CWE-290— Authentication Bypass by Spoofing
This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.— MITRE CWE catalog
740 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-290page 15 of 15
- CVE-2026-7656MEDIUMCVSS 6.8EG 6.82026-06-29
The IPv6 Neighbor Discovery handlers in subsys/net/ip/ipv6_nbr.c (handle_ra_input, handle_ns_input, handle_na_input) used an incorrect boolean expression that combined the RFC 4861 validity checks with the ICMPv6 code check using the wrong…
- CVE-2026-76835CRITICALCVSS 9.1EG 9.12026-08-24
OAuth2 Proxy honours a client-supplied X-Forwarded-Uri header when deciding whether a request may skip authentication, because the guard added for CVE-2026-40575 is inert in the default reverse-proxy configuration. GetRequestURI in pkg/req…
- CVE-2026-76949CRITICALCVSS 9.1EG 9.12026-09-17
Authentication Bypass by Spoofing vulnerability in team-alembic ash_authentication allows an attacker who can plant a remember-me cookie in a victim's browser to replace that victim's authenticated session with one for the attacker's own a…
- CVE-2026-77089CRITICALCVSS 9.8EG 9.82026-09-08
Command Center API contained an authentication bypass issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update Command Center.
- CVE-2026-77337CRITICALCVSS 9.1EG 9.12026-08-24
CakePHP Authentication is an authentication plugin for CakePHP that can also be used in PSR-7 based applications. Versions before 2.11.2, from 3.0.0 through 3.3.6, and from 4.0.0 through 4.2.0 allow authentication bypass and potential CPU …
- CVE-2026-77903CRITICALCVSS 9.0EG 9.02026-09-17
Authentication bypass by spoofing in Microsoft Dataverse allows an unauthorized attacker to elevate privileges over a network.
- CVE-2026-80349CRITICALCVSS 9.8EG 9.82026-08-26
TarsWeb decides whether a request comes from a trusted local caller using a client-controlled header. app.js sets Koa's proxy option to true without naming which upstream proxies may be trusted and without limiting the number of forwarded …
- CVE-2026-81777MEDIUMCVSS 5.3EG 5.32026-08-28
Authentication Bypass by Spoofing vulnerability in WPDeveloper Essential Addons for Elementor allows Identity Spoofing. This issue affects Essential Addons for Elementor: from n/a through 6.8.0.
- CVE-2026-82180CRITICALCVSS 9.5EG 9.52026-09-03
In Eclipse Arrowhead versions from 5.0.0 to 5.2.1 when the MQTT API is enabled with the certificate authentication policy, CertificateMqttFilter parses an X.509 certificate that the client sends inside the MQTT message payload (the authent…
- CVE-2026-82228HIGHCVSS 8.1EG 8.12026-08-31
Unauthenticated Bypass Vulnerability in SiteGround Security <= 1.6.6 versions.
- CVE-2026-82530MEDIUMCVSS 5.3EG 5.32026-09-09
IP2Location Country Blocker plugin for WordPress before 2.45.0 contains an access control bypass vulnerability that allows unauthenticated remote attackers to circumvent IP-based restrictions by forging the X-Real-IP HTTP header. Attackers…
- CVE-2026-82563HIGHCVSS 7.6EG 7.62026-09-09
An attacker could impersonate the camera and place themselves in a man-in-the-middle or device-emulation position. This permits manipulation of device status responses, observation of application requests, and potential triggering of firmw…
- CVE-2026-84186MEDIUMCVSS 6.9EG 6.92026-09-07
Vulnerability involving incorrect access control in the Tools::getRemoteAddr() function in PrestaShop, which allows the client’s IP address to be spoofed via the X-Forwarded-For header when the application is running behind a reverse pro…
- CVE-2026-84476HIGHCVSS 7.5EG 7.52026-09-01
WWBN AVideo fails to validate trusted proxies before accepting X-Real-IP and X-Forwarded-For headers, allowing attackers to spoof the client address used by enforceRateLimit(). Attackers can rotate the header value per request to bypass lo…
- CVE-2026-84479CRITICALCVSS 9.1EG 9.12026-09-01
WWBN AVideo (current e01e41ecc and earlier) makes three login-time security controls depend solely on the client-supplied User-Agent header. The isAVideoEncoder()/isAVideoMobileApp() checks match HTTP_USER_AGENT against a hardcoded literal…
- CVE-2026-84766MEDIUMCVSS 5.9EG 5.92026-09-03
Unauthenticated Bypass Vulnerability in FluentBooking Pro <= 2.2.1 versions.
- CVE-2026-84849MEDIUMCVSS 6.5EG 6.52026-09-03
Unauthenticated Bypass Vulnerability in Pre-Orders for WooCommerce <= 2.3 versions.
- CVE-2026-85432HIGHCVSS 8.2EG 8.22026-09-03
MOOS core-moos through 10.4.0 fails to validate client identity in MOOSDB message processing, allowing authenticated attackers to attribute writes to other clients by supplying arbitrary source identifiers in serialized messages. Attackers…
- CVE-2026-85511MEDIUMCVSS 4.2EG 4.22026-09-18
A flaw was found in EAP's Elytron. An EAP application whose security domain is backed by an Elytron token-realm with oauth2-introspection would allow parameter substitution due to missing URL encoding.
