CVE & CISA-KEV Catalog
| Severity | Description | ||||||
|---|---|---|---|---|---|---|---|
| CVE-2026-81868 | Medium | 6.5 v3 | - | - | -No fix available yet | 2026-09-17 | Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. Prior to 4.3.0, Steeltoe.Security.Authorization.Certificate deployments using AddOrgAndSpacePolicies() and UseCertificateAuthorization() trust the public certificate supplied in the X-Client-Cert request header without proving possession of the corresponding private key. Common Cloud Foundry routers do not remove this header from inbound requests. When inbound requests are not restricted to a known trusted proxy source IP, an attacker who obtains the public certificate of an application instance in the target organization or space and can reach the application can spoof X-Client-Cert to bypass the SameOrg and SameSpace policies for the certificate validity period. Th |
| CVE-2026-62101 | Critical | 9.8 v3 | - | - | -No fix available yet | 2026-09-17 | Unauthenticated Broken Authentication in EduAdmin Booking <= 5.4.2 versions. |
| CVE-2026-14917 | High | 7.7 v4 | - | - | -No fix available yet | 2026-09-16 | A SAML authentication bypass vulnerability affects the Kong SAML plugin when the validate_assertion_signature option is explicitly set to false. This option is enabled by default. When disabled, the plugin may extract the SAML identity from an unsigned assertion and authenticate the user without verifying a valid cryptographic signature. As a result, an unauthenticated remote attacker may be able to submit a crafted SAML response and impersonate arbitrary users, including administrators |
| CVE-2026-27546 | Critical | 9.8 v3 | - | - | -No fix available yet | 2026-09-16 | An unauthenticated remote attacker can exploit an authentication bypass in the _account_log function to log in as an admin, even when accounts are properly configured. |
| CVE-2026-57134 | High | 8.2 v3 | 0.4% | - | -No fix available yet | 2026-09-15 | PraisonAI is a multi-agent teams system. From 1.5.1 until 1.7.2, MCPSecurity.evaluatePolicy() in src/praisonai-ts/src/mcp/security.ts invokes the configured credential validator only when AuthMethod is api-key or bearer. Basic and OAuth policies accept any non-empty Authorization header without calling auth.validate(), then return an authenticated result, allowing callers with invalid credentials to access MCP tools and resources protected by those policies. This issue is fixed in version 1.7.2. |
| CVE-2026-91143 | High | 7.2 v3 | 0.3% | - | -No fix available yet | 2026-09-14 | goproxy through 15.3 fails to apply HTTP proxy basic authentication to CONNECT tunnel requests, allowing unauthenticated clients to bypass credential requirements. Attackers can issue CONNECT requests to establish tunnels through the authenticated proxy without providing credentials, enabling arbitrary TCP traffic relay and access to restricted destinations. |
| CVE-2026-88260 | High | 8.7 v4 | 0.2% | - | -No fix available yet | 2026-09-11 | Authentication bypass using an alternate path or channel and Improper validation of syntactic correctness of input vulnerability in Brainzcompany Zenius EMS 8.0 allows Remote Code Inclusion. This issue affects Zenius EMS 8.0: through OAM (Build 109). |
| CVE-2026-81906 | Medium | 6.3 v4 | 0.3% | - | -No fix available yet | 2026-09-11 | Concrete CMS OAuth callback login path prior to version 9.5.3 did not check whether an account was active or email-validated before establishing a session. A deactivated or unvalidated user with an existing OAuth binding could complete authentication and receive a session that was fully authenticated for the callback response, with the login recorded and login events dispatched. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 6.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Yonatan Drori from Tenzai for reporting. |
| CVE-2026-81796 | High | 7.3 v3 | 0.2% | - | -No fix available yet | 2026-09-10 | Unauthenticated Broken Authentication in WP Travel <= 12.0.3 versions. |
| CVE-2026-81787 | Medium | 6.5 v3 | 0.2% | - | -No fix available yet | 2026-09-10 | Unauthenticated Broken Authentication in IMPress for IDX Broker <= 3.3.0 versions. |
| CVE-2026-81783 | High | 7.1 v3 | 0.2% | - | -No fix available yet | 2026-09-10 | Subscriber Broken Authentication in MailMunch – Grow your Email List <= 3.2.5 versions. |
