CWE-290— Authentication Bypass by Spoofing
This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.— MITRE CWE catalog
740 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-290page 14 of 15
- CVE-2026-56357MEDIUMCVSS 5.3EG 5.32026-02-26
n8n before 1.123.15 and 2.5.0 contains a webhook forgery vulnerability in the GitHub Webhook Trigger node that fails to implement HMAC-SHA256 signature verification. Attackers who know the webhook URL can send unsigned POST requests to tri…
- CVE-2026-56360MEDIUMCVSS 4.0EG 4.02026-07-08
n8n before versions 1.123.18 and 2.6.2 fails to verify HMAC-SHA256 signatures on Zendesk webhooks in the ZendeskTrigger node. Attackers who know the webhook URL can send unsigned POST requests to trigger workflows with arbitrary malicious …
- CVE-2026-56675HIGHCVSS 8.3EG 8.32026-07-10
9Router is an AI router & token saver. Prior to 0.5.2, 9router treats loopback requests as trusted and allows /v1/* access without an API key, so a same-host reverse proxy that forwards public traffic to the backend through 127.0.0.1 cause…
- CVE-2026-5792MEDIUMCVSS 6.5EG 6.52026-06-12
Authentication bypass by spoofing vulnerability in Hedef Media Promotion Interactive Media Marketing Inc. Related Marketing Cloud (RMC) allows Brute Force. This issue affects Related Marketing Cloud (RMC): through 12052026.
- CVE-2026-58370HIGHCVSS 8.1EG 8.12026-06-30
Woodpecker before 3.15.0 matches the ApprovalAllowedUsers bypass list against pipeline.Author. For the GitLab forge driver, pipeline.Author is populated from the git commit author name (commit.author.name) carried in the webhook payload, w…
- CVE-2026-58488MEDIUMCVSS 6.9EG 6.92026-07-13
HedgeDoc is an open source, real-time, collaborative, markdown notes application. Versions prior to 1.11.0 allowed attackers to circumvent the rate-limiting of the /login and /register routes by spoofing IP addresses. HedgeDoc instances ch…
- CVE-2026-58575HIGHCVSS 8.8EG 8.82026-09-01
Dell PowerStore contains an Authentication Bypass by Spoofing vulnerability. An authenticated attacker could potentially exploit this vulnerability to escalate privileges to Administrator.
- CVE-2026-58593HIGHCVSS 7.5EG 7.52026-07-01
NodeBB does not bind the claimed author of an inbound ActivityPub object to the authenticated remote actor. The inbound middleware verifies the HTTP-signature actor and checks the origin of object.id, but never validates that attributedTo …
- CVE-2026-59157MEDIUMCVSS 6.5EG 6.52026-09-09
webhookd is a minimalist webhook server that triggers shell scripts and external processes through HTTP requests. Prior to 1.22.0, webhookd deployments without htpasswd authentication forwarded all incoming HTTP headers through HTTPParamsT…
- CVE-2026-59224HIGHCVSS 8.0EG 8.02026-07-09
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, backend/open_webui/routers/terminals.py built the ws_terminal upstream URL from an unencoded session_id and appended user_id as a query …
- CVE-2026-59914HIGHCVSS 7.8EG 7.82026-08-12
Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain an Authentication Bypass by Spoofing vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading t…
- CVE-2026-59916HIGHCVSS 7.8EG 7.82026-08-12
Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation o…
- CVE-2026-6090HIGHCVSS 7.0EG 7.02026-06-10
A potential authentication bypass was reported in Lenovo Smart Connect for Windows that could allow a local authenticated user to execute arbitrary code with elevated privileges.
- CVE-2026-61217MEDIUMCVSS 6.4EG 6.42026-07-21
Vulnerability in the Oracle Security Service product of Oracle Fusion Middleware (component: Oracle SSL API). The supported version that is affected is 12.2.1.4.0. Difficult to exploit vulnerability allows low privileged attacker with ne…
- CVE-2026-61428HIGHCVSS 7.3EG 7.32026-07-11
PraisonAI AgentMail versions before 4.6.78 lack signature verification in webhook mode, allowing unauthenticated attackers to inject messages with spoofed sender addresses. Attackers can POST crafted message.received events to the webhook …
- CVE-2026-61682CRITICALCVSS 9.9EG 9.92026-09-18
kcp is a Kubernetes-like control plane for form-factors and use-cases beyond Kubernetes and container workloads. Prior to 0.31.4 and 0.32.2, the kcp front-proxy does not remove inbound X-Remote-User, X-Remote-Group, or X-Remote-Extra-* ide…
- CVE-2026-6181MEDIUMCVSS 5.9EG 5.92026-08-11
The Device Configuration Framework is vulnerable to an authentication bypass flaw. This flaw can only be exploited after authenticating with a viewer-privileged service account.
- CVE-2026-62108CRITICALCVSS 9.8EG 9.82026-09-17
Unauthenticated Broken Authentication in Headless Single Sign On <= 1.7.0 versions.
- CVE-2026-6213CRITICALCVSS 10.0EG 10.02026-05-08
A vulnerability in Remote Spark SparkView before build 1122 allows an attacker to bypasses the local connection check and achieve arbitrary code execution as root on the server side. Depending on implementation the vulnerability can be…
- CVE-2026-62224MEDIUMCVSS 5.4EG 5.42026-07-17
OpenClaw MS Teams before 2026.5.12 contain an authorization bypass vulnerability where the allowFrom feature binds to mutable display names. Attackers with lower-trust access can perform actions requiring stronger authorization by exploiti…
- CVE-2026-62644CRITICALCVSS 9.8EG 9.82026-07-14
In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the password plugin of the Roundcube Webmail was subject to username spoofing via session data, which could lead to account takeover.
- CVE-2026-62759HIGHCVSS 7.5EG 7.52026-09-08
Authentication bypass by spoofing in Windows Netlogon allows an unauthorized attacker to perform spoofing over an adjacent network.
- CVE-2026-63427HIGHCVSS 7.8EG 7.82026-09-10
An authentication bypass vulnerability was discovered in Lenovo Software Fix that could allow a local authenticated user to perform arbitrary code execution with elevated privileges.
- CVE-2026-63683HIGHCVSS 7.5EG 7.52026-07-22
Joomla Extension - regularlabs.com - Client IP spoofing vulnerability in Regular Labs conditions manager - IP and GeoIP conditions trusted spoofable forwarded headers, allowing remote clients to bypass location-based rules.
- CVE-2026-6387HIGHCVSS 7.0EG 7.02026-08-13
A potential authentication bypass vulnerability was reported in Lenovo System Update that could allow a local authenticated user to execute arbitrary code with elevated privileges.
- CVE-2026-64665HIGHCVSS 8.1EG 8.12026-08-06
Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, when OAuth login was enabled with a provider that does not guarantee verified email addresses, an unauthenticated attacker could sign in as …
- CVE-2026-64797HIGHCVSS 7.5EG 7.52026-07-22
Joomla Extension - regularlabs.com - IP spoofing vulnerability in IP login extension - IP Login trusted forwarded client-IP headers without requiring a configured trusted proxy. Attackers could spoof the IP used for automatic login and pot…
- CVE-2026-64875MEDIUMCVSS 6.5EG 6.52026-07-23
Joomla Extension - regularlabs.com - IP spoofing vulnerability in GeoIP extension - GeoIP lookups trusted spoofable forwarded client-IP headers, this could cause GeoIP-rule bypass.
- CVE-2026-65399MEDIUMCVSS 4.4EG 4.42026-09-14
A file quarantine bypass was addressed with additional checks. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, visionOS 27, watchOS 27. An archive may be ab…
- CVE-2026-65502MEDIUMCVSS 5.3EG 5.32026-08-06
Unauthenticated Bypass Vulnerability in Element Pack Elementor Addons <= 8.7.13 versions.
- CVE-2026-65570HIGHCVSS 8.1EG 8.12026-08-06
Unauthenticated Bypass Vulnerability in Login with phone number <= 1.8.70 versions.
- CVE-2026-66674MEDIUMCVSS 5.6EG 5.62026-09-10
Unauthenticated Bypass Vulnerability in Simple Cloudflare Turnstile <= 1.42.1 versions.
- CVE-2026-67558HIGHCVSS 7.4EG 7.42026-08-11
The Mira Android companion app v4.5.15.4 identifies the paired Mira hormone analyzer by performing a substring match against the BLE advertisement name only, with no cryptographic peripheral authentication, MAC allowlist, or bonded-identit…
- CVE-2026-6762MEDIUMCVSS 6.3EG 6.32026-04-21
Spoofing issue in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
- CVE-2026-69183HIGHCVSS 7.5EG 7.52026-08-20
Monkeytype is a minimalistic and customizable typing test. In 26.26.0 and earlier, the backend rate-limit key generator in backend/src/middlewares/rate-limit.ts uses client-controlled cf-connecting-ip and x-forwarded-for headers before the…
- CVE-2026-69843CRITICALCVSS 10.0EG 10.02026-09-17
Authentication bypass by spoofing in Microsoft Fabric allows an unauthorized attacker to elevate privileges over a network.
- CVE-2026-71485CRITICALCVSS 9.1EG 9.12026-08-20
Centrifugo is an open-source scalable real-time messaging server. Prior to 6.9.0, Centrifugo copies the client-controlled protocol.ConnectRequest.headers map through OnClientConnecting in internal/client/handler.go, ConnectEvent.Headers, a…
- CVE-2026-72809HIGHCVSS 8.0EG 8.02026-08-12
SiYuan versions <= v3.7.2 (patched in v3.7.4) contain an authentication bypass vulnerability in the kernel's CheckAuth function, which grants the administrator role (RoleAdministrator) to any request whose RemoteAddr is loopback (127.0.0.1…
- CVE-2026-72815MEDIUMCVSS 6.9EG 6.92026-08-14
go-chi chi versions >= 5.2.1 and before 5.3.0 contain an IP spoofing vulnerability in the RealIP middleware, which blindly trusts the first (leftmost) value of the X-Forwarded-For HTTP header. A remote attacker can bypass IP-based access c…
- CVE-2026-72816MEDIUMCVSS 6.5EG 6.52026-08-14
go-chi/chi through 5.2.1 contains an IP spoofing vulnerability in the RealIP middleware (middleware/realip.go). The realIP() function reads client-controlled headers (True-Client-IP, X-Real-IP, and X-Forwarded-For) and overwrites r.RemoteA…
- CVE-2026-73449MEDIUMCVSS 5.9EG 5.92026-09-14
On affected platforms running Arista EOS with both 802.1X port authentication and the RADIUS proxy feature configured with dynamic authorization, a low-privileged attacker on an adjacent network segment who induces a RADIUS packet through …
- CVE-2026-73742MEDIUMCVSS 4.3EG 4.32026-09-01
A vulnerability in an API endpoint of HPE Networking Fabric Composer could allow an authenticated low privilege operator user to spoof the source address attributed to their requests. Successful exploitation could allow an attacker to caus…
- CVE-2026-73840MEDIUMCVSS 5.3EG 5.32026-08-13
OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.3, 1.1.3, and 1.2.0-rc.2, the POST /api/v1alpha1/autobuild endpoint in internal/openchoreo-api/api/handlers/webhook_handler.go selected a webhook provide…
- CVE-2026-73995MEDIUMCVSS 5.4EG 5.42026-08-18
Subscriber Broken Authentication in User Registration <= 5.2.6 versions.
- CVE-2026-7422MEDIUMCVSS 6.5EG 6.52026-04-29
Insufficient packet validation in FreeRTOS-Plus-TCP before V4.2.6 and V4.4.1 allows an adjacent network actor to bypass all checksum and minimum-size validation by spoofing the Ethernet source MAC address to match one of the device's own r…
- CVE-2026-75037HIGHCVSS 7.0EG 7.02026-08-25
Polkit Authentication Based on UnixProcessSubject / Peer PID in LACT on Linux allows an Authentication Bypass. This issue affects LACT through 0.10.0. Fixed by commit d0478fe42c2219454e272f96b1cbd29ab37ee566.
- CVE-2026-7507HIGHCVSS 7.5EG 7.52026-05-19
A session fixation vulnerability was found in Keycloak's login-actions endpoints. An unauthenticated attacker could exploit this flaw by pre-creating an authentication session and tricking a victim into visiting a maliciously crafted link.…
- CVE-2026-75509MEDIUMCVSS 6.5EG 6.52026-08-24
joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards. Prior to version 1.7.3, JWTClaimsRegistry applies membership matching to list-valued iss and sub claims, allowing a…
- CVE-2026-76356HIGHCVSS 8.1EG 8.12026-08-19
In Splunk SOAR versions below 8.6.0, an unauthenticated user could spoof the source IP address in a crafted request to an Automation Broker notification endpoint and execute arbitrary code on the Splunk SOAR host. The vulnerability is poss…
- CVE-2026-76423CRITICALCVSS 10.0EG 10.02026-09-16
A vulnerability in the REST API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to gain administrative access to an affected device. This vulnerability is due to the REST API web service being exposed with…
Map vulnerabilities like CWE-290 to your infrastructure
EchelonGraph correlates every CVE — across CWE-290 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →