CWE-290— Authentication Bypass by Spoofing
This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.— MITRE CWE catalog
740 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-290page 11 of 15
- CVE-2025-69258CRITICALCVSS 9.8EG 9.82026-01-08
A LoadLibraryEX vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to load an attacker-controlled DLL into a key executable, leading to execution of attacker-supplied code under the context of SYSTEM o…
- CVE-2025-69401HIGHCVSS 7.5EG 7.52026-02-20
Authentication Bypass by Spoofing vulnerability in mdalabar WooODT Lite byconsole-woo-order-delivery-time allows Identity Spoofing.This issue affects WooODT Lite: from n/a through <= 2.5.2.
- CVE-2025-71056CRITICALCVSS 8.1EG 9.12026-02-23
Improper session management in GCOM EPON 1GE ONU version C00R371V00B01 allows attackers to execute a session hijacking attack via spoofing the IP address of an authenticated user.
- CVE-2025-7448HIGHCVSS 8.6EG 8.62025-09-12
Wi-SUN unexpected 4- Way Handshake packet receptions may lead to predictable keys and potentially leading to Man in the middle (MitM) attack
- CVE-2025-8853CRITICALCVSS 9.8EG 9.82025-08-11
Official Document Management System developed by 2100 Technology has an Authentication Bypass vulnerability, allowing unauthenticated remote attackers to obtain any user's connection token and use it to log into the system as that user.
- CVE-2025-9265CRITICALCVSS 10.0EG 10.02025-10-13
A broken authorization vulnerability in Kiloview NDI N30 allows a remote unauthenticated attacker to deactivate user verification, giving them access to state changing actions that should only be initiated by administratorsThis issue affec…
- CVE-2026-0292MEDIUMCVSS 6.0EG 6.02026-08-13
An authentication bypass vulnerability in the network driver of Palo Alto Networks Prisma® Access Agent on Windows enables a local administrator to bypass security inspection, subsequently allowing them to inject and intercept arbitrary …
- CVE-2026-0385MEDIUMCVSS 5.0EG 5.02026-03-16
Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability
- CVE-2026-0834HIGHCVSS 8.8EG 8.82026-01-21
Logic vulnerability in TP-Link Archer C20 v5, 6.0, Archer AX53 v1.0 and TL-WR841N v13 (TDDP module) allows unauthenticated adjacent attackers to execute administrative commands including factory reset and device reboot without credentials.…
- CVE-2026-0890MEDIUMCVSS 5.4EG 6.52026-01-13
Spoofing issue in the DOM: Copy & Paste and Drag & Drop component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7.
- CVE-2026-11001MEDIUMCVSS 6.5EG 6.52026-06-04
Inappropriate implementation in Payments in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: …
- CVE-2026-11019MEDIUMCVSS 6.5EG 6.52026-06-04
Inappropriate implementation in Payments in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to perform domain spoofing via a crafted HTML page. (Chromium security severity:…
- CVE-2026-11870MEDIUMCVSS 5.4EG 5.42026-07-30
The WP Ghost (Hide My WP Ghost) WordPress plugin before 7.0.05 does not verify that client IP information comes from a trusted proxy before trusting attacker-controllable HTTP headers, allowing unauthenticated attackers to spoof their IP …
- CVE-2026-11922MEDIUMCVSS 6.5EG 6.52026-07-24
A vulnerability in zenml-io/zenml versions 0.57.0 through 0.94.2 allows an attacker to bypass rate-limiting on the `POST /api/v1/login` and self password-change endpoints by rotating the `X-Forwarded-For` header. The rate limiter keys requ…
- CVE-2026-12382HIGHCVSS 8.2EG 8.22026-07-15
A flaw was found in the AAP Gateway Envoy proxy configuration. The non-mTLS route to EDA event streams does not remove the Subject HTTP header from client requests, despite the source code defining requestHeadersToRemove for this header. A…
- CVE-2026-13143MEDIUMCVSS 5.3EG 5.32026-07-30
The WP Travel WordPress plugin before 11.8.1 does not verify PayPal Instant Payment Notifications through the PayPal post-back handshake before marking a booking paid, allowing unauthenticated attackers to forge a notification that flips …
- CVE-2026-13207HIGHCVSS 7.5EG 7.52026-06-30
FUXA versions 1.3.1 and prior contain an authentication bypass vulnerability via dot-segment path normalization in the REST API. The API router fails to normalize dot-segment sequences before applying authentication middleware, allowing un…
