VulnSea

CWE-305

CVEs classified under CWE-305, newest first.

25 CVEsRSS

CVE-2026-85500Critical· 9.1
4d ago

Authentication Bypass by Primary Weakness vulnerability in team-alembic AshAuthentication allows an unconfirmed user to obtain a session, defeating a mandatory email confirmation requirement. AshAuthentication.Strategy.Password.Actions.…

Authentication Bypass by Primary Weakness vulnerability in team-alembic AshAuthentication allows an unconfirmed user to obtain a session, defeating a mandatory email confirmation requirement. AshAuthentication.Strategy.Password.Actions.…

Midnightteam-alembic · ash_authenticationEPSS 0.55%via NVD
CVE-2026-92075Low· 3.4
6d ago

Mitigation bypass in the Networking component

Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

SunlitMozilla · FirefoxEPSS 0.16%via NVD
CVE-2026-86207High· 7.7PoC
2w ago

An authentication bypass in N-central < 2026.3 HF 3 leads to authentication bypass in internal only APIs

An authentication bypass in N-central < 2026.3 HF 3 leads to authentication bypass in internal only APIs

MidnightN-able · N-centralEPSS 0.73%via NVD
CVE-2026-85596Critical· 9.8⚖ disputed
2w ago

Traefik versions >= v3.7.0 and <= v3.7.10 contain an authentication bypass in the Kubernetes Ingress NGINX provider

Traefik versions >= v3.7.0 and <= v3.7.10 contain an authentication bypass in the Kubernetes Ingress NGINX provider. The TLS option generated for an Ingress carrying the nginx.ingress.kubernetes.io/auth-tls-secret annotation was named af…

Midnighttraefik · traefikEPSS 0.24%via NVD
CVE-2026-85595Critical· 9.8
2w ago

Traefik versions before v2.11.55 and versions v3.0.0 through v3.7.10 contain an authentication bypass vulnerability in the digestAuth middleware where unknown usernames receive an empty secret instead of rejection

Traefik versions before v2.11.55 and versions v3.0.0 through v3.7.10 contain an authentication bypass vulnerability in the digestAuth middleware where unknown usernames receive an empty secret instead of rejection. Attackers can compute …

Midnighttraefik · traefikEPSS 0.45%via NVD
CVE-2026-81578Critical· 9.8CISA KEVPoC
3w ago

An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG

An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions pri…

Hadalpapercut · papercut_mfEPSS 3.3%via NVD
CVE-2026-68569High· 8.1
3w ago

Improper Authentication vulnerability in Apache Tomcat meant that in some circumstances (e.g

Improper Authentication vulnerability in Apache Tomcat meant that in some circumstances (e.g. CLIENT-CERT, SPNEGO) that a user would be authenticated even if the user did not exist in the DataSourceRealm. This issue affects Apache Tom…

Twilightapache · tomcatEPSS 0.53%via NVD
CVE-2026-65935None
1mo ago

Passkey entry Bluetooth LE legacy pairing can be bypassed in the RS9116W and SiWx917 by manipulating the temporary key value.  See vulnerability B-E3 in the related paper below.

Passkey entry Bluetooth LE legacy pairing can be bypassed in the RS9116W and SiWx917 by manipulating the temporary key value.  See vulnerability B-E3 in the related paper below.

SunlitEPSS 0.18%via NVD
CVE-2026-19292High· 8.8
1mo ago

Re-pairing with a legitimate device can use a lower security level than previous making brute-forcing the LTK easier

Re-pairing with a legitimate device can use a lower security level than previous making brute-forcing the LTK easier. See V4 in the BLERP paper linked below.

TwilightEPSS 0.23%via NVD
CVE-2026-73283Low· 2.5⚖ disputed
1mo ago

In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not.

In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not.

Sunlitopenbsd · opensshEPSS 0.09%via NVD
CVE-2026-16103Medium· 4.3
2mo ago

A flaw was found in the keycloak-services component of Keycloak

A flaw was found in the keycloak-services component of Keycloak. This issue is an incomplete fix for CVE-2026-9798, where brute-force protection checks were added to the Client-Initiated Backchannel Authentication (CIBA) initiation handl…

Sunlitredhat · build_of_keycloakEPSS 0.34%via NVD
CVE-2026-9597Medium· 5.4
2mo ago

Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4 fail to verify whether a guest account is deactivated before creating a session in the magic-link token login path, which allows a deactivated guest user to obtain a fully functional…

Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4 fail to verify whether a guest account is deactivated before creating a session in the magic-link token login path, which allows a deactivated guest user to obtain a fully functional…

SunlitEPSS 0.23%via NVD
CVE-2026-9571Medium· 5.9
2mo ago

Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to invalidate OAuth refresh tokens upon user account deactivation, which allows a deactivated user or an attacker in possession of a valid refresh token to …

Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to invalidate OAuth refresh tokens upon user account deactivation, which allows a deactivated user or an attacker in possession of a valid refresh token to …

SunlitEPSS 0.30%via NVD
CVE-2026-35159Medium· 5.3
2mo ago

Dell Client Platform BIOS contains an Authentication Bypass by Primary Weakness vulnerability

Dell Client Platform BIOS contains an Authentication Bypass by Primary Weakness vulnerability. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Information Disclosure.

SunlitDell · Inspiron 15 3520EPSS 0.21%via NVD
CVE-2026-8932High· 7.5PoC
2mo ago

libcurl would reuse a previously created connection even when some mTLS config related option had been changed that should have prohibited reuse. libcurl keeps previously used connections in a connection pool for subsequent transfers to…

libcurl would reuse a previously created connection even when some mTLS config related option had been changed that should have prohibited reuse. libcurl keeps previously used connections in a connection pool for subsequent transfers to…

Midnighthaxx · curlEPSS 0.40%via NVD
CVE-2026-8458Medium· 6.5PoC
2mo ago

libcurl might in some circumstances reuse the wrong connection when asked to do Negotiate-authenticated ones, even when they are set to use different "services". libcurl features a pool of recent connections so that subsequent requests …

libcurl might in some circumstances reuse the wrong connection when asked to do Negotiate-authenticated ones, even when they are set to use different "services". libcurl features a pool of recent connections so that subsequent requests …

Twilighthaxx · curlEPSS 0.37%via NVD
CVE-2026-41052Critical· 8.4
2mo ago

Rancher has Privilege Escalation from Project Owner to Host

Rancher has Privilege Escalation from Project Owner to Host

Midnightrancher · github.com/rancher/rancherEPSS 0.42%via GHSA
CVE-2025-4994None
3mo ago

The SafeLine SL6 and SL6+ devices integrated into elevator emergency intercom systems are vulnerable to an authentication bypass

The SafeLine SL6 and SL6+ devices integrated into elevator emergency intercom systems are vulnerable to an authentication bypass. This vulnerability allows attackers to bypass authentication requirements and access the device's configura…

SunlitEPSS 0.33%via NVD
CVE-2026-9798Medium· 4.3
3mo ago

A flaw was found in Keycloak, an open-source identity and access management solution

A flaw was found in Keycloak, an open-source identity and access management solution. When a user account is temporarily locked due to repeated failed login attempts, an attacker with valid client credentials can exploit the Client-Initi…

Sunlitredhat · build_of_keycloakEPSS 0.35%via NVD
CVE-2026-5545Medium· 6.5
4mo ago

libcurl might in some circumstances reuse the wrong connection when asked to do an authenticated HTTP(S) request after a Negotiate-authenticated one, when both use the same host. libcurl features a pool of recent connections so that sub…

libcurl might in some circumstances reuse the wrong connection when asked to do an authenticated HTTP(S) request after a Negotiate-authenticated one, when both use the same host. libcurl features a pool of recent connections so that sub…

Sunlithaxx · curlEPSS 0.41%via NVD
CVE-2026-6266High· 8.3
4mo ago

A flaw was found in the AAP gateway

A flaw was found in the AAP gateway. The user auto-link strategy, introduced in AAP 2.6, automatically links an external Identity Provider (IDP) identity to an existing AAP user account based on email matching without verifying email own…

TwilightEPSS 0.40%via NVD
CVE-2026-3784Medium· 6.5
6mo ago

curl would wrongly reuse an existing HTTP proxy connection doing CONNECT to a server, even if the new request uses different credentials for the HTTP proxy. The proper behavior is to create or use a separate connection.

curl would wrongly reuse an existing HTTP proxy connection doing CONNECT to a server, even if the new request uses different credentials for the HTTP proxy. The proper behavior is to create or use a separate connection.

Sunlithaxx · curlEPSS 0.41%via NVD
CVE-2026-1965Medium· 6.5
6mo ago

libcurl can in some circumstances reuse the wrong connection when asked to do an Negotiate-authenticated HTTP or HTTPS request. libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection t…

libcurl can in some circumstances reuse the wrong connection when asked to do an Negotiate-authenticated HTTP or HTTPS request. libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection t…

Sunlithaxx · curlEPSS 0.26%via NVD
CVE-2023-4727High· 7.5
2y ago

A flaw was found in dogtag-pki and pki-core

A flaw was found in dogtag-pki and pki-core. The token authentication scheme can be bypassed with a LDAP injection. By passing the query string parameter sessionID=*, an attacker can authenticate with an existing session saved in the LDA…

TwilightEPSS 0.66%via NVD
CVE-2023-4501Critical· 9.8
3y ago

User authentication with username and password credentials is ineffective in OpenText (Micro Focus) Visual COBOL, COBOL Server, Enterprise Developer, and Enterprise Server (including product variants such as Enterprise Test Server), vers…

User authentication with username and password credentials is ineffective in OpenText (Micro Focus) Visual COBOL, COBOL Server, Enterprise Developer, and Enterprise Server (including product variants such as Enterprise Test Server), vers…

Midnightmicrofocus · cobol_serverEPSS 0.75%via NVD
CWE-305 vulnerabilities (CVEs) · VulnSea