CWE-287
CVEs classified under CWE-287, newest first.
462 CVEsRSS
CVE-2026-56169High· 8.1Windows Admin Center Elevation of Privilege Vulnerability
Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges over a network.
CVE-2026-50365High· 8.0Remote Access Management service/API (RPC server) Elevation of Privilege Vulnerability
Improper authentication in Windows RPC API allows an unauthorized attacker to elevate privileges over an adjacent network.
CVE-2026-47677CriticalFacturaScripts: Account takeover of any 2FA-enabled user
FacturaScripts: Account takeover of any 2FA-enabled user
CVE-2026-59955High· 7.5Apollo ConfigService access key authentication bypass via raw config file appId parsing
Apollo ConfigService access key authentication bypass via raw config file appId parsing
CVE-2026-59954High· 7.5Apollo ConfigService access key authentication bypass via appId parsing and non-canonical matching
Apollo ConfigService access key authentication bypass via appId parsing and non-canonical matching
CVE-2026-15542High· 7.3A vulnerability has been found in will-moss Isaiah up to 1.36.9
A vulnerability has been found in will-moss Isaiah up to 1.36.9. This affects an unknown function of the file app/main.go of the component Websocket Connection Authentication. The manipulation leads to improper authentication. The attack…
CVE-2026-15491High· 7.3A weakness has been identified in RafyMrX TOKO-ONLINE-ROTI up to ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99
A weakness has been identified in RafyMrX TOKO-ONLINE-ROTI up to ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99. This affects an unknown part. This manipulation causes missing authentication. The attack is possible to be carried out remotely. …
CVE-2026-56666Medium· 4.8ZITADEL is an open source identity management platform
ZITADEL is an open source identity management platform. Prior to 4.15.3, ZITADEL's external identity provider handler checks that the local user's email is verified but does not verify that the external IdP confirmed ownership of the sam…
CVE-2026-57216Medium· 6.8RabbitMQ is a messaging and streaming broker
RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, AMQP 0-9-1, AMQP 1.0, and Stream Protocol authentication can allow a loopback-restricted user such as guest to connect remotely when traffic is ac…
CVE-2026-12761Critical· 9.8The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin for WordPress is vulnerable to authentication bypass leading to account takeover in versions up to and including 7.7.0
The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin for WordPress is vulnerable to authentication bypass leading to account takeover in versions up to and including 7.7.0. This is due to the Profile Compl…
CVE-2026-55377High· 8.1Logto is the modern, open-source auth infrastructure for SaaS and AI apps
Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 1.41.0, Logto's Account Center step-up check accepted any active verification record that belonged to the current user and had isVerified === true. A Web…
GHSA-g936-7jqj-mwv8Critical· 9.0TSDProxy: Internal proxy auth token forwarded to backend services enables management API escalation
TSDProxy: Internal proxy auth token forwarded to backend services enables management API escalation
CVE-2026-54089Critical· 9.1File Browser: Authentication Bypass via Proxy Auth Header Forgery
File Browser: Authentication Bypass via Proxy Auth Header Forgery
CVE-2026-15192Medium· 6.5A vulnerability has been found in mettle sendportal up to 3.0.1
A vulnerability has been found in mettle sendportal up to 3.0.1. This issue affects the function sendgrid/postmark/postal/mailjet of the component APIv1 Webhooks. The manipulation leads to missing authentication. The attack is possible t…
CVE-2026-58253High· 8.8NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system
NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.0, 2.12.7, and 2.11.16, when no_auth_user was configured, a parser fast path intended for ordinary client connections could a…
CVE-2026-59822High· 8.2CISA KEVPoCLiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, LiteLLM's MCP Streamable HTTP endpoint allowed an unauthenticated attacker to use a fabricated Authorization header to trigger an OAut…
GHSA-f66q-9rf6-8795MediumFlask-Security-Too: WebAuthn reauthentication freshness bypass via cross-user assertion
Flask-Security-Too: WebAuthn reauthentication freshness bypass via cross-user assertion
CVE-2026-53514High· 7.7Better Auth vulnerable to unauthorized invitation acceptance via unverified email match in organization plugin
Better Auth vulnerable to unauthorized invitation acceptance via unverified email match in organization plugin
CVE-2026-53516High· 8.3Better Auth has an account takeover issue via OAuth auto-link to unverified pre-registered email
Better Auth has an account takeover issue via OAuth auto-link to unverified pre-registered email
CVE-2026-53512Critical· 9.1Better Auth: OAuth refresh-token replay via missing client authentication on oidc-provider and mcp plugins
Better Auth: OAuth refresh-token replay via missing client authentication on oidc-provider and mcp plugins
CVE-2026-55076High· 7.4Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking
Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking
CVE-2026-55075High· 7.4Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass
Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass
CVE-2026-14627Medium· 5.6A security vulnerability has been detected in NousResearch hermes-agent up to 0.15.2
A security vulnerability has been detected in NousResearch hermes-agent up to 0.15.2. This affects the function DiscordAdapter._is_allowed_user of the file gateway/platforms/discord.py of the component Discord Platform Integration. Such …
CVE-2026-12196NoneHestiaCP panel cronjob feature is affected by a broken access control vulnerability
HestiaCP panel cronjob feature is affected by a broken access control vulnerability. Low privilege users can modify the panel cronjob to execute scripts HestiaCP management scripts with passwordless sudo. This could result in the takeove…
CVE-2026-14622High· 7.3A vulnerability was found in jairiidriss restaurant-website-php-mysql up to 521428b5b612449df0cf4a5d15ee40cba67f3d35
A vulnerability was found in jairiidriss restaurant-website-php-mysql up to 521428b5b612449df0cf4a5d15ee40cba67f3d35. This vulnerability affects unknown code of the file /admin/ajax_files of the component AJAX Endpoint. Performing a mani…
CVE-2026-52830Critical· 9.4fast-mcp-telegram: Bearer token path traversal bypasses reserved Telegram session protection
fast-mcp-telegram: Bearer token path traversal bypasses reserved Telegram session protection
CVE-2026-49852Highjoserfc: HS256/HS384/HS512 verify accepts empty/nil HMAC key (cross-language sibling of CVE-2026-45363)
joserfc: HS256/HS384/HS512 verify accepts empty/nil HMAC key (cross-language sibling of CVE-2026-45363)
GHSA-rggc-m335-3wvjHighOpenClaw: Same-host trusted-proxy deployments could accept local forged identity headers
OpenClaw: Same-host trusted-proxy deployments could accept local forged identity headers
CVE-2026-53817High· 8.0OpenClaw: Control UI locality spoofing could mint a durable admin device token
OpenClaw: Control UI locality spoofing could mint a durable admin device token
CVE-2026-55955Medium· 6.5⚖ disputedImproper Authentication vulnerability in Apache Tomcat allowed a replay attack against the EncryptionInterceptor in the cluster component. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55,…
Improper Authentication vulnerability in Apache Tomcat allowed a replay attack against the EncryptionInterceptor in the cluster component. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55,…