account hijacking on magic-link and email-OTP sign-in when open email/password registrat…

▾ TwilightEPSS 0.43%via NVD
CVE-2026-18215Medium· 6.8
1mo ago

Keycloak provides a way to let users log in using Microsoft accounts while restricting access to a specific organization (tenant)

Keycloak provides a way to let users log in using Microsoft accounts while restricting access to a specific organization (tenant). A flaw was discovered where this restriction is ignored when using the token exchange feature. This means …

▾ Sunlitredhat · build_of_keycloakEPSS 0.40%via NVD
CVE-2026-14541High· 7.5
1mo ago

An authentication bypass and audience confusion vulnerability exists in the Google OAuth provider component of Google mcp-toolbox version 1.4.0

An authentication bypass and audience confusion vulnerability exists in the Google OAuth provider component of Google mcp-toolbox version 1.4.0. When a Google authService is initialized with mcpEnabled: true but lacks an explicitly defin…

▾ Twilightgoogle · mcp_toolbox_for_databasesEPSS 0.25%via NVD
CVE-2026-49447Medium· 5.3
2mo ago

Cosmos-Server's constellation public-devices endpoint accepts arbitrary bearer tokens

Cosmos-Server's constellation public-devices endpoint accepts arbitrary bearer tokens

▾ Sunlitazukaar · github.com/azukaar/cosmos-serverEPSS 0.38%via GHSA
CVE-2026-54635High· 7.5
2mo ago

pytonapi has a Webhook Custom Path Authentication Bypass

pytonapi has a Webhook Custom Path Authentication Bypass

▾ Twilightpytonapi · pytonapiEPSS 0.71%via GHSA
GHSA-hp74-gm6m-2qm5Medium
2mo ago

Pocket ID has a reauthentication bypass via one-time access token login — passkey step-up requirement defeated by JWT freshness check that accepts any login method

Pocket ID has a reauthentication bypass via one-time access token login — passkey step-up requirement defeated by JWT freshness check that accepts any login method

▾ Sunlitpocket-id · github.com/pocket-id/pocket-id/backendvia GHSA
CVE-2026-66014High· 8.8
2mo ago

JFrog Artifactory contains an authentication handling weakness in internal request processing that, under specific conditions, may allow an attacker to escalate privileges beyond the intended access level.

JFrog Artifactory contains an authentication handling weakness in internal request processing that, under specific conditions, may allow an attacker to escalate privileges beyond the intended access level.

▾ Twilightjfrog · artifactoryEPSS 0.64%via NVD
CVE-2026-56191Critical· 10.0
2mo ago

Microsoft Exchange Online Tampering Vulnerability

Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network.

▾ MidnightMicrosoft · Microsoft Exchange OnlineEPSS 0.90%via CVEORG
CVE-2026-62825Critical· 10.0
2mo ago

Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network.

Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network.

▾ Midnightmicrosoft · azure_key_vaultEPSS 0.92%via NVD
GHSA-cmwh-g2h8-c222High· 8.1
2mo ago

Poweradmin: OIDC `sub` collation bypass in Poweradmin leading to account takeover

Poweradmin: OIDC `sub` collation bypass in Poweradmin leading to account takeover

▾ Twilightpoweradmin · poweradmin/poweradminvia GHSA
CVE-2026-59224High· 8.0
2mo ago

Open WebUI: Terminal proxy forwards a spoofable, integrity-unbound user identity to the upstream (X-User-Id header and ws_terminal session_id query injection)

Open WebUI: Terminal proxy forwards a spoofable, integrity-unbound user identity to the upstream (X-User-Id header and ws_terminal session_id query injection)

▾ Twilightopen-webui · open-webuiEPSS 0.39%via GHSA
GHSA-hp6v-6jw7-gv2fCritical
2mo ago

Budibase: OIDC SSO account takeover: incoming identity linked by email without checking email_verified

Budibase: OIDC SSO account takeover: incoming identity linked by email without checking email_verified

▾ Midnightbudibase · @budibase/servervia GHSA
GHSA-r277-6w6q-xmqwCritical· 9.1
2mo ago

kin-openapi: ValidationHandler.Load() Fail-Open Authentication Bypass via NoopAuthenticationFunc Default

kin-openapi: ValidationHandler.Load() Fail-Open Authentication Bypass via NoopAuthenticationFunc Default

▾ Midnightgetkin · github.com/getkin/kin-openapivia GHSA
GHSA-qq9h-g4jm-xgf3High· 8.3
2mo ago

Better Auth: Account takeover via pre-account hijacking on magic-link and email-OTP sign-in

Better Auth: Account takeover via pre-account hijacking on magic-link and email-OTP sign-in

▾ Twilightbetter-auth · better-authvia GHSA
CVE-2026-16232Critical· 9.1CISA KEV0dayPoC
2mo ago

An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges

An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successfu…

▾ Hadalcheckpoint · multi-domain_security_managementEPSS 78%via NVD
CVE-2026-59208High
2mo ago

n8n: Cross-Issuer Token Exchange Account Binding via Subject-Only Identity Resolution

n8n: Cross-Issuer Token Exchange Account Binding via Subject-Only Identity Resolution

▾ Twilightn8n · n8nEPSS 0.27%via GHSA
CVE-2026-60678High· 8.8
2mo ago

Vulnerability in the Oracle General Ledger product of Oracle E-Business Suite (component: Internal Operations)

Vulnerability in the Oracle General Ledger product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker wit…

▾ Twilightoracle · e-business_suiteEPSS 0.43%via NVD
CWE-287 vulnerabilities (CVEs) — page 10 · VulnSea