- CVE-2026-13735LOWCVSS 3.7EG 3.72026-08-28
Zephyr's WireGuard implementation in subsys/net/lib/wireguard/wg_crypto.c mishandled keepalive packets. In wg_process_data_message(), any type-4 transport-data message whose payload was exactly 16 bytes (an empty plaintext plus a bare Poly…
- CVE-2026-13984MEDIUMCVSS 4.3EG 4.32026-06-30
Incorrect security UI in TabStrip in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2026-13985MEDIUMCVSS 6.5EG 6.52026-06-30
Inappropriate implementation in MediaCapture in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2026-14118MEDIUMCVSS 6.5EG 6.52026-07-01
Insufficient data validation in DevTools in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-origin data via a crafted HTML page. (Chromium security severit…
- CVE-2026-14199HIGHCVSS 8.1EG 8.12026-09-02
Only self-managed Grafana instances with Auth Proxy authentication and identity caching enabled (sync_ttl greater than zero) are affected. The Auth Proxy cache key concatenated the username and forwarded identity attributes without a delim…
- CVE-2026-14381MEDIUMCVSS 6.5EG 6.52026-07-02
Incorrect security UI in WebAppInstalls in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2026-14450CRITICALCVSS 9.9EG 9.92026-08-10
A flaw was found in the MaaS API. This vulnerability allows any pod within the cluster to bypass the Kuadrant AuthPolicy gateway by forging HTTP headers, specifically `X-MaaS-Username` and `X-MaaS-Group`, which are trusted verbatim. This l…
- CVE-2026-14840MEDIUMCVSS 5.3EG 5.32026-08-01
The YOP Poll WordPress plugin before 7.0.6 does not validate the connection's origin IP address and instead trusts client-controlled forwarding headers when enforcing its per-IP vote restriction, allowing unauthenticated attackers to bypas…
- CVE-2026-15640CRITICALCVSS 9.5EG 9.52026-09-15
Under certain conditions a valid SAML IdP response may be used to impersonate another Secret Server user.
- CVE-2026-15812MEDIUMCVSS 4.8EG 4.82026-07-21
A vulnerability was found in the internal Access Control List (ACL) subsystem of kronosnet (Version affected: <= 1.34). When the framework is explicitly configured to manage dynamic links (accepting network traffic from any IP address) wit…
- CVE-2026-16076MEDIUMCVSS 6.3EG 6.32026-07-18
A vulnerability has been found in AstrBotDevs AstrBot up to 4.25.5. This issue affects the function OpenApiRoute.chat_send of the file astrbot/dashboard/routes/open_api.py of the component API. Such manipulation of the argument Username le…
- CVE-2026-16101HIGHCVSS 8.8EG 8.82026-08-13
Spoofing an already bonded device can force either RS9116W or SiWx917 to re-pair/bond with a rogue device. See V1 in BLERP paper below
- CVE-2026-16404HIGHCVSS 7.4EG 7.42026-07-21
Spoofing issue in Firefox for Android. This vulnerability was fixed in Firefox 153.
- CVE-2026-18065MEDIUMCVSS 5.3EG 5.32026-09-14
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote unauthenticated attacker to gain access to sensitive information through session IP binding bypass in Navigator for i.
- CVE-2026-18639HIGHCVSS 7.3EG 7.32026-08-11
When Velociraptor is configured to use an OIDC IdP for authentication, it uses the email claim as a username. However, some IdP allow users to change the email claim without verification. Some IdPs do not set the "email_verified" claim and…
- CVE-2026-18677MEDIUMCVSS 6.0EG 6.02026-08-12
In Kong Mesh running in universal mode with a MeshIdentity whose SPIFFE ID path template derives from the dataplane's kuma.io/workload label, the XDS authenticator in kuma-cp validates that label only when the dataplane token is bound to a…
- CVE-2026-18972CRITICALCVSS 9.6EG 9.62026-08-11
An authenticated attacker can spoof another GUI user's identity by sending their request with the custom header \"Grpc-Metadata-USER\". This can lead to an account takeover attack from a user with low privileges to administrator.
- CVE-2026-19117CRITICALCVSS 9.8EG 9.82026-09-02
Under specific conditions, an attacker can register an attacker-controlled FIDO2 credential against a target account and then authenticate as that user. This issue affects on-premises deployments only.