| CVE-2026-88861 | High | 8.3 v3 | 0.3% | - | -No fix available yet | 2026-09-10 | Capgo (Cap-go/capgo.app) contains an authentication bypass affecting all versions (no patched version available at time of publication). The Edge authorization path allows a password-only Supabase aal1 session to exercise privileged RBAC permissions even when the account has a verified MFA factor that has not been used for the session: the Edge JWT middleware (foundJWT() in supabase/functions/_backend/utils/hono_middleware.ts) accepts the JWT without validating its assurance level, and the direct RBAC path (checkPermission()/checkPermissionPg() in supabase/functions/_backend/utils/rbac.ts calling public.rbac_check_permission_direct()) authorizes by user ID without passing or checking the session aal, unlike the public.verify_mfa() control which correctly requires aal2. An attacker who know |
| CVE-2026-86084 | Medium | 5.5 v3 | 0.3% | - | Fix available | 2026-09-08 | n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the public OIDC login and callback endpoints completed authentication even when OIDC was not the enabled active authentication method. An Enterprise administrator who had configured and later disabled an identity provider still exposed a working route that could issue valid sessions. The affected logic is packages/cli/src/modules/sso-oidc/oidc.service.ee.ts, including generateLoginUrl and the callback flow that lacked assertOidcLoginEnabled. This issue is fixed in versions 1.123.76, 2.37.7 and 2.38.2. |
| CVE-2026-49887 | High | 7.8 v3 | 0.1% | - | -No fix available yet | 2026-09-08 | In maybeRemoveInvalidInstallerPackageName of InstallRepository.kt, there is a possible unauthorized app update due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. |
| CVE-2026-83527 | High | 8.1 v3 | 1.5% | - | -No fix available yet | 2026-09-08 | An Authentication Bypass vulnerability in Sentry before R10.8.2, R10.7.3 and R10.6.4 allows a remote unauthenticated attacker to gain administrative level access. |
| CVE-2026-77103 | High | 7.5 v3 | 0.3% | - | Fix available | 2026-09-08 | CommServe contained an authentication bypass issue affecting access authorization and information disclosure. Software customers upgrade to resolved maintenance release. Update CommServe. |
| CVE-2026-62650 | High | 8.8 v3 | 0.3% | - | -No fix available yet | 2026-09-08 | A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). Server-side authorization checks in the web-based management interface are not properly enforced, allowing role-based access control (RBAC) restrictions to be bypassed through manipulation of request data. This could allow an authenticated, low-privileged remote attacker to escalate privileges to an administrative level. |
| CVE-2026-62916 | Critical | 9.1 v3 | 0.6% | - | -No fix available yet | 2026-09-08 | Authentication bypass using an alternate path or channel in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network. |
| CVE-2026-76169 | High | 7.5 v3 | 0.5% | - | Fix available | 2026-09-04 | fastify versions >= 4.0.0 and before 5.12.2 can route a malformed URL sent under one plugin prefix to the custom not-found handler of a different sibling plugin, and invoke it without the preHandler hook declared for that handler. The internal not-found router for encapsulated handlers dispatches malformed paths through a single shared handler pointer before URL decoding, ignoring the prefix and skipping the selected handler's normal lifecycle. An unauthenticated attacker can therefore reach an authentication-protected private fallback through an unrelated public prefix and read its full response, bypassing the authentication hook and breaking prefix encapsulation. Users should upgrade to fastify 5.12.2 or later. |
| CVE-2026-84777 | High | 7.4 v3 | 0.2% | - | -No fix available yet | 2026-09-03 | Unauthenticated Broken Authentication in Really Simple SSL <= 9.8.0 versions. |
| CVE-2026-81168 | Low | 3.7 v3 | 0.3% | - | Fix available | 2026-09-02 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal CAPTCHA Protected Page allows Functionality Bypass. This issue affects CAPTCHA Protected Page versions: from 0.0.0 to 1.0.2. |
| CVE-2026-16647 | Medium | 4.1 v3 | 0.3% | - | Fix available | 2026-09-02 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Disable Login Page allows Functionality Bypass. This issue affects Disable Login Page versions: from 0.0.0 to 1.1.4. |
| CVE-2026-82225 | High | 7.4 v3 | 0.2% | - | -No fix available yet | 2026-08-31 | Unauthenticated Broken Authentication in RegistrationMagic <= 6.0.9.8 versions. |
| CVE-2026-82269 | High | 8.1 v3 | 0.3% | - | -No fix available yet | 2026-08-28 | Gophish through 0.12.1 fails to enforce account lockout and password change requirements in the API authentication middleware. Attackers with valid API keys can bypass these security controls and retain full API access even when their account is locked or password change is required. |
