VYPR

CWE-290

Authentication Bypass by Spoofing

BaseIncomplete

Description

This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-21 · CAPEC-22 · CAPEC-459 · CAPEC-461 · CAPEC-473 · CAPEC-476 · CAPEC-59 · CAPEC-60 · CAPEC-667 · CAPEC-94

CVEs mapped to this weakness (677)

page 33 of 34
  • CVE-2026-50755CriJul 21, 2026
    risk 0.00cvss 9.8epss 0.00

    An issue in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to obtain sensitive information via the X-Forwarded-For header value

  • CVE-2026-3183HigJul 21, 2026
    risk 0.00cvss 7.1epss 0.00

    Zohocorp ManageEngine ADSelfService Plus versions before 6524 are vulnerable to Multi Factor Authentication Bypass.

  • CVE-2026-16076MedJul 18, 2026
    risk 0.00cvss 6.3epss 0.00

    A vulnerability has been found in AstrBotDevs AstrBot up to 4.25.5. This issue affects the function OpenApiRoute.chat_send of the file astrbot/dashboard/routes/open_api.py of the component API. Such manipulation of the argument Username leads to authentication bypass by…

  • CVE-2026-62224MedJul 17, 2026
    risk 0.00cvss 5.4epss 0.00

    OpenClaw MS Teams before 2026.5.12 contain an authorization bypass vulnerability where the allowFrom feature binds to mutable display names. Attackers with lower-trust access can perform actions requiring stronger authorization by exploiting the mutable display name binding in…

  • CVE-2026-55652CriJul 15, 2026
    risk 0.00cvss 9.8epss 0.00

    Wekan is open source kanban built with Meteor. Prior to 9.46, header-login with HEADER_LOGIN_TRUSTED_IPS uses getRequestIp() in server/lib/headerLoginAuth.js to trust the client-supplied X-Forwarded-For header before the real socket address, allowing an unauthenticated attacker…

  • CVE-2026-55954CriJul 14, 2026
    risk 0.00cvss epss 0.00

    Authentication Bypass by Spoofing vulnerability in ueberauth ueberauth_apple allows account takeover via unvalidated ID token claims. The Ueberauth.Strategy.Apple.Token.payload/2 function verifies the JWT signature of the callback id_token against Apple's JWKS but does not…

  • CVE-2026-58488MedJul 13, 2026
    risk 0.00cvss epss 0.00

    HedgeDoc is an open source, real-time, collaborative, markdown notes application. Versions prior to 1.11.0 allowed attackers to circumvent the rate-limiting of the /login and /register routes by spoofing IP addresses. HedgeDoc instances checked for CloudFlare's cf-connecting-ip…

  • CVE-2026-61428HigJul 11, 2026
    risk 0.00cvss 7.3epss 0.00

    PraisonAI AgentMail versions before 4.6.78 lack signature verification in webhook mode, allowing unauthenticated attackers to inject messages with spoofed sender addresses. Attackers can POST crafted message.received events to the webhook endpoint to inject arbitrary content…

  • CVE-2026-56675HigJul 10, 2026
    risk 0.00cvss 8.3epss 0.00

    9Router is an AI router & token saver. Prior to 0.5.2, 9router treats loopback requests as trusted and allows /v1/* access without an API key, so a same-host reverse proxy that forwards public traffic to the backend through 127.0.0.1 causes src/dashboardGuard.js to misclassify…

  • CVE-2026-55641HigJul 10, 2026
    risk 0.00cvss 8.2epss 0.00

    9Router is an AI router & token saver. Prior to 0.5.2, 9router determines whether a /v1 LLM proxy request is local by reading the client-controlled Host header, allowing a remote unauthenticated attacker to send Host: localhost and bypass API-key authentication. In the default…

  • CVE-2026-55501HigJul 10, 2026
    risk 0.00cvss 7.3epss 0.00

    9Router is an AI router & token saver. Prior to 0.4.80, the dashboard login rate limiter in src/lib/auth/loginLimiter.js derives the client identity from the attacker-controlled X-Forwarded-For HTTP header, and src/app/api/auth/login/route.js uses that spoofable value for…

  • CVE-2026-8651LowJul 8, 2026
    risk 0.00cvss 3.7epss 0.00

    Limited authentication bypass by spoofing vulnerability in Progress MOVEit Transfer (HTTPS module). This issue affects MOVEit Transfer: before 2025.0.7, from 2025.1.0 before 2025.1.3.

  • CVE-2026-56360MedJul 8, 2026
    risk 0.00cvss 4.0epss 0.00

    n8n before versions 1.123.18 and 2.6.2 fails to verify HMAC-SHA256 signatures on Zendesk webhooks in the ZendeskTrigger node. Attackers who know the webhook URL can send unsigned POST requests to trigger workflows with arbitrary malicious data.

  • CVE-2026-24013CriJul 6, 2026
    risk 0.00cvss 9.1epss 0.01

    Authentication Bypass by Spoofing vulnerability in Apache IoTDB. Certain Thrift RPC query handlers lack strict validation of the sessionId parameter. An attacker can construct requests with a forged sessionId and, without performing openSession authentication, receive valid…

  • CVE-2026-45489MedJul 3, 2026
    risk 0.00cvss 6.5epss 0.00

    Microsoft Edge (Chromium-based) Spoofing Vulnerability

  • CVE-2026-14381MedJul 1, 2026
    risk 0.00cvss 6.5epss 0.00

    Incorrect security UI in WebAppInstalls in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-58593HigJul 1, 2026
    risk 0.00cvss 7.5epss 0.00

    NodeBB does not bind the claimed author of an inbound ActivityPub object to the authenticated remote actor. The inbound middleware verifies the HTTP-signature actor and checks the origin of object.id, but never validates that attributedTo corresponds to the sender. In the object…

  • CVE-2026-24270CriJul 1, 2026
    risk 0.00cvss 9.8epss 0.01

    NVIDIA AIStore framework contains a vulnerability where an attacker could bypass authentication. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, and data tampering.

  • CVE-2026-58399HigJul 1, 2026
    risk 0.00cvss epss 0.01

    @acastellon/auth is an authentication control system for microservices. Versions prior to 2.3.0 appear to allow an unauthenticated authentication bypass in validateToken() through spoofable auth-user and Host request headers. The validateToken middleware contains a…

  • CVE-2026-58370HigJun 30, 2026
    risk 0.00cvss 8.1epss 0.01

    Woodpecker before 3.15.0 matches the ApprovalAllowedUsers bypass list against pipeline.Author. For the GitLab forge driver, pipeline.Author is populated from the git commit author name (commit.author.name) carried in the webhook payload, which is attacker-controlled and not…