VulnSea

CWE-287

CVEs classified under CWE-287, newest first.

462 CVEsRSS

CVE-2026-13543Medium· 5.6
3mo ago

A vulnerability was detected in Documenso up to 2.11.0

A vulnerability was detected in Documenso up to 2.11.0. Affected by this vulnerability is an unknown functionality of the file packages/auth/server/lib/utils/handle-oauth-callback-url.ts of the component Google OAuth Login. The manipulat…

▾ SunlitEPSS 0.59%via NVD
CVE-2026-49869Critical· 10.0CISA KEVPoC
3mo ago

Kestra is an open-source, event-driven orchestration platform

Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, AuthenticationFilter in Kestra OSS uses request.getPath().endsWith("/configs") to whitelist the public configuration endpoint from Basic Auth. Bec…

▾ Hadalkestra · kestraEPSS 2.1%via NVD
CVE-2026-49454Critical· 9.1
3mo ago

Relyra SAML SignatureValue not cryptographically verified -> authentication bypass

Relyra SAML SignatureValue not cryptographically verified -> authentication bypass

▾ Midnightrelyra · relyraEPSS 0.23%via GHSA
CVE-2026-56223High· 8.7PoC
3mo ago

Capgo before 12.128.2 contains a cross-domain SSO account takeover vulnerability in the provision-user endpoint that allows attackers to merge arbitrary victim accounts based on email match without validating SSO provider domain authoriz…

Capgo before 12.128.2 contains a cross-domain SSO account takeover vulnerability in the provision-user endpoint that allows attackers to merge arbitrary victim accounts based on email match without validating SSO provider domain authoriz…

▾ MidnightCapgo · CapgoEPSS 0.40%via NVD
CVE-2026-13208Medium· 6.5
3mo ago

A flaw was found in KubeVirt's virt-handler domain notify server

A flaw was found in KubeVirt's virt-handler domain notify server. The gRPC handlers for HandleDomainEvent and HandleK8SEvent derive the VMI identity (namespace/name) solely from the request body without validating it against the connecti…

▾ Sunlitkubevirt · kubevirtEPSS 0.13%via NVD
CVE-2026-12112High· 7.8
3mo ago

A flaw was found in the foreman-mcp-server

A flaw was found in the foreman-mcp-server. A session management vulnerability in the MCP Server allows unauthenticated attackers to hijack active administrative sessions due to an improper cache of authenticated client connections, by t…

▾ Twilightredhat · satelliteEPSS 0.22%via NVD
CVE-2026-44584Medium· 4.3
3mo ago

Paymenter doesn't reset email verification status after email change

Paymenter doesn't reset email verification status after email change

▾ Sunlitpaymenter · paymenter/paymenterEPSS 0.16%via GHSA
CVE-2026-12795High· 7.3
3mo ago

LiteLLM: SSO Debug Flow Has Improper Authentication

LiteLLM: SSO Debug Flow Has Improper Authentication

▾ Twilightlitellm · litellmEPSS 0.80%via OSV
CVE-2026-12773High· 7.3
3mo ago

LiteLLM: MCP Proxy Has Improper Authentication

LiteLLM: MCP Proxy Has Improper Authentication

▾ Twilightlitellm · litellmEPSS 1.0%via OSV
CVE-2026-45480Critical· 10.0
3mo ago

Azure Active Directory Elevation of Privilege Vulnerability

Improper authentication in Azure Active Directory allows an unauthorized attacker to elevate privileges over a network.

▾ MidnightMicrosoft · Azure Active DirectoryEPSS 0.90%via CVEORG
CVE-2026-50559High· 7.5
3mo ago

Quarkus is a Java framework for building cloud-native applications

Quarkus is a Java framework for building cloud-native applications. Prior to versions 3.37.0, 3.36.3, 3.33.2.1, 3.33.3, 3.27.4.1, 3.27.5, and 3.20.6.2, Quarkus HTTP path-based authorization policies can be bypassed using encoded semicolo…

▾ Twilightquarkus · quarkusEPSS 0.67%via NVD
CVE-2026-55689Medium· 6.8
3mo ago

OpenFGA: OIDC audience validation skipped when --authn-oidc-audience is unset

OpenFGA: OIDC audience validation skipped when --authn-oidc-audience is unset

▾ Sunlitopenfga · github.com/openfga/openfgaEPSS 0.41%via GHSA
CVE-2026-54781High· 7.4
3mo ago

CoreWCF: SAML SubjectConfirmation methods and holder-of-key proof keys are not enforced

CoreWCF: SAML SubjectConfirmation methods and holder-of-key proof keys are not enforced

▾ TwilightCoreWCF · CoreWCF.PrimitivesEPSS 0.25%via GHSA
CVE-2026-32174High· 7.7
3mo ago

Azure Bot Service Elevation of Privilege Vulnerability

Improper authentication in Azure Bot Service allows an authorized attacker to elevate privileges over a network.