- CVE-2026-19291HIGHCVSS 8.8EG 8.82026-08-13
Bluetooth re-pairing with an existing device can use a lower security level. RS9116W and SiWx91x impacted. See V3 in the BLERP paper linked below.
- CVE-2026-19538HIGHCVSS 7.5EG 7.52026-08-26
The BLOCKED access control list items that are evaluated to deny access on the the proxy protocol port can be bypassed completely when connecting over TCP or TLS and sending the query twice on connection that is kept open.
- CVE-2026-20071LOWCVSS 3.8EG 3.82026-09-16
A vulnerability in the SSID bring-your-own-device (BYOD) onboarding workflow of Cisco ISE could allow an unauthenticated, adjacent attacker to hijack the onboarding session of another user and access protected 802.1X networks. …
- CVE-2026-2032MEDIUMCVSS 4.3EG 4.32026-02-16
Malicious scripts that interrupt new tab page loading could cause desynchronization between the address bar and page content, allowing the attacker to spoof arbitrary HTML under a trusted domain. This vulnerability was fixed in Firefox for…
- CVE-2026-21391CRITICALCVSS 9.5EG 9.52026-09-14
An improper validation vulnerability exists within PingAM where a well-crafted request allows arbitrary or protected ID Token claims to be set or overridden. In certain configurations this could allow an attacker to bypass authentication c…
- CVE-2026-21862HIGHCVSS 7.5EG 7.52026-02-03
RustFS is a distributed object storage system built in Rust. Prior to version alpha.78, IP-based access control can be bypassed: get_condition_values trusts client-supplied X-Forwarded-For/X-Real-Ip without verifying a trusted proxy, so an…
- CVE-2026-21894MEDIUMCVSS 6.5EG 6.52026-01-08
n8n is an open source workflow automation platform. In versions from 0.150.0 to before 2.2.2, an authentication bypass vulnerability in the Stripe Trigger node allows unauthenticated parties to trigger workflows by sending forged Stripe we…
- CVE-2026-22199HIGHCVSS 7.5EG 7.52026-03-13
Voltronic Power SNMP Web Pro version 1.1 contains a pre-authentication path traversal vulnerability in the upload.cgi endpoint that allows unauthenticated attackers to read arbitrary files on the device filesystem by supplying directory tr…
- CVE-2026-22734HIGHCVSS 8.6EG 8.62026-04-17
Cloud Foundry UUA is vulnerable to a bypass that allows an attacker to obtain a token for any user and gain access to UAA-protected systems. This vulnerability exists when SAML 2.0 bearer assertions are enabled for a client, as the UAA ac…
- CVE-2026-22797CRITICALCVSS 9.9EG 9.92026-01-19
An issue was discovered in OpenStack keystonemiddleware 10.5 through 10.7 before 10.7.2, 10.8 and 10.9 before 10.9.1, and 10.10 through 10.12 before 10.12.1. The external_oauth2_token middleware fails to sanitize incoming authentication he…
- CVE-2026-24000MEDIUMCVSS 5.3EG 5.32026-05-14
Fleet is open source device management software. Prior to version 4.80.1, Fleet trusted client-supplied IP address headers when determining the source IP for incoming requests. This allowed authenticated and unauthenticated clients to spoo…
- CVE-2026-24013CRITICALCVSS 9.1EG 9.12026-07-06
Authentication Bypass by Spoofing vulnerability in Apache IoTDB. Certain Thrift RPC query handlers lack strict validation of the sessionId parameter. An attacker can construct requests with a forged sessionId and, without performing openSe…
- CVE-2026-24270CRITICALCVSS 9.8EG 9.82026-07-01
NVIDIA AIStore framework contains a vulnerability where an attacker could bypass authentication. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, and data tamperi…
- CVE-2026-24372HIGHCVSS 7.5EG 7.52026-03-25
Authentication Bypass by Spoofing vulnerability in WP Swings Subscriptions for WooCommerce subscriptions-for-woocommerce allows Input Data Manipulation.This issue affects Subscriptions for WooCommerce: from n/a through <= 1.8.10.
- CVE-2026-24853CRITICALCVSS 9.8EG 9.82026-02-13
Caido is a web security auditing toolkit. Prior to 0.55.0, Caido blocks non whitelisted domains to reach out through the 8080 port, and shows Host/IP is not allowed to connect to Caido on all endpoints. But this is bypassable by injecting …
Map vulnerabilities like CWE-290 to your infrastructure
EchelonGraph correlates every CVE — across CWE-290 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →