CWE-305— Authentication Bypass by Primary Weakness
The authentication algorithm is sound, but the implemented mechanism can be bypassed as the result of a separate weakness that is primary to the authentication error.— MITRE CWE catalog
173 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-305page 4 of 4
- CVE-2026-3591MEDIUMCVSS 5.4EG 5.42026-03-25
A use-after-return vulnerability exists in the `named` server when handling DNS queries signed with SIG(0). Using a specially-crafted DNS request, an attacker may be able to cause an ACL to improperly (mis)match an IP address. In a default…
- CVE-2026-3784MEDIUMCVSS 6.5EG 6.52026-03-11
curl would wrongly reuse an existing HTTP proxy connection doing CONNECT to a server, even if the new request uses different credentials for the HTTP proxy. The proper behavior is to create or use a separate connection.
- CVE-2026-40039MEDIUMCVSS 6.5EG 6.52026-04-13
Pachno 1.0.6 contains an open redirection vulnerability that allows attackers to redirect users to arbitrary external websites by manipulating the return_to parameter. Attackers can craft malicious login URLs with unvalidated return_to val…
- CVE-2026-40582CRITICALCVSS 9.1EG 9.12026-04-18
ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the /api/public/user/login endpoint validates only the username and password before returning the user's API key, bypassing the normal authentication flow th…
- CVE-2026-40976CRITICALCVSS 9.1EG 9.12026-04-28
In certain circumstances, Spring Boot's default web security is ineffective allowing unauthorized access to all endpoints. For an application to be vulnerable, it must: be a servlet-based web application; have no Spring Security configurat…
- CVE-2026-41052HIGHCVSS 8.8EG 8.82026-06-29
Improper privilege handling could be used by users with Project Owner role to escalate privileges, in Rancher versions 2.14 before 2.14.2, 2.13 before 2.13.6, and 2.12 before 2.12.10.
- CVE-2026-41054HIGHCVSS 7.8EG 7.82026-05-20
In `src/havegecmd.c`, the `socket_handler` function performs a credential check on the abstract UNIX socket (`\0/sys/entropy/haveged`). However, while it detects if the connecting user is not root (`cred.uid != 0`) and prepares a negative …
- CVE-2026-4670CRITICALCVSS 9.8EG 9.82026-04-30
Authentication bypass by primary weakness vulnerability in Progress Software MOVEit Automation allows Authentication Bypass. This issue affects MOVEit Automation: from 2025.0.0 before 2025.0.9, from 2024.0.0 before 2024.1.8, versions prio…
- CVE-2026-53561HIGHCVSS 7.4EG 7.42026-08-25
An improper authentication vulnerability in HiveServer2 SAML bearer-token validation in Apache Hive 4.0.0 through 4.2.0 (and later unreleased branches) on deployments using HTTP transport with hive.server2.authentication=SAML allows an una…
- CVE-2026-5545MEDIUMCVSS 6.5EG 6.52026-05-13
libcurl might in some circumstances reuse the wrong connection when asked to do an authenticated HTTP(S) request after a Negotiate-authenticated one, when both use the same host. libcurl features a pool of recent connections so that subse…
- CVE-2026-62427HIGHCVSS 8.8EG 8.82026-07-28
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] To manage the system, sysctl and platform operations are used by the control domain or a possible Xenstore do…
- CVE-2026-6266HIGHCVSS 8.3EG 8.32026-05-04
A flaw was found in the AAP gateway. The user auto-link strategy, introduced in AAP 2.6, automatically links an external Identity Provider (IDP) identity to an existing AAP user account based on email matching without verifying email owner…
- CVE-2026-6334LOWCVSS 3.1EG 3.12026-05-18
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to enforce client identity binding during the OAuth authorization code redemption flow which allows an authenticated OAuth client to redeem authorization codes issued to a diff…
- CVE-2026-65935HIGHCVSS 7.6EG 7.62026-08-13
Passkey entry Bluetooth LE legacy pairing can be bypassed in the RS9116W and SiWx917 by manipulating the temporary key value. See vulnerability B-E3 in the related paper below.
- CVE-2026-78619CRITICALCVSS 9.8EG 9.82026-08-25
Punk::Plugin::TOTP versions before 0.05 for Perl accept another account's recovery code at the two-factor challenge because totp_use_recovery compares user identifiers numerically. The helper searches the recovery model for the submitted …
- CVE-2026-81578CRITICALCVSS 9.8EG 9.8⚠ KEV2026-08-28
An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions prio…
- CVE-2026-85500CRITICALCVSS 9.1EG 9.12026-09-17
Authentication Bypass by Primary Weakness vulnerability in team-alembic AshAuthentication allows an unconfirmed user to obtain a session, defeating a mandatory email confirmation requirement. AshAuthentication.Strategy.Password.Actions.ch…
- CVE-2026-86207HIGHCVSS 7.7EG 7.72026-09-05
An authentication bypass in N-central < 2026.3 HF 3 leads to authentication bypass in internal only APIs
- CVE-2026-8932HIGHCVSS 7.5EG 7.52026-07-03
libcurl would reuse a previously created connection even when some mTLS config related option had been changed that should have prohibited reuse. libcurl keeps previously used connections in a connection pool for subsequent transfers to r…
- CVE-2026-9047HIGHCVSS 7.6EG 7.62026-05-26
Improper handling of factor key state in the multi-factor authentication management feature in Devolutions Server allows an attacker with knowledge of a user's password to bypass the user's multi-factor authentication after the user reconf…
- CVE-2026-9571MEDIUMCVSS 6.5EG 6.52026-07-13
Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to invalidate OAuth refresh tokens upon user account deactivation, which allows a deactivated user or an attacker in possession of a valid refresh token to ob…
- CVE-2026-9597MEDIUMCVSS 5.4EG 5.42026-07-13
Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4 fail to verify whether a guest account is deactivated before creating a session in the magic-link token login path, which allows a deactivated guest user to obtain a fully functional s…
- CVE-2026-9798MEDIUMCVSS 4.3EG 4.32026-05-28
A flaw was found in Keycloak, an open-source identity and access management solution. When a user account is temporarily locked due to repeated failed login attempts, an attacker with valid client credentials can exploit the Client-Initiat…
Map vulnerabilities like CWE-305 to your infrastructure
EchelonGraph correlates every CVE — across CWE-305 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →