VulnSea

CWE-288

CVEs classified under CWE-288, newest first.

63 CVEsRSS

CVE-2026-93928High· 7.3
today

Authentication Bypass Using an Alternate Path or Channel vulnerability in Magepeople inc

Authentication Bypass Using an Alternate Path or Channel vulnerability in Magepeople inc. Taxi Booking Manager for WooCommerce allows Authentication Bypass. This issue affects Taxi Booking Manager for WooCommerce: from n/a before 2.0.8.

TwilightMagepeople inc. · ecab-taxi-booking-managervia NVD
CVE-2026-58269High· 8.1
yesterday

Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing

Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing. Prior to version 2.4.0, `POST /api/auth/token` authenticates with username and password only, then calls `getTokens()`, which returns full a…

TwilightSync-in · servervia NVD
CVE-2026-81868Medium· 6.5
5d ago

Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications

Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. Prior to 4.3.0, Steeltoe.Security.Authorization.Certificate deployments using AddOrgAndSpacePolicies() and UseCe…

SunlitSteeltoeOSS · security-advisoriesEPSS 0.16%via NVD
CVE-2026-62101Critical· 9.8
5d ago

Unauthenticated Broken Authentication in EduAdmin Booking <= 5.4.2 versions.

Unauthenticated Broken Authentication in EduAdmin Booking <= 5.4.2 versions.

MidnightChris Åkerfeldt Wendel · eduadmin-bookingEPSS 0.40%via NVD
CVE-2026-14917High· 7.7
6d ago

A SAML authentication bypass vulnerability affects the Kong SAML plugin when the validate_assertion_signature option is explicitly set to false

A SAML authentication bypass vulnerability affects the Kong SAML plugin when the validate_assertion_signature option is explicitly set to false. This option is enabled by default. When disabled, the plugin may extract the SAML identity f…

TwilightKong · Kong Enterprise GatewayEPSS 0.69%via NVD
CVE-2026-27546Critical· 9.8
6d ago

An unauthenticated remote attacker can exploit an authentication bypass in the _account_log function to log in as an admin, even when accounts are properly configured.

An unauthenticated remote attacker can exploit an authentication bypass in the _account_log function to log in as an admin, even when accounts are properly configured.

MidnightPepperl+Fuchs · ICE2-8IOL1-G65L-V1DEPSS 0.95%via NVD
CVE-2026-57134High· 8.2PoC
1w ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. From 1.5.1 until 1.7.2, MCPSecurity.evaluatePolicy() in src/praisonai-ts/src/mcp/security.ts invokes the configured credential validator only when AuthMethod is api-key or bearer. Basic and OAuth …

MidnightMervinPraison · PraisonAIEPSS 0.30%via NVD
CVE-2026-91143High· 7.2PoC
1w ago

goproxy through 15.3 fails to apply HTTP proxy basic authentication to CONNECT tunnel requests, allowing unauthenticated clients to bypass credential requirements

goproxy through 15.3 fails to apply HTTP proxy basic authentication to CONNECT tunnel requests, allowing unauthenticated clients to bypass credential requirements. Attackers can issue CONNECT requests to establish tunnels through the aut…

Midnightsnail007 · goproxyEPSS 0.27%via NVD
CVE-2026-88260High· 8.7
1w ago

Authentication bypass using an alternate path or channel and Improper validation of syntactic correctness of input vulnerability in Brainzcompany Zenius EMS 8.0 allows Remote Code Inclusion. This issue affects Zenius EMS 8.0: through OA…

Authentication bypass using an alternate path or channel and Improper validation of syntactic correctness of input vulnerability in Brainzcompany Zenius EMS 8.0 allows Remote Code Inclusion. This issue affects Zenius EMS 8.0: through OA…

TwilightBrainzcompany · Zenius EMS 8.0EPSS 0.20%via NVD
CVE-2026-81906Medium· 6.3
1w ago

Concrete CMS OAuth callback login path prior to version 9.5.3 did not check whether an account was active or email-validated before establishing a session

Concrete CMS OAuth callback login path prior to version 9.5.3 did not check whether an account was active or email-validated before establishing a session. A deactivated or unvalidated user with an existing OAuth binding could complete a…

SunlitConcrete CMS · Concrete CMSEPSS 0.39%via NVD
CVE-2026-81796High· 7.3
1w ago

Authentication Bypass Using an Alternate Path or Channel vulnerability in WEN Solutions WP Travel wp-travel allows Password Recovery Exploitation.This issue affects WP Travel: from n/a through 12.0.3.

Authentication Bypass Using an Alternate Path or Channel vulnerability in WEN Solutions WP Travel wp-travel allows Password Recovery Exploitation.This issue affects WP Travel: from n/a through 12.0.3.

TwilightWEN Solutions · wp-travelEPSS 0.22%via NVD
CVE-2026-81787Medium· 6.5
1w ago

WordPress IMPress for IDX Broker plugin <= 3.3.0 - Broken Authentication vulnerability

Unauthenticated Broken Authentication in IMPress for IDX Broker <= 3.3.0 versions.

SunlitIDX Broker · idx-broker-platinumEPSS 0.25%via CVEORG
CVE-2026-81783High· 7.1
1w ago

Subscriber Broken Authentication in MailMunch – Grow your Email List <= 3.2.5 versions.

Subscriber Broken Authentication in MailMunch – Grow your Email List <= 3.2.5 versions.

Twilightmailmunch · mailmunchEPSS 0.23%via NVD
CVE-2026-88861High· 8.3PoC
1w ago

Capgo (Cap-go/capgo.app) contains an authentication bypass affecting all versions (no patched version available at time of publication)

Capgo (Cap-go/capgo.app) contains an authentication bypass affecting all versions (no patched version available at time of publication). The Edge authorization path allows a password-only Supabase aal1 session to exercise privileged RBAC…

MidnightCap-go · capgo.appEPSS 0.29%via NVD
CVE-2026-86084Medium· 5.5
2w ago

n8n is an open source workflow automation platform

n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the public OIDC login and callback endpoints completed authentication even when OIDC was not the enabled active authentication method. An Enterpri…

Sunlitn8n · n8nEPSS 0.26%via NVD
CVE-2026-49887High· 7.8
2w ago

In maybeRemoveInvalidInstallerPackageName of InstallRepository.kt, there is a possible unauthorized app update due to a permissions bypass

In maybeRemoveInvalidInstallerPackageName of InstallRepository.kt, there is a possible unauthorized app update due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. …

TwilightGoogle · AndroidEPSS 0.08%via NVD
CVE-2026-83527High· 8.1
2w ago

An Authentication Bypass vulnerability in Sentry before R10.8.2, R10.7.3 and R10.6.4 allows a remote unauthenticated attacker to gain administrative level access.

An Authentication Bypass vulnerability in Sentry before R10.8.2, R10.7.3 and R10.6.4 allows a remote unauthenticated attacker to gain administrative level access.

TwilightIvanti · SentryEPSS 1.5%via NVD
CVE-2026-77103High· 7.5
2w ago

CommServe contained an authentication bypass issue affecting access authorization and information disclosure

CommServe contained an authentication bypass issue affecting access authorization and information disclosure. Software customers upgrade to resolved maintenance release. Update CommServe.

Twilightcommvault · commvaultEPSS 0.29%via NVD
CVE-2026-62650High· 8.8
2w ago

A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70)

A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). Server-side authorization checks in the web-based management interface are not properly enforced, allowing role-based access control (RBAC) restrictions to be b…

TwilightSiemens · Reyrolle 7SR5EPSS 0.32%via NVD
CVE-2026-76169High· 7.5
2w ago

fastify versions >= 4.0.0 and before 5.12.2 can route a malformed URL sent under one plugin prefix to the custom not-found handler of a different sibling plugin, and invoke it without the preHandler hook declared for that handler

fastify versions >= 4.0.0 and before 5.12.2 can route a malformed URL sent under one plugin prefix to the custom not-found handler of a different sibling plugin, and invoke it without the preHandler hook declared for that handler. The in…

Twilightfastify · fastifyEPSS 0.51%via NVD
CVE-2026-62916Critical· 9.1
2w ago

Authentication bypass using an alternate path or channel in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network.

Authentication bypass using an alternate path or channel in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network.

Midnightmicrosoft · entra_idEPSS 0.60%via NVD
CVE-2026-68584High· 8.6
2w ago

SiYuan: Anonymous publish-password authentication bypass via getHeadingChildrenDOM / getHeading*Transaction / getBacklinkDoc (publish mode)

SiYuan: Anonymous publish-password authentication bypass via getHeadingChildrenDOM / getHeading*Transaction / getBacklinkDoc (publish mode)

Twilightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.31%via OSV
GHSA-7j72-f6wg-cxw6High· 8.6
2w ago

SiYuan: Anonymous publish-password authentication bypass via getHeadingChildrenDOM / getHeading*Transaction / getBacklinkDoc (publish mode)

SiYuan: Anonymous publish-password authentication bypass via getHeadingChildrenDOM / getHeading*Transaction / getBacklinkDoc (publish mode)

Twilightsiyuan-note · github.com/siyuan-note/siyuan/kernelvia GHSA
CVE-2026-81168Low· 3.7
2w ago

Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal CAPTCHA Protected Page allows Functionality Bypass

Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal CAPTCHA Protected Page allows Functionality Bypass. This issue affects CAPTCHA Protected Page versions: from 0.0.0 to 1.0.2.

Sunlitcaptcha_protected_page_project · captcha_protected_pageEPSS 0.32%via NVD
CVE-2026-16647Medium· 4.1
2w ago

Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Disable Login Page allows Functionality Bypass

Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Disable Login Page allows Functionality Bypass. This issue affects Disable Login Page versions: from 0.0.0 to 1.1.4.

Sunlitzyxware · disable_login_pageEPSS 0.27%via NVD
CVE-2026-65641None
3w ago

A vulnerability allowing an unauthenticated network attacker to coerce SMB authentication from the service account.

A vulnerability allowing an unauthenticated network attacker to coerce SMB authentication from the service account.

SunlitEPSS 0.54%via NVD
CVE-2026-19490Critical· 9.8CISA KEVPoC
1mo ago

Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.

Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.

Hadalcitrix · netscaler_application_delivery_controllerEPSS 5.6%via NVD
CVE-2026-75627Critical· 9.8PoC
1mo ago

Bastillion fails to properly validate request URI paths in its controller dispatcher, allowing unauthenticated attackers to bypass authentication filters by prefixing requests with arbitrary path segments

Bastillion fails to properly validate request URI paths in its controller dispatcher, allowing unauthenticated attackers to bypass authentication filters by prefixing requests with arbitrary path segments. Attackers can access administra…

Abyssalbastillion-io · BastillionEPSS 0.58%via NVD
CVE-2026-50191High· 8.8
1mo ago

4gaBoards is a boards system for realtime project management

4gaBoards is a boards system for realtime project management. Prior to 3.3.8, 4gaBoards is vulnerable to pre-account takeover when registrationEnabled, localRegistrationEnabled, and ssoRegistrationEnabled are enabled and Google, GitHub, …

TwilightEPSS 0.33%via NVD
CVE-2021-43718Medium· 5.3
1mo ago

An Authentication Bypass vulnerability exists in EPSON EH-TW5350 EPSON 150075647YWWV110, which could let a remote malicious user cause a Denial of Service via specially crafted series of HTTP..

An Authentication Bypass vulnerability exists in EPSON EH-TW5350 EPSON 150075647YWWV110, which could let a remote malicious user cause a Denial of Service via specially crafted series of HTTP..

SunlitEPSS 0.37%via NVD
CWE-288 vulnerabilities (CVEs) · VulnSea