| CVE-2026-76943 | Critical | 9.8 v3 | 0.7% | - | -No fix available yet | 2026-08-28 | Xiiaozet LK100Wt contains an authentication weakness within an administrative service that may allow an attacker to bypass intended access controls and obtain command execution capabilities. Successful exploitation could allow unauthorized interaction with privileged functionality and may lead to complete device compromise. |
| CVE-2026-65641 | Critical | 9.3 v4 | 0.5% | - | -No fix available yet | 2026-08-26 | A vulnerability allowing an unauthenticated network attacker to coerce SMB authentication from the service account. |
| CVE-2026-3035 | Medium | 5.5 v3 | 0.2% | - | Fix available | 2026-08-26 | GitLab has remediated an issue in GitLab EE affecting all versions from 11.3 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain conditions, an authenticated user with project Maintainer permissions could have accessed the terminal of a protected environment they were not authorized to use due to improper authorization checks. |
| CVE-2026-58092 | High | 8.1 v3 | 0.2% | - | -No fix available yet | 2026-08-26 | In FreeBSD 15.0, the kernel structure used to represent user credentials changed: previously the primary group ID was stored in the first element of the array containing the list of supplementary group IDs, whereas now the primary group ID is stored in a dedicated field. This change was largely internal to the kernel and not user-visible. One function, group_is_primary(), was not properly updated as a part of this transition. This function is used by mac_do to determine the primary group ID of the credential after applying a transition rule, used when the rule target does not explicitly specify a group. As a result, with certain mac_do rules, it is possible for a credential switch to incorrectly set the primary group ID to the ID stored in the first element of the original credential's |
| CVE-2026-16639 | Critical | 9.8 v3 | 0.3% | - | -No fix available yet | 2026-08-25 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Internationalization Single Sign-On allows Authentication Bypass. This issue affects Internationalization Single Sign-On versions: from 0.0.0 to 1.8.0. |
| CVE-2026-63587 | High | 8.6 v3 | 0.3% | - | -No fix available yet | 2026-08-25 | The SMS control function of IE-SR-2TX-WL-4G devices can require a password for SMS commands via the 'Enable Password Authorization' setting. The device increments a retry counter on each failed SMS password attempt; after 5 consecutive failed attempts, SMS password authorization is automatically disabled. An unauthenticated remote attacker who is able to send SMS messages to the device can deliberately trigger this by submitting 5 or more invalid passwords, after which subsequent SMS commands are executed without requiring a password, resulting in potential limited configuration tampering, limited information leakage and potentially full loss of availability. |
| CVE-2026-78259 | High | 7.3 v3 | 0.2% | - | -No fix available yet | 2026-08-24 | Unauthenticated Broken Authentication in WPLegalPages <= 3.7.0 versions. |
| CVE-2026-74001 | Critical | 9.8 v3 | 0.4% | - | -No fix available yet | 2026-08-20 | Unauthenticated Broken Authentication in User Registration & Membership Pro <= 5.4.5 versions. |
| CVE-2026-66677 | High | 7.6 v3 | 0.4% | - | -No fix available yet | 2026-08-20 | Subscriber Broken Authentication in Leyka <= 3.32.3 versions. |
| CVE-2026-19490 | Critical | 9.8 v3 | 5.6% | KEV | Fix available | 2026-08-19 | Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21. |
| CVE-2026-50191 | High | 8.8 v3 | 0.3% | - | -No fix available yet | 2026-08-18 | 4gaBoards is a boards system for realtime project management. Prior to 3.3.8, 4gaBoards is vulnerable to pre-account takeover when registrationEnabled, localRegistrationEnabled, and ssoRegistrationEnabled are enabled and Google, GitHub, Microsoft, or OIDC SSO is configured. The POST /api/register endpoint permits creation of an unverified local account with a victim's email address, and POST /api/access-tokens permits that account to authenticate while isVerified is false. During the victim's first SSO login, server/api/helpers/users/get-create-one-for-github-sso.js, server/api/helpers/users/get-create-one-for-google-sso.js, server/api/helpers/users/get-create-one-for-microsoft-sso.js, and server/api/helpers/users/get-create-one-for-oidc-sso.js find the attacker-controlled account by email |
| CVE-2026-24185 | High | 7.1 v3 | 0.2% | - | -No fix available yet | 2026-08-18 | NVIDIA NVOS for network switches contains a vulnerability in the secure shell (SSH) server configuration component while PKA-only mode is enabled, where an administrator could inadvertently enable an alternative authentication path. If best practices for replacing the default password as recommended by NVIDIA are not followed, this alternative authentication path might lead to unauthorized access. A successful exploit of this vulnerability might lead to escalation of privileges. |
