VulnSea

CWE-290

CVEs classified under CWE-290, newest first.

109 CVEsRSS

CVE-2026-62987Medium· 5.8
today

Fabio is an HTTP(S) and TCP router for deploying applications managed by consul

Fabio is an HTTP(S) and TCP router for deploying applications managed by consul. From 1.6.6 until 1.7.2, the CVE-2025-48865 fix in proxy/http_headers.go uses protectHeaders for a hardcoded set of forwarded headers but omits the operator-…

Sunlitfabiolb · fabiovia NVD
CVE-2026-85751Critical· 9.8
today

Mailu is a mail server distributed as a set of Docker images

Mailu is a mail server distributed as a set of Docker images. From Mailu 2.0 until 2024.06.55 and prior to Mailu helm-charts 2.7.3, deployments with PROXY_AUTH_WHITELIST configured but REAL_IP_HEADER unset trusted a client-controlled X-F…

MidnightMailu · Mailuvia NVD
CVE-2026-61682Critical· 9.9
3d ago

kcp is a Kubernetes-like control plane for form-factors and use-cases beyond Kubernetes and container workloads

kcp is a Kubernetes-like control plane for form-factors and use-cases beyond Kubernetes and container workloads. Prior to 0.31.4 and 0.32.2, the kcp front-proxy does not remove inbound X-Remote-User, X-Remote-Group, or X-Remote-Extra-* i…

Midnightkcp-dev · kcpEPSS 0.28%via NVD
CVE-2026-85511Medium· 4.2
3d ago

A flaw was found in EAP's Elytron

A flaw was found in EAP's Elytron. An EAP application whose security domain is backed by an Elytron token-realm with oauth2-introspection would allow parameter substitution due to missing URL encoding.

SunlitRed Hat · wildfly-elytron-realm-tokenEPSS 0.13%via NVD
CVE-2026-69843Critical· 10.0
3d ago

Authentication bypass by spoofing in Microsoft Fabric allows an unauthorized attacker to elevate privileges over a network.

Authentication bypass by spoofing in Microsoft Fabric allows an unauthorized attacker to elevate privileges over a network.

MidnightMicrosoft · Microsoft FabricEPSS 0.62%via NVD
CVE-2026-77903Critical· 9.0
4d ago

Authentication bypass by spoofing in Microsoft Dataverse allows an unauthorized attacker to elevate privileges over a network.

Authentication bypass by spoofing in Microsoft Dataverse allows an unauthorized attacker to elevate privileges over a network.

MidnightMicrosoft · Microsoft DataverseEPSS 0.38%via NVD
CVE-2026-76949Critical· 9.1
4d ago

Authentication Bypass by Spoofing vulnerability in team-alembic ash_authentication allows an attacker who can plant a remember-me cookie in a victim's browser to replace that victim's authenticated session with one for the attacker's own…

Authentication Bypass by Spoofing vulnerability in team-alembic ash_authentication allows an attacker who can plant a remember-me cookie in a victim's browser to replace that victim's authenticated session with one for the attacker's own…

Midnightteam-alembic · ash_authenticationEPSS 0.49%via NVD
CVE-2026-91039Critical· 9.1
4d ago

Authentication Bypass by Spoofing vulnerability in team-alembic ash_authentication allows an attacker who operates one identity-provider connection of a dynamic_oidc strategy to be signed in as a local user established through a differen…

Authentication Bypass by Spoofing vulnerability in team-alembic ash_authentication allows an attacker who operates one identity-provider connection of a dynamic_oidc strategy to be signed in as a local user established through a differen…

Midnightteam-alembic · ash_authenticationEPSS 0.40%via NVD
CVE-2026-86863Critical· 9.8
4d ago

pgAdmin 4's Webserver authentication source is intended to accept an identity asserted by the web server or reverse proxy in front of pgAdmin, delivered through the WSGI/CGI environment

pgAdmin 4's Webserver authentication source is intended to accept an identity asserted by the web server or reverse proxy in front of pgAdmin, delivered through the WSGI/CGI environment. WebserverAuthentication.get_user() read config.WEB…

Midnightpgadmin · pgadmin_4EPSS 0.36%via NVD
CVE-2026-86039High· 8.2
4d ago

libp2p is a JavaScript implementation of the libp2p networking stack

libp2p is a JavaScript implementation of the libp2p networking stack. From 8.0.0 until 12.0.24, @libp2p/peer-store in packages/peer-store/src/index.ts uses consumePeerRecord to verify a RecordEnvelope signature but does not require PeerR…

Twilightlibp2p · js-libp2pEPSS 0.18%via NVD
CVE-2026-62108Critical· 9.8
4d ago

Unauthenticated Broken Authentication in Headless Single Sign On <= 1.7.0 versions.

Unauthenticated Broken Authentication in Headless Single Sign On <= 1.7.0 versions.

MidnightminiOrange · headless-single-sign-onEPSS 0.40%via NVD
CVE-2026-76423Critical· 10.0
5d ago

A vulnerability in the REST API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to gain administrative access to an affected device. This vulnerability is due to the REST API web service being exposed wi…

A vulnerability in the REST API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to gain administrative access to an affected device. This vulnerability is due to the REST API web service being exposed wi…

MidnightCisco · Cisco Identity Services Engine SoftwareEPSS 0.55%via NVD
CVE-2026-20071Low· 3.8
5d ago

A vulnerability in the SSID bring-your-own-device (BYOD) onboarding workflow of Cisco ISE could allow an unauthenticated, adjacent attacker to hijack the onboarding session of&nbsp;another user and access protected 802.1X networks

A vulnerability in the SSID bring-your-own-device (BYOD) onboarding workflow of Cisco ISE could allow an unauthenticated, adjacent attacker to hijack the onboarding session of&nbsp;another user and access protected 802.1X networks. &nbsp…

SunlitCisco · Cisco Identity Services Engine SoftwareEPSS 0.15%via NVD
CVE-2026-77119Medium· 5.9
5d ago

A validly signed NSEC3 from an unrelated sibling zone may be accepted as an insecurity proof, downgrading a secure delegation and letting a forged unsigned answer through. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0…

A validly signed NSEC3 from an unrelated sibling zone may be accepted as an insecurity proof, downgrading a secure delegation and letting a forged unsigned answer through. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0…

SunlitISC · BIND 9EPSS 0.19%via NVD
CVE-2026-92395Critical· 9.1
5d ago

@fastify/proxy-addr is a Fastify plugin that determines a request's client address behind trusted reverse proxies, and it backs Fastify request.ip and request.ips

@fastify/proxy-addr is a Fastify plugin that determines a request's client address behind trusted reverse proxies, and it backs Fastify request.ip and request.ips. In versions 3.0.0 through 5.1.0, a trust subnet written in IPv4-mapped IP…

Midnight@fastify/proxy-addr · @fastify/proxy-addrEPSS 0.30%via NVD
CVE-2026-40854High· 8.7
5d ago

WNC T-Mobile 5G Box IDU router contains an authentication bypass vulnerability in the portal.cgi component

WNC T-Mobile 5G Box IDU router contains an authentication bypass vulnerability in the portal.cgi component. The session verification mechanism improperly validates the sessionid cookie by checking for the existence of a corresponding fil…

TwilightWNC · T-Mobile 5G Box IDUEPSS 0.30%via NVD
CVE-2026-89327Low· 3.8
5d ago

The FluentBoards WordPress plugin before 2.0.15 does not verify that a board member submitting a comment is the user the comment is attributed to, allowing any board member to post comments that appear to be authored by another user, in…

The FluentBoards WordPress plugin before 2.0.15 does not verify that a board member submitting a comment is the user the comment is attributed to, allowing any board member to post comments that appear to be authored by another user, in…

SunlitEPSS 0.21%via NVD
CVE-2026-15640Critical· 9.5
5d ago

Under certain conditions a valid SAML IdP response may be used to impersonate another Secret Server user.

Under certain conditions a valid SAML IdP response may be used to impersonate another Secret Server user.

MidnightDelinea · Secret Server (On-Prem)EPSS 0.28%via NVD
CVE-2026-89022High· 7.4
6d ago

BookStack before 26.05.5 contains an authentication bypass vulnerability in its social login implementation that allows unauthenticated attackers to sign in as arbitrary users by authenticating through a different social provider sharing…

BookStack before 26.05.5 contains an authentication bypass vulnerability in its social login implementation that allows unauthenticated attackers to sign in as arbitrary users by authenticating through a different social provider sharing…

Twilightbookstackapp · bookstackEPSS 0.29%via NVD
CVE-2026-90711Critical· 9.1
6d ago

proxy-addr is a Node.js module that determines a request's client address behind trusted reverse proxies, and it backs Express req.ip and req.ips

proxy-addr is a Node.js module that determines a request's client address behind trusted reverse proxies, and it backs Express req.ip and req.ips. In versions 1.1.0 through 2.0.7, a trust subnet written in IPv4-mapped IPv6 notation with …

Midnightproxy-addr · proxy-addrEPSS 0.19%via NVD
CVE-2026-59157Medium· 6.5
6d ago

webhookd is a minimalist webhook server that triggers shell scripts and external processes through HTTP requests

webhookd is a minimalist webhook server that triggers shell scripts and external processes through HTTP requests. Prior to 1.22.0, webhookd deployments without htpasswd authentication forwarded all incoming HTTP headers through HTTPParam…

Sunlitncarlier · webhookdEPSS 0.46%via NVD
CVE-2026-49446Medium· 6.1PoC
6d ago

Cosmos provides users the ability self-host a home server by acting as a secure gateway to your application, as well as a server manager

Cosmos provides users the ability self-host a home server by acting as a secure gateway to your application, as well as a server manager. Prior to 0.22.19, tokenMiddleware in src/proxy/routerGen.go can return through the Constellation tu…

Twilightazukaar · Cosmos-ServerEPSS 0.29%via NVD
CVE-2026-73449Medium· 5.9
1w ago

On affected platforms running Arista EOS with both 802.1X port authentication and the RADIUS proxy feature configured with dynamic authorization, a low-privileged attacker on an adjacent network segment who induces a RADIUS packet throug…

On affected platforms running Arista EOS with both 802.1X port authentication and the RADIUS proxy feature configured with dynamic authorization, a low-privileged attacker on an adjacent network segment who induces a RADIUS packet throug…

SunlitArista Networks · EOSEPSS 0.14%via NVD
CVE-2026-65399Medium· 4.4
1w ago

A file quarantine bypass was addressed with additional checks

A file quarantine bypass was addressed with additional checks. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, visionOS 27, watchOS 27. An archive may be …

Sunlitapple · ipadosEPSS 0.11%via NVD
CVE-2026-18065Medium· 5.3
1w ago

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote unauthenticated attacker to gain access to sensitive information through session IP binding bypass in Navigator for i.

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote unauthenticated attacker to gain access to sensitive information through session IP binding bypass in Navigator for i.

SunlitIBM · iEPSS 0.31%via NVD
CVE-2026-88819Medium· 6.3
1w ago

In Siglet current and past versions the refresh token handler do not enforce proof of possession of the issuer DID.

In Siglet current and past versions the refresh token handler do not enforce proof of possession of the issuer DID.

SunlitEclipse Foundation · Eclipse Data Plane CoreEPSS 0.12%via NVD
CVE-2025-68624Medium· 4.3PoC
1w ago

N-able Mail Assure through April 2026 contains a design-level authorization flaw that allows an authenticated SMTP user to send outbound email using MAIL FROM addresses belonging to other tenants

N-able Mail Assure through April 2026 contains a design-level authorization flaw that allows an authenticated SMTP user to send outbound email using MAIL FROM addresses belonging to other tenants. When connecting to the SMTP TCP port and…

TwilightN-able · Mail AssureEPSS 0.29%via NVD
CVE-2026-87785Critical· 9.1
1w ago

Authentication bypass by spoofing vulnerability in Apache Syncope. When the configured JWKS settings for internal JWT authentication are disclosed (at least protocol and key), an attacker can spoof another user's privileges after comp…

Authentication bypass by spoofing vulnerability in Apache Syncope. When the configured JWKS settings for internal JWT authentication are disclosed (at least protocol and key), an attacker can spoof another user's privileges after comp…

MidnightApache Software Foundation · org.apache.syncope.core:syncope-core-springEPSS 0.51%via NVD
CVE-2026-21391Critical· 9.5
1w ago

An improper validation vulnerability exists within PingAM where a well-crafted request allows arbitrary or protected ID Token claims to be set or overridden

An improper validation vulnerability exists within PingAM where a well-crafted request allows arbitrary or protected ID Token claims to be set or overridden. In certain configurations this could allow an attacker to bypass authentication…

MidnightPing Identity · PingAMEPSS 0.45%via NVD
CVE-2026-45056Medium· 6.9⚖ disputed
1w ago

matrix-sdk-crypto is a no-network-IO implementation of a state machine that handles end-to-end encryption for Matrix clients

matrix-sdk-crypto is a no-network-IO implementation of a state machine that handles end-to-end encryption for Matrix clients. Starting in version 0.12.0 and prior to version 0.17.0, the matrix-sdk-crypto crate was missing a check for the…

Sunlitmatrix-org · matrix-rust-sdkEPSS 0.23%via NVD
CWE-290 vulnerabilities (CVEs) · VulnSea