VYPR

CWE-302

Authentication Bypass by Assumed-Immutable Data

BaseIncomplete

Description

The authentication scheme or implementation uses key data elements that are assumed to be immutable, but can be controlled or modified by the attacker.

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-10 · CAPEC-13 · CAPEC-21 · CAPEC-274 · CAPEC-31 · CAPEC-39 · CAPEC-45 · CAPEC-77

CVEs mapped to this weakness (45)

page 3 of 3
  • CVE-2025-46647MedJul 2, 2025
    risk 0.27cvss 5.3epss 0.00

    A vulnerability of plugin openid-connect in Apache APISIX. This vulnerability will only have an impact if all of the following conditions are met: 1. Use the openid-connect plugin with introspection mode 2. The auth service connected to openid-connect provides services to…

  • CVE-2026-27840MedFeb 26, 2026
    risk 0.21cvss 4.3epss 0.00

    ZITADEL is an open source identity management platform. Starting in version 2.31.0 and prior to versions 3.4.7 and 4.11.0, opaque OIDC access tokens in the v2 format truncated to 80 characters are still considered valid. Zitadel uses a symmetric AES encryption for opaque…

  • CVE-2023-47127MedNov 14, 2023
    risk 0.20cvss 4.2epss 0.01

    TYPO3 is an open source PHP based web content management system released under the GNU GPL. In typo3 installations there are always at least two different sites. Eg. first.example.org and second.example.com. In affected versions a session cookie generated for the first site can…

  • CVE-2026-77508LowAug 26, 2026
    risk 0.16cvss 3.5epss 0.00

    Weblate is a web based localization tool. Prior to 2026.8, an authenticated user can change the account's primary email through PUT or PATCH requests to /api/users/{username}/ without verifying the new address, allowing a later team invitation for that address to be accepted…

  • CVE-2026-48117MedJun 17, 2026
    risk 0.00cvss 6.8epss 0.00

    DroneAware is a drone detection platform. The centralized DroneAware server backing droneaware.io was vulnerable to an account pre-hijacking attack in which an attacker could register an account using a victim's email address with an attacker-controlled password before the…