▾ TwilightMicrosoft · Azure AI Bot ServiceEPSS 0.77%via CVEORG
CVE-2026-55672High· 7.4
3mo ago

ZITADEL: Missing client_id binding in OIDC authorization code exchange and refresh token flows (RFC 6749 Section 4.1.3 violation)

ZITADEL: Missing client_id binding in OIDC authorization code exchange and refresh token flows (RFC 6749 Section 4.1.3 violation)

▾ Twilightzitadel · github.com/zitadel/zitadelEPSS 0.43%via GHSA
GHSA-5qw8-f2g9-ff29High· 8.2
3mo ago

PraisonAI recipe serve Typer command bypasses the non-localhost authentication guard

PraisonAI recipe serve Typer command bypasses the non-localhost authentication guard

▾ Twilightpraisonai · praisonaivia GHSA
GHSA-fc26-m9pf-v56qHigh· 8.6
3mo ago

PraisonAI LinearBot processes unsigned webhooks when LINEAR_WEBHOOK_SECRET is missing

PraisonAI LinearBot processes unsigned webhooks when LINEAR_WEBHOOK_SECRET is missing

▾ Twilightpraisonai · praisonaivia GHSA
CVE-2026-11717Critical
3mo ago

googleapis/mcp-toolbox: authentication bypass vulnerability in the generic opaque token validation path (validateOpaqueToken)

googleapis/mcp-toolbox: authentication bypass vulnerability in the generic opaque token validation path (validateOpaqueToken)

▾ Midnightgoogleapis · github.com/googleapis/mcp-toolboxEPSS 0.18%via GHSA
CVE-2026-11718Critical
3mo ago

googleapis/mcp-toolbox: authentication bypass vulnerability in the generic opaque token validation path (validateOpaqueToken)

googleapis/mcp-toolbox: authentication bypass vulnerability in the generic opaque token validation path (validateOpaqueToken)

▾ Midnightgoogleapis · github.com/googleapis/mcp-toolboxEPSS 0.18%via GHSA
GHSA-4qq2-2j2x-x62cHigh· 8.2
3mo ago

npm PraisonAI MCPSecurity Basic/OAuth authentication policies accept invalid credentials without validation

npm PraisonAI MCPSecurity Basic/OAuth authentication policies accept invalid credentials without validation

▾ Twilightpraisonai · praisonaivia GHSA
GHSA-f38v-77qj-h4jqCritical· 9.8
3mo ago

praisonai-platform 0.1.4 still boots on the hardcoded JWT secret dev-secret-change-me (default-open production guard)

praisonai-platform 0.1.4 still boots on the hardcoded JWT secret dev-secret-change-me (default-open production guard)

▾ Midnightpraisonai-platform · praisonai-platformvia GHSA
GHSA-8ccj-p46r-jwqqHigh· 8.2
3mo ago

PraisonAI: PRAISONAI_CALL_AUTH=disabled environment variable unconditionally disables authentication

PraisonAI: PRAISONAI_CALL_AUTH=disabled environment variable unconditionally disables authentication

▾ Twilightpraisonai · praisonaivia GHSA
CVE-2026-46859Critical· 9.8
3mo ago

Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security)

Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP …

▾ Midnightoracle · agile_product_lifecycle_managementEPSS 0.51%via NVD
CVE-2026-52845High· 8.1
3mo ago

Caddy: FastCGI header normalization bypass in `forward_auth copy_headers`

Caddy: FastCGI header normalization bypass in `forward_auth copy_headers`

▾ Twilightcaddyserver · github.com/caddyserver/caddy/v2EPSS 0.45%via GHSA
CVE-2026-12183Critical· 9.8
3mo ago

Nefteprodukttekhnika BUK TS-G Gas Station Automation System 2.9.1 through 2.10.2 on Linux contains an Improper Authentication vulnerability (CWE-287) in the system configuration module.

Nefteprodukttekhnika BUK TS-G Gas Station Automation System 2.9.1 through 2.10.2 on Linux contains an Improper Authentication vulnerability (CWE-287) in the system configuration module.

▾ MidnightEPSS 0.44%via NVD
CVE-2026-50623Medium· 4.8
3mo ago

An authentication bypass vulnerability exists in the OAuth2 TokenIntrospectionService in Apache CXF. Due to a missing 'throw' keyword in the security context check, the introspection endpoint (/services/oauth2/introspect) can be accessed…

An authentication bypass vulnerability exists in the OAuth2 TokenIntrospectionService in Apache CXF. Due to a missing 'throw' keyword in the security context check, the introspection endpoint (/services/oauth2/introspect) can be accessed…

▾ Sunlitapache · cxfEPSS 0.54%via NVD
CVE-2026-40995Medium· 5.4
3mo ago

X509AuthenticationProvider could issue a fully authenticated X509AuthenticationToken when a presented certificate mapped to UserDetails, without applying Spring Security's standard account lifecycle checks (disabled, locked, expired, or …

X509AuthenticationProvider could issue a fully authenticated X509AuthenticationToken when a presented certificate mapped to UserDetails, without applying Spring Security's standard account lifecycle checks (disabled, locked, expired, or …

▾ Sunlitbroadcom · spring_web_servicesEPSS 0.18%via NVD
CVE-2026-47838Medium· 6.8
3mo ago

Spring Security Vulnerable to Unauthorized User Impersonation when Using X.509 Client Certificates

Spring Security Vulnerable to Unauthorized User Impersonation when Using X.509 Client Certificates

▾ Sunlitspringframework · org.springframework.security:spring-security-webEPSS 0.19%via GHSA
CVE-2026-44810High· 8.4
3mo ago

Microsoft Cryptographic Services Elevation of Privilege Vulnerability

Improper authentication in Windows Cryptographic Services allows an unauthorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 11 version 23H2EPSS 0.30%via CVEORG
CVE-2026-45691Medium· 5.9
3mo ago

Nextcloud is an open source content collaboration platform

Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.9, and 33.0.0 to before 33.0.3, a pre-2FA session cookie (created after successful password authentication but before TOT…

▾ Sunlitnextcloud · nextcloud_serverEPSS 0.43%via NVD
CWE-287 vulnerabilities (CVEs) — page 13 · VulnSea