VYPR

CWE-290

Authentication Bypass by Spoofing

BaseIncomplete

Description

This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-21 · CAPEC-22 · CAPEC-459 · CAPEC-461 · CAPEC-473 · CAPEC-476 · CAPEC-59 · CAPEC-60 · CAPEC-667 · CAPEC-94

CVEs mapped to this weakness (677)

page 32 of 34
  • CVE-2025-26419LowSep 4, 2025
    risk 0.21cvss 3.3epss 0.00

    In initPhoneSwitch of SystemSettingsFragment.java, there is a possible FRP bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

  • CVE-2025-26428LowSep 4, 2025
    risk 0.21cvss 3.2epss 0.00

    In startLockTaskMode of LockTaskController.java, there is a possible lock screen bypass due to a logic error in the code. This could lead to physical escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

  • CVE-2025-32788MedApr 22, 2025
    risk 0.21cvss 4.3epss 0.00

    OctoPrint provides a web interface for controlling consumer 3D printers. In versions up to and including 1.10.3, OctoPrint has a vulnerability that allows an attacker to bypass the login redirect and directly access the rendered HTML of certain frontend pages. The primary risk…

  • CVE-2024-5812LowJun 11, 2024
    risk 0.21cvss 3.3epss 0.00

    A low severity vulnerability in BIPS has been identified where an attacker with high privileges or a compromised high privilege account can overwrite Read-Only smart rules via a specially crafted API request.

  • CVE-2025-65046LowDec 18, 2025
    risk 0.20cvss 3.1epss 0.00

    Microsoft Edge (Chromium-based) Spoofing Vulnerability

  • CVE-2021-43220LowNov 24, 2021
    risk 0.20cvss 3.1epss 0.01

    Microsoft Edge for iOS Spoofing Vulnerability

  • CVE-2021-42308LowNov 24, 2021
    risk 0.20cvss 3.1epss 0.01

    Microsoft Edge (Chromium-based) Spoofing Vulnerability

  • CVE-2026-56357MedJun 22, 2026
    risk 0.19cvss 4.0epss 0.00

    n8n before 1.123.15 and 2.5.0 contains a webhook forgery vulnerability in the GitHub Webhook Trigger node that fails to implement HMAC-SHA256 signature verification. Attackers who know the webhook URL can send unsigned POST requests to trigger workflows with arbitrary data,…

  • CVE-2026-54478LowJul 22, 2026
    risk 0.17cvss 3.7epss 0.00

    In NLnet Labs Unbound 1.18.0 up to and including 1.25.1, when Unbound listens on a 'proxy-protocol-port' interface with 'answer-cookie: yes', the RFC 9018 server-cookie SipHash is computed over the proxy's wire address instead of the PROXYv2-declared client. One server cookie…

  • CVE-2026-0292LowAug 13, 2026
    risk 0.14cvss epss 0.00

    An authentication bypass vulnerability in the network driver of Palo Alto Networks Prisma® Access Agent on Windows enables a local administrator to bypass security inspection, subsequently allowing them to inject and intercept arbitrary network traffic. The Prisma Access…

  • CVE-2026-39419LowApr 14, 2026
    risk 0.13cvss 3.1epss 0.00

    MaxKB is an open-source AI assistant for enterprise. In versions 2.7.1 and below, an authenticated user can bypass sandbox result validation and spoof tool execution results by exploiting Python frame introspection to read the wrapper's UUID from its bytecode constants, then…

  • CVE-2021-29441HigApr 27, 2021
    risk 0.06cvss 8.6epss 0.70

    Nacos is a platform designed for dynamic service discovery and configuration and service management. In Nacos before version 1.4.1, when configured to use authentication (-Dnacos.core.auth.enabled=true) Nacos uses the AuthFilter servlet filter to enforce authentication. This…

  • CVE-2026-13143MedJul 30, 2026
    risk 0.00cvss 5.3epss 0.00

    The WP Travel WordPress plugin before 11.8.1 does not verify PayPal Instant Payment Notifications through the PayPal post-back handshake before marking a booking paid, allowing unauthenticated attackers to forge a notification that flips an arbitrary pending booking to a paid…

  • CVE-2026-11870MedJul 30, 2026
    risk 0.00cvss 5.4epss 0.00

    The WP Ghost (Hide My WP Ghost) WordPress plugin before 7.0.05 does not verify that client IP information comes from a trusted proxy before trusting attacker-controllable HTTP headers, allowing unauthenticated attackers to spoof their IP address to bypass the WP Ghost (Hide My…

  • CVE-2026-28900MedJul 27, 2026
    risk 0.00cvss 5.5epss 0.00

    A file quarantine bypass was addressed with additional checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. A maliciously crafted ZIP archive may bypass Gatekeeper checks.

  • CVE-2026-28849MedJul 27, 2026
    risk 0.00cvss 5.5epss 0.00

    The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. A maliciously crafted ZIP archive may bypass Gatekeeper checks.

  • CVE-2026-64875MedJul 23, 2026
    risk 0.00cvss 6.5epss 0.00

    Joomla Extension - regularlabs.com - IP spoofing vulnerability in GeoIP extension - GeoIP lookups trusted spoofable forwarded client-IP headers, this could cause GeoIP-rule bypass.

  • CVE-2026-64797HigJul 22, 2026
    risk 0.00cvss 7.5epss 0.00

    Joomla Extension - regularlabs.com - IP spoofing vulnerability in IP login extension - IP Login trusted forwarded client-IP headers without requiring a configured trusted proxy. Attackers could spoof the IP used for automatic login and potentially impersonate mapped accounts.

  • CVE-2026-63683HigJul 22, 2026
    risk 0.00cvss 7.5epss 0.00

    Joomla Extension - regularlabs.com - Client IP spoofing vulnerability in Regular Labs conditions manager - IP and GeoIP conditions trusted spoofable forwarded headers, allowing remote clients to bypass location-based rules.

  • CVE-2026-61217MedJul 21, 2026
    risk 0.00cvss 6.4epss 0.00

    Vulnerability in the Oracle Security Service product of Oracle Fusion Middleware (component: Oracle SSL API). The supported version that is affected is 12.2.1.4.0. Difficult to exploit vulnerability allows low privileged attacker with network access via TLS to compromise…