| CVE-2021-43718 | Medium | 5.3 v3 | 0.4% | - | -No fix available yet | 2026-08-18 | An Authentication Bypass vulnerability exists in EPSON EH-TW5350 EPSON 150075647YWWV110, which could let a remote malicious user cause a Denial of Service via specially crafted series of HTTP.. |
| CVE-2026-71879 | Critical | 9.1 v4 | 0.5% | - | -No fix available yet | 2026-08-18 | Missing authentication in initial setup functionality left exposed until first reboot in GBIF Integrated Publishing Toolkit versions before 3.3.4 allows remote authenticated attackers to gain administrative control via authentication bypass |
| CVE-2026-73399 | Medium | 6.5 v3 | 0.4% | - | -No fix available yet | 2026-08-18 | Unauthenticated Broken Authentication in Flutterwave WooCommerce <= 3.3.0 versions. |
| CVE-2026-73398 | Medium | 6.5 v3 | 0.3% | - | -No fix available yet | 2026-08-18 | Unauthenticated Broken Authentication in Piraeus Bank WooCommerce Payment Gateway 3.2.0 versions. |
| CVE-2026-73396 | High | 7.1 v3 | 0.4% | - | -No fix available yet | 2026-08-18 | Subscriber Broken Authentication in MWB HubSpot for WooCommerce <= 1.6.7 versions. |
| CVE-2026-73381 | Critical | 9.1 v3 | 0.5% | - | -No fix available yet | 2026-08-18 | Unauthenticated Broken Authentication in Popup by Supsystic <= 1.13.0 versions. |
| CVE-2026-73379 | Medium | 6.5 v3 | 0.2% | - | -No fix available yet | 2026-08-18 | Unauthenticated Bypass Vulnerability in Contact Form by Supsystic < 1.10.0 versions. |
| CVE-2026-32481 | High | 7.5 v3 | 0.3% | - | -No fix available yet | 2026-08-18 | Unauthenticated Broken Authentication in Ezoic <= 2.22.11 versions. |
| CVE-2026-75627 | Critical | 9.8 v3 | 0.4% | - | -No fix available yet | 2026-08-18 | Bastillion fails to properly validate request URI paths in its controller dispatcher, allowing unauthenticated attackers to bypass authentication filters by prefixing requests with arbitrary path segments. Attackers can access administrative controllers to read user listings, create manager accounts, and register managed systems, gaining control over SSH access to the managed fleet. |
| CVE-2026-75045 | Critical | 9.1 v3 | 0.3% | - | Fix available | 2026-08-17 | In JetBrains YouTrack before 2025.3.156085, 2026.1.13913, 2026.2.18112 an unauthenticated attacker could download database backups via shared draft signature |
| CVE-2026-66465 | Critical | 9.8 v3 | 0.4% | - | -No fix available yet | 2026-08-13 | Unauthenticated Broken Authentication in Cartify <= 1.3.0.1 versions. |
| CVE-2026-66453 | Critical | 9.8 v3 | 0.4% | - | -No fix available yet | 2026-08-13 | Unauthenticated Broken Authentication in Salon booking system <= 10.30.26 versions. |
| CVE-2026-70468 | High | 8.1 v3 | 0.7% | - | Fix available | 2026-08-12 | A authentication bypass using an alternate path or channel vulnerability in Fortinet FortiManager 7.6.1, FortiManager 7.4.3 through 7.4.5, FortiManager 7.2.5 through 7.2.9, FortiManager Cloud 7.6.1, FortiManager Cloud 7.4.3 through 7.4.5, FortiManager Cloud 7.2.5 through 7.2.9 may allow attacker to improper access control via <insert attack vector here> |
| CVE-2026-18636 | Medium | 6.8 v3 | 0.2% | - | -No fix available yet | 2026-08-11 | The Velociraptor gRPC API has a VFSGetBuffer endpoint which allows reading files from the datastore. To prevent users from reading sensitive files or accessing other orgs, the requested path is prefix checked against a list of denied prefixes. This prefix check can be bypassed allowing a user to access usually denied files. If the user has read permission in the ROOT org, this allows access to other orgs, in which the user may not have permission. |
- MediumCVSS 6.5 v3·EPSS -·No fix yet
Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. Prior to 4.3.0, Steeltoe.Security.Authorization.Certificate deployments using AddOrgAndSpacePolicies() and UseCertificateAuthorization() trust the public certificate supplied in the X-Client-Cert request header without proving possession of the corresponding private key. Common Cloud Foundry routers do not remove this header from inbound requests. When inbound requests are not restricted to a known trusted proxy source IP, an attacker who obtains the public certificate of an application instance in the target organization or space and can reach the application can spoof X-Client-Cert to bypass the SameOrg and SameSpace policies for the certificate validity period. Th
Published 2026-09-17
- CriticalCVSS 9.8 v3·EPSS -·No fix yet
Unauthenticated Broken Authentication in EduAdmin Booking <= 5.4.2 versions.
Published 2026-09-17
- HighCVSS 7.7 v4·EPSS -·No fix yet
A SAML authentication bypass vulnerability affects the Kong SAML plugin when the validate_assertion_signature option is explicitly set to false. This option is enabled by default. When disabled, the plugin may extract the SAML identity from an unsigned assertion and authenticate the user without verifying a valid cryptographic signature. As a result, an unauthenticated remote attacker may be able to submit a crafted SAML response and impersonate arbitrary users, including administrators
Published 2026-09-16
- CriticalCVSS 9.8 v3·EPSS -·No fix yet
An unauthenticated remote attacker can exploit an authentication bypass in the _account_log function to log in as an admin, even when accounts are properly configured.
Published 2026-09-16
- HighCVSS 8.2 v3·EPSS 0.4%·No fix yet
PraisonAI is a multi-agent teams system. From 1.5.1 until 1.7.2, MCPSecurity.evaluatePolicy() in src/praisonai-ts/src/mcp/security.ts invokes the configured credential validator only when AuthMethod is api-key or bearer. Basic and OAuth policies accept any non-empty Authorization header without calling auth.validate(), then return an authenticated result, allowing callers with invalid credentials to access MCP tools and resources protected by those policies. This issue is fixed in version 1.7.2.
Published 2026-09-15
- HighCVSS 7.2 v3·EPSS 0.3%·No fix yet
goproxy through 15.3 fails to apply HTTP proxy basic authentication to CONNECT tunnel requests, allowing unauthenticated clients to bypass credential requirements. Attackers can issue CONNECT requests to establish tunnels through the authenticated proxy without providing credentials, enabling arbitrary TCP traffic relay and access to restricted destinations.
Published 2026-09-14
- HighCVSS 8.7 v4·EPSS 0.2%·No fix yet
Authentication bypass using an alternate path or channel and Improper validation of syntactic correctness of input vulnerability in Brainzcompany Zenius EMS 8.0 allows Remote Code Inclusion. This issue affects Zenius EMS 8.0: through OAM (Build 109).
Published 2026-09-11
- MediumCVSS 6.3 v4·EPSS 0.3%·No fix yet
Concrete CMS OAuth callback login path prior to version 9.5.3 did not check whether an account was active or email-validated before establishing a session. A deactivated or unvalidated user with an existing OAuth binding could complete authentication and receive a session that was fully authenticated for the callback response, with the login recorded and login events dispatched. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 6.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Yonatan Drori from Tenzai for reporting.
Published 2026-09-11
- HighCVSS 7.3 v3·EPSS 0.2%·No fix yet
Unauthenticated Broken Authentication in WP Travel <= 12.0.3 versions.
Published 2026-09-10
- MediumCVSS 6.5 v3·EPSS 0.2%·No fix yet
Unauthenticated Broken Authentication in IMPress for IDX Broker <= 3.3.0 versions.
Published 2026-09-10
- HighCVSS 7.1 v3·EPSS 0.2%·No fix yet
Subscriber Broken Authentication in MailMunch – Grow your Email List <= 3.2.5 versions.
Published 2026-09-10
- HighCVSS 8.3 v3·EPSS 0.3%·No fix yet
Capgo (Cap-go/capgo.app) contains an authentication bypass affecting all versions (no patched version available at time of publication). The Edge authorization path allows a password-only Supabase aal1 session to exercise privileged RBAC permissions even when the account has a verified MFA factor that has not been used for the session: the Edge JWT middleware (foundJWT() in supabase/functions/_backend/utils/hono_middleware.ts) accepts the JWT without validating its assurance level, and the direct RBAC path (checkPermission()/checkPermissionPg() in supabase/functions/_backend/utils/rbac.ts calling public.rbac_check_permission_direct()) authorizes by user ID without passing or checking the session aal, unlike the public.verify_mfa() control which correctly requires aal2. An attacker who know
Published 2026-09-10
- MediumCVSS 5.5 v3·EPSS 0.3%·Fix available
n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the public OIDC login and callback endpoints completed authentication even when OIDC was not the enabled active authentication method. An Enterprise administrator who had configured and later disabled an identity provider still exposed a working route that could issue valid sessions. The affected logic is packages/cli/src/modules/sso-oidc/oidc.service.ee.ts, including generateLoginUrl and the callback flow that lacked assertOidcLoginEnabled. This issue is fixed in versions 1.123.76, 2.37.7 and 2.38.2.
Published 2026-09-08
- HighCVSS 7.8 v3·EPSS 0.1%·No fix yet
In maybeRemoveInvalidInstallerPackageName of InstallRepository.kt, there is a possible unauthorized app update due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2026-09-08
- HighCVSS 8.1 v3·EPSS 1.5%·No fix yet
An Authentication Bypass vulnerability in Sentry before R10.8.2, R10.7.3 and R10.6.4 allows a remote unauthenticated attacker to gain administrative level access.
Published 2026-09-08
- HighCVSS 7.5 v3·EPSS 0.3%·Fix available
CommServe contained an authentication bypass issue affecting access authorization and information disclosure. Software customers upgrade to resolved maintenance release. Update CommServe.
Published 2026-09-08
- HighCVSS 8.8 v3·EPSS 0.3%·No fix yet
A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). Server-side authorization checks in the web-based management interface are not properly enforced, allowing role-based access control (RBAC) restrictions to be bypassed through manipulation of request data. This could allow an authenticated, low-privileged remote attacker to escalate privileges to an administrative level.
Published 2026-09-08
- CriticalCVSS 9.1 v3·EPSS 0.6%·No fix yet
Authentication bypass using an alternate path or channel in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network.
Published 2026-09-08
- HighCVSS 7.5 v3·EPSS 0.5%·Fix available
fastify versions >= 4.0.0 and before 5.12.2 can route a malformed URL sent under one plugin prefix to the custom not-found handler of a different sibling plugin, and invoke it without the preHandler hook declared for that handler. The internal not-found router for encapsulated handlers dispatches malformed paths through a single shared handler pointer before URL decoding, ignoring the prefix and skipping the selected handler's normal lifecycle. An unauthenticated attacker can therefore reach an authentication-protected private fallback through an unrelated public prefix and read its full response, bypassing the authentication hook and breaking prefix encapsulation. Users should upgrade to fastify 5.12.2 or later.
Published 2026-09-04
- HighCVSS 7.4 v3·EPSS 0.2%·No fix yet
Unauthenticated Broken Authentication in Really Simple SSL <= 9.8.0 versions.
Published 2026-09-03
- CVSS 3.7 v3·EPSS 0.3%·Fix available
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal CAPTCHA Protected Page allows Functionality Bypass. This issue affects CAPTCHA Protected Page versions: from 0.0.0 to 1.0.2.
Published 2026-09-02
- MediumCVSS 4.1 v3·EPSS 0.3%·Fix available
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Disable Login Page allows Functionality Bypass. This issue affects Disable Login Page versions: from 0.0.0 to 1.1.4.
Published 2026-09-02
- HighCVSS 7.4 v3·EPSS 0.2%·No fix yet
Unauthenticated Broken Authentication in RegistrationMagic <= 6.0.9.8 versions.
Published 2026-08-31
- HighCVSS 8.1 v3·EPSS 0.3%·No fix yet
Gophish through 0.12.1 fails to enforce account lockout and password change requirements in the API authentication middleware. Attackers with valid API keys can bypass these security controls and retain full API access even when their account is locked or password change is required.
Published 2026-08-28
- CriticalCVSS 9.8 v3·EPSS 0.7%·No fix yet
Xiiaozet LK100Wt contains an authentication weakness within an administrative service that may allow an attacker to bypass intended access controls and obtain command execution capabilities. Successful exploitation could allow unauthorized interaction with privileged functionality and may lead to complete device compromise.
Published 2026-08-28
- CriticalCVSS 9.3 v4·EPSS 0.5%·No fix yet
A vulnerability allowing an unauthenticated network attacker to coerce SMB authentication from the service account.
Published 2026-08-26
- MediumCVSS 5.5 v3·EPSS 0.2%·Fix available
GitLab has remediated an issue in GitLab EE affecting all versions from 11.3 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain conditions, an authenticated user with project Maintainer permissions could have accessed the terminal of a protected environment they were not authorized to use due to improper authorization checks.
Published 2026-08-26
- HighCVSS 8.1 v3·EPSS 0.2%·No fix yet
In FreeBSD 15.0, the kernel structure used to represent user credentials changed: previously the primary group ID was stored in the first element of the array containing the list of supplementary group IDs, whereas now the primary group ID is stored in a dedicated field. This change was largely internal to the kernel and not user-visible. One function, group_is_primary(), was not properly updated as a part of this transition. This function is used by mac_do to determine the primary group ID of the credential after applying a transition rule, used when the rule target does not explicitly specify a group. As a result, with certain mac_do rules, it is possible for a credential switch to incorrectly set the primary group ID to the ID stored in the first element of the original credential's
Published 2026-08-26
- CriticalCVSS 9.8 v3·EPSS 0.3%·No fix yet
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Internationalization Single Sign-On allows Authentication Bypass. This issue affects Internationalization Single Sign-On versions: from 0.0.0 to 1.8.0.
Published 2026-08-25
- HighCVSS 8.6 v3·EPSS 0.3%·No fix yet
The SMS control function of IE-SR-2TX-WL-4G devices can require a password for SMS commands via the 'Enable Password Authorization' setting. The device increments a retry counter on each failed SMS password attempt; after 5 consecutive failed attempts, SMS password authorization is automatically disabled. An unauthenticated remote attacker who is able to send SMS messages to the device can deliberately trigger this by submitting 5 or more invalid passwords, after which subsequent SMS commands are executed without requiring a password, resulting in potential limited configuration tampering, limited information leakage and potentially full loss of availability.
Published 2026-08-25
- HighCVSS 7.3 v3·EPSS 0.2%·No fix yet
Unauthenticated Broken Authentication in WPLegalPages <= 3.7.0 versions.
Published 2026-08-24
- CriticalCVSS 9.8 v3·EPSS 0.4%·No fix yet
Unauthenticated Broken Authentication in User Registration & Membership Pro <= 5.4.5 versions.
Published 2026-08-20
- HighCVSS 7.6 v3·EPSS 0.4%·No fix yet
Subscriber Broken Authentication in Leyka <= 3.32.3 versions.
Published 2026-08-20
- CriticalKEVCVSS 9.8 v3·EPSS 5.6%·Fix available
Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.
Published 2026-08-19
- HighCVSS 8.8 v3·EPSS 0.3%·No fix yet
4gaBoards is a boards system for realtime project management. Prior to 3.3.8, 4gaBoards is vulnerable to pre-account takeover when registrationEnabled, localRegistrationEnabled, and ssoRegistrationEnabled are enabled and Google, GitHub, Microsoft, or OIDC SSO is configured. The POST /api/register endpoint permits creation of an unverified local account with a victim's email address, and POST /api/access-tokens permits that account to authenticate while isVerified is false. During the victim's first SSO login, server/api/helpers/users/get-create-one-for-github-sso.js, server/api/helpers/users/get-create-one-for-google-sso.js, server/api/helpers/users/get-create-one-for-microsoft-sso.js, and server/api/helpers/users/get-create-one-for-oidc-sso.js find the attacker-controlled account by email
Published 2026-08-18
- HighCVSS 7.1 v3·EPSS 0.2%·No fix yet
NVIDIA NVOS for network switches contains a vulnerability in the secure shell (SSH) server configuration component while PKA-only mode is enabled, where an administrator could inadvertently enable an alternative authentication path. If best practices for replacing the default password as recommended by NVIDIA are not followed, this alternative authentication path might lead to unauthorized access. A successful exploit of this vulnerability might lead to escalation of privileges.
Published 2026-08-18
- MediumCVSS 5.3 v3·EPSS 0.4%·No fix yet
An Authentication Bypass vulnerability exists in EPSON EH-TW5350 EPSON 150075647YWWV110, which could let a remote malicious user cause a Denial of Service via specially crafted series of HTTP..
Published 2026-08-18
- CriticalCVSS 9.1 v4·EPSS 0.5%·No fix yet
Missing authentication in initial setup functionality left exposed until first reboot in GBIF Integrated Publishing Toolkit versions before 3.3.4 allows remote authenticated attackers to gain administrative control via authentication bypass
Published 2026-08-18
- MediumCVSS 6.5 v3·EPSS 0.4%·No fix yet
Unauthenticated Broken Authentication in Flutterwave WooCommerce <= 3.3.0 versions.
Published 2026-08-18
- MediumCVSS 6.5 v3·EPSS 0.3%·No fix yet
Unauthenticated Broken Authentication in Piraeus Bank WooCommerce Payment Gateway 3.2.0 versions.
Published 2026-08-18
- HighCVSS 7.1 v3·EPSS 0.4%·No fix yet
Subscriber Broken Authentication in MWB HubSpot for WooCommerce <= 1.6.7 versions.
Published 2026-08-18
- CriticalCVSS 9.1 v3·EPSS 0.5%·No fix yet
Unauthenticated Broken Authentication in Popup by Supsystic <= 1.13.0 versions.
Published 2026-08-18
- MediumCVSS 6.5 v3·EPSS 0.2%·No fix yet
Unauthenticated Bypass Vulnerability in Contact Form by Supsystic < 1.10.0 versions.
Published 2026-08-18
- HighCVSS 7.5 v3·EPSS 0.3%·No fix yet
Unauthenticated Broken Authentication in Ezoic <= 2.22.11 versions.
Published 2026-08-18
- CriticalCVSS 9.8 v3·EPSS 0.4%·No fix yet
Bastillion fails to properly validate request URI paths in its controller dispatcher, allowing unauthenticated attackers to bypass authentication filters by prefixing requests with arbitrary path segments. Attackers can access administrative controllers to read user listings, create manager accounts, and register managed systems, gaining control over SSH access to the managed fleet.
Published 2026-08-18
- CriticalCVSS 9.1 v3·EPSS 0.3%·Fix available
In JetBrains YouTrack before 2025.3.156085, 2026.1.13913, 2026.2.18112 an unauthenticated attacker could download database backups via shared draft signature
Published 2026-08-17
- CriticalCVSS 9.8 v3·EPSS 0.4%·No fix yet
Unauthenticated Broken Authentication in Cartify <= 1.3.0.1 versions.
Published 2026-08-13
- CriticalCVSS 9.8 v3·EPSS 0.4%·No fix yet
Unauthenticated Broken Authentication in Salon booking system <= 10.30.26 versions.
Published 2026-08-13
- HighCVSS 8.1 v3·EPSS 0.7%·Fix available
A authentication bypass using an alternate path or channel vulnerability in Fortinet FortiManager 7.6.1, FortiManager 7.4.3 through 7.4.5, FortiManager 7.2.5 through 7.2.9, FortiManager Cloud 7.6.1, FortiManager Cloud 7.4.3 through 7.4.5, FortiManager Cloud 7.2.5 through 7.2.9 may allow attacker to improper access control via <insert attack vector here>
Published 2026-08-12
- MediumCVSS 6.8 v3·EPSS 0.2%·No fix yet
The Velociraptor gRPC API has a VFSGetBuffer endpoint which allows reading files from the datastore. To prevent users from reading sensitive files or accessing other orgs, the requested path is prefix checked against a list of denied prefixes. This prefix check can be bypassed allowing a user to access usually denied files. If the user has read permission in the ROOT org, this allows access to other orgs, in which the user may not have permission.
Published 2026-08-11
Free CVE lookup by TridentStack Control, automated patching for Windows, macOS, and Linux fleets. Learn more·Uses NVD data but is not endorsed or certified by the NVD. EPSS scores courtesy of FIRST.org (https://www.first.org/epss). Source: CISA KEV Catalog.