- CVE-2026-86039HIGHCVSS 8.2EG 8.22026-09-17
libp2p is a JavaScript implementation of the libp2p networking stack. From 8.0.0 until 12.0.24, @libp2p/peer-store in packages/peer-store/src/index.ts uses consumePeerRecord to verify a RecordEnvelope signature but does not require PeerRec…
- CVE-2026-86196HIGHCVSS 8.7EG 8.72026-09-05
Grav API plugin versions before 1.0.20 build password reset links from the untrusted Host header in the forgot-password endpoint, allowing unauthenticated attackers to redirect reset tokens to attacker-controlled domains. Attackers can sen…
- CVE-2026-8644CRITICALCVSS 9.1EG 9.12026-06-01
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to identity spoofing.
- CVE-2026-86478CRITICALCVSS 9.8EG 9.82026-09-07
In JetBrains YouTrack before 2025.3.161254, 2026.1.14042 improper authentication in YouTrack Helpdesk allowed unauthenticated account takeover via a self-asserted email address
- CVE-2026-8651HIGHCVSS 7.5EG 7.52026-07-08
Limited authentication bypass by spoofing vulnerability in Progress MOVEit Transfer (HTTPS module). This issue affects MOVEit Transfer: before 2025.0.7, from 2025.1.0 before 2025.1.3.
- CVE-2026-8676HIGHCVSS 8.8EG 8.82026-05-26
An attacker is able to downgrade the security of a Bluetooth LE connection by deleting an existing bond, spoofing the bonded device and creating a new bond.
- CVE-2026-86863CRITICALCVSS 9.8EG 9.82026-09-17
pgAdmin 4's Webserver authentication source is intended to accept an identity asserted by the web server or reverse proxy in front of pgAdmin, delivered through the WSGI/CGI environment. WebserverAuthentication.get_user() read config.WEBSE…
- CVE-2026-87785CRITICALCVSS 9.1EG 9.12026-09-14
Authentication bypass by spoofing vulnerability in Apache Syncope. When the configured JWKS settings for internal JWT authentication are disclosed (at least protocol and key), an attacker can spoof another user's privileges after comple…
- CVE-2026-88011HIGHCVSS 8.1EG 8.12026-09-10
Traefik is an open source HTTP reverse proxy and load balancer. Prior to 2.11.56, and from 3.0.0 until 3.7.12, a client-supplied dot-form header such as X.Authenticated.User survives ForwardAuth replacement and underscoreHeadersStrategy be…
- CVE-2026-88819MEDIUMCVSS 6.3EG 6.32026-09-14
In Siglet current and past versions the refresh token handler do not enforce proof of possession of the issuer DID.
- CVE-2026-88879HIGHCVSS 8.2EG 8.22026-09-10
Traefik is an HTTP reverse proxy and load balancer. In Traefik v1.x, v2.x through v2.11.55, and v3.0.0 through v3.7.11, header names are canonicalized only on dashes, so X-Auth-User, X_Auth_User and X.Auth.User are treated as three distinc…
- CVE-2026-89022HIGHCVSS 7.4EG 7.42026-09-15
BookStack before 26.05.5 contains an authentication bypass vulnerability in its social login implementation that allows unauthenticated attackers to sign in as arbitrary users by authenticating through a different social provider sharing t…
- CVE-2026-89327LOWCVSS 3.8EG 3.82026-09-16
The FluentBoards WordPress plugin before 2.0.15 does not verify that a board member submitting a comment is the user the comment is attributed to, allowing any board member to post comments that appear to be authored by another user, incl…
- CVE-2026-8951MEDIUMCVSS 6.5EG 6.52026-05-19
Spoofing issue in the Toolbar component in Firefox for Android. This vulnerability was fixed in Firefox 151.
- CVE-2026-8960HIGHCVSS 7.5EG 7.52026-05-19
Spoofing issue in WebExtensions. This vulnerability was fixed in Firefox 151 and Thunderbird 151.
- CVE-2026-8961MEDIUMCVSS 6.5EG 6.52026-05-19
Spoofing issue in the Form Autofill component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.
- CVE-2026-8963HIGHCVSS 7.5EG 7.52026-05-19
Spoofing issue in the Web Speech component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.
- CVE-2026-90447HIGHCVSS 7.1EG 7.12026-09-11
A routing rule selects between two different authentication mechanisms for the same downstream service based on the value of a client-supplied request header, rather than on any property the client cannot control. An authenticated user in …
- CVE-2026-90711CRITICALCVSS 9.1EG 9.12026-09-15
proxy-addr is a Node.js module that determines a request's client address behind trusted reverse proxies, and it backs Express req.ip and req.ips. In versions 1.1.0 through 2.0.7, a trust subnet written in IPv4-mapped IPv6 notation with an…
- CVE-2026-91039CRITICALCVSS 9.1EG 9.12026-09-17
Authentication Bypass by Spoofing vulnerability in team-alembic ash_authentication allows an attacker who operates one identity-provider connection of a dynamic_oidc strategy to be signed in as a local user established through a different …
- CVE-2026-92395CRITICALCVSS 9.1EG 9.12026-09-16
@fastify/proxy-addr is a Fastify plugin that determines a request's client address behind trusted reverse proxies, and it backs Fastify request.ip and request.ips. In versions 3.0.0 through 5.1.0, a trust subnet written in IPv4-mapped IPv6…
Map vulnerabilities like CWE-290 to your infrastructure
EchelonGraph correlates every CVE — across CWE-290 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →