CVE & CISA-KEV Catalog
Want to know which of these are on your machines? Scan your endpoints with the free CVE scanner, 200 endpoints free.
| Severity | Description | ||||||
|---|---|---|---|---|---|---|---|
| CVE-2026-62367 | High | 7.5 v4 | - | - | -No fix available yet | 2026-10-09 | Vikunja is an open-source self-hosted task management platform. In versions 1.0.0 through 2.3.0, when an administrator enables the per-provider `emailfallback` option on an OpenID Connect provider, Vikunja links an SSO login to a pre-existing local (username+password) account using only the `email` claim from the IdP. The fallback never checks an `email_verified` (or Microsoft `xms_edov`) signal and never requires the matched account's password. An attacker who can obtain a token from the configured issuer carrying a victim's email logs in as that victim with a full session, with no consent or interaction from the victim. Version 2.4.0 fixes the issue. |
| CVE-2026-96336 | High | 7.5 v3 | - | - | -No fix available yet | 2026-10-09 | Authentication Bypass by Spoofing vulnerability in WPMU DEV Forminator forminator allows Identity Spoofing.This issue affects Forminator: from n/a through 1.57.2. |
| CVE-2026-96333 | High | 7.5 v3 | - | - | -No fix available yet | 2026-10-09 | Authentication Bypass by Spoofing vulnerability in Liquid Web / StellarWP GiveWP give allows Identity Spoofing.This issue affects GiveWP: from n/a through 4.16.8.1. |
| CVE-2026-107336 | Medium | 6.5 v3 | 0.2% | - | -No fix available yet | 2026-10-08 | Malcolm's front nginx reverse proxy defines a "Dashboards → Arkime shortcut" location using a case-insensitive regex matcher but a case-sensitive rewrite. A request whose path segment is not exact-lowercase (for example /IDDASH2ARK/...) enters the location (the matcher fires) but evades the rewrite (no redirect is issued), so nginx falls through to the location's proxy_pass to the Arkime backend. That location is the one proxied location in the shipped config that does not include the per-location authentication file, so the request reaches Arkime unauthenticated. The same location also forwards a client-supplied X-Forwarded-User header un-overwritten, and Arkime is configured to trust X-Forwarded-User as the authenticated username — so an unauthenticated network caller can reach the Arkim |
| CVE-2026-107589 | High | 7.5 v3 | 0.1% | - | -No fix available yet | 2026-10-08 | Insufficient job validation for service accounts in Jacamar CI prior to v0.30.0 allows authenticated CI users to generate arbitrary account names. |
| CVE-2026-4894 | Medium | 6.9 v4 | 0.4% | - | -No fix available yet | 2026-10-08 | A vulnerability has been identified regarding insufficient validation in the Frappe Cloud/ERPNext authentication process, which allows multiple email addresses to be accepted by manipulating the email field in the /api/method/press.api.account.signup endpoint. The vulnerability occurs when an unauthenticated remote attacker adds more than one email address. The service processes the entire value as a valid list of recipients and sends the OTP code to all addresses without proper validation of all added emails (only one of them needs to be valid). Exploiting this vulnerability would allow an attacker to: * Obtain the authentication OTP; * Impersonate someone else in the registration process; * Register accounts using other people's email addresses without access to the mailbox; |
| CVE-2026-87663 | High | 7.1 v4 | 0.7% | - | -No fix available yet | 2026-10-08 | An authentication bypass and command injection vulnerability exists in the inter-switch remote execution service of Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. When processing remote command execution IPC frames across the fabric, the receiving switch processes these commands at an elevated processing level without proper verification of transmitted parameters. This allows an attacker on a single fabric-connected switch to escalate privileges and execute arbitrary root commands locally or across other managed fabric members where remote execution functionality is enabled. |
| CVE-2026-87686 | Medium | 5.3 v4 | 0.2% | - | -No fix available yet | 2026-10-08 | An authentication and access control bypass vulnerability exists in the web server management interface of Brocade Fabric OS versions before 10.0.1. The web dispatcher routine evaluates internal management VLAN trust decisions using the client-supplied HTTP host header instead of the actual socket transport layer source IP address. Successful exploitation allows the attacker to bypass IP-filtering access control lists (ACLs) and obtain sensitive device metadata (such as model, serial number, hardware revision, and firmware version) without authentication. |
| CVE-2026-87670 | Medium | 5.1 v4 | 0.1% | - | -No fix available yet | 2026-10-08 | An authorization logic vulnerability exists in the Brocade Fabric OS versions before 10.0.1 REST API gateway. The internal gate guarding restricted management endpoints relies exclusively on client-controlled HTTP headers. An authenticated user with any valid REST session can spoof these headers to gain unauthorized access to internal management endpoints. This allows low-privilege users to view sensitive chassis metadata, hardware memory patrolling state, and firmware integrity audit logs. |
| CVE-2026-92542 | Medium | 6.9 v4 | 0.1% | - | -No fix available yet | 2026-10-07 | The firewall rules which mark VXLAN datagrams for encryption indiscriminately match both authentic VXLAN datagrams sent from the kernel and forged datagrams sent by user processes. Any packet sent from the host network namespace of a Linux Swarm node is encrypted with the overlay-network IPsec parameters which meets the following criteria: - UDP datagram - Destination port is the Swarm data-path port - Datagram starts with a VXLAN header for the VNI of an encrypted overlay network which any running container on the node is connected to |
| CVE-2026-33586 | Medium | 6.3 v4 | 0.1% | - | -No fix available yet | 2026-10-07 | Authenticated users are able to manipulate both the SMTP envelope “Envelope-from” and “From” fields when sending emails through OVH mail servers. Due to OVH's default SPF configuration, which commonly includes include:mx.ovh.com, any authenticated user with a valid OVH email account can send messages that appear to originate from any OVH-hosted domains using the default SPF record. Since the SPF policy explicitly authorizes OVH mail servers (mx.ovh.com) to send mail on behalf of these domains, forged messages successfully pass SPF validation despite not being authorized by the impersonated domain owner. |
| CVE-2026-97146 | Medium | 4.8 v4 | 0.3% | - | -No fix available yet | 2026-10-07 | Apache YuniKorn 1.9.0 and earlier allows bypassing the check for the user annotation by setting a secondary label on the pod. If the pod has the label 'app=yunikorn' the checks limiting the user annotation content are not run. The label is used to identify the YuniKorn application itself in the deployments. The bypass allows any user to specify an arbitrary user info annotation. The arbitrary user information could allow access to a queue that the user normally would not have access to. Quota usage for the queue might be impacted if the application runs in the incorrect queue. User based quota enforcement is also based on the user annotation. User quota tracking could be side stepped even if the application runs in the correct queue. Users are recommended to upgrade to version 1.10.0 |
| CVE-2026-102161 | High | 8.8 v3 | 0.2% | - | -No fix available yet | 2026-10-06 | An unauthenticated attacker located on an adjacent private network (or any attacker routed through a reverse proxy/load balancer that forwards client headers) can forge their source IP address and gain administrative session privileges on the CV-CUE backend. |
| CVE-2026-105863 | Critical | 9.2 v4 | 0.4% | - | Fix available | 2026-10-06 | Payload is a free and open source headless content management system. In versions after 3.0.0 and before 3.90.0, a custom field option that maps a field to a reserved authentication claim name can place unintended values in the authentication token issued at login. This issue is fixed in version 3.90.0. |
| CVE-2026-97308 | Medium | 4.8 v3 | 0.2% | - | -No fix available yet | 2026-10-06 | Unauthenticated Bypass Vulnerability in Login Lockdown <= 2.17 versions. |
| CVE-2026-39772 | Medium | 5.3 v3 | 0.4% | - | -No fix available yet | 2026-10-06 | Unauthenticated Bypass Vulnerability in Captcha by BestWebSoft <= 5.2.8 versions. |
| CVE-2026-105057 | Medium | 5.3 v3 | 0.3% | - | -No fix available yet | 2026-10-06 | Unauthenticated Bypass Vulnerability in Zero Spam <= 5.7.11 versions. |
| CVE-2026-41558 | High | 7.5 v3 | 0.3% | - | -No fix available yet | 2026-10-06 | Subscriber Bypass Vulnerability in WP Migration Plugin DB & Files – WP Synchro <= 1.16.1 versions. |
| CVE-2026-105741 | High | 7.1 v3 | 0.2% | - | -No fix available yet | 2026-10-05 | Langflow is a tool for building and deploying AI-powered agents and workflows. From 1.5.0 until 1.10.3, an IP spoofing vulnerability in the Model Context Protocol (MCP) configuration installation endpoint (POST /api/v1/mcp/project/{project_id}/install) allowed authenticated remote attackers to bypass the "local-only" access restriction. By sending a spoofed X-Forwarded-For: 127.0.0.1 header, an attacker could make the server treat the request as originating from localhost, letting them write/overwrite an MCP client configuration file on the server's filesystem. This vulnerability is fixed in 1.10.3. |
| CVE-2026-105640 | Critical | 9.1 v3 | 0.4% | - | -No fix available yet | 2026-10-05 | Plane is an open-source project management tool. Prior to 1.4.0, Plane trusts email addresses returned by Gitea OAuth and by self-managed GitLab OAuth deployments where email confirmation is disabled, without verifying that the provider authenticated ownership of the address. An attacker can set an OAuth identity's unverified provider email to a victim's address, which Plane matches directly to the victim's existing local account. The attacker can then log in to the victim's Plane account without knowing the victim's password. GitHub, GitLab.com, and Google are not affected because those providers return verified email addresses. This issue is fixed in 1.4.0. |
| CVE-2026-104891 | High | 7.5 v3 | 0.3% | - | Fix available | 2026-10-05 | mppx-condition-gate provides conditional free-access wrappers for mppx payment methods. Prior to @insumermodel/mppx-condition-gate 3.0.0 and @insumermodel/mppx-token-gate 1.0.4, the packages read a wallet address from the client-supplied credential.source, checked whether that public address met configured on-chain conditions, and returned a successful free-access receipt without invoking the wrapped payment verifier or proving that the caller controlled the wallet. An unauthenticated attacker could name any qualifying wallet and obtain content that should require payment, and cached grants could be reused for the configured cache lifetime. The corrected packages prevent free-access authorization unless payer control has been established. These issues are fixed in @insumermodel/mppx-condit |
| CVE-2026-103512 | Medium | 5.3 v4 | 0.4% | - | -No fix available yet | 2026-10-05 | Perforce P4 Search prior to 2026.4.2 trusts a client-supplied address when validating certain authentication requests. An attacker holding a stolen P4 Server ticket can bypass host-based ticket restrictions and trusted-address controls, gaining access to P4 Search as the ticket's owner. |
| CVE-2026-105215 | Critical | 9.1 v3 | 0.3% | - | -No fix available yet | 2026-10-04 | ZITADEL before 3.4.14 and 4.x before 4.16.2 contains an authentication bypass in the hosted Login V1 UI because the 'external account not found' registration endpoint trusts client-supplied external identity fields without a completed IdP callback. Unauthenticated attackers can submit forged IDPConfigID and ExternalUserID values to pre-create an account bound to a victim's external IdP identity, which the victim's later genuine external login then signs into. |
| CVE-2026-104988 | High | 8.1 v3 | 0.2% | - | -No fix available yet | 2026-10-02 | A flaw was found in Dogtag PKI (pki-core). The CMCAuthForEST authentication plugin fails open when an EST fullcmc enrollment request is submitted via BasicAuth without an end-user TLS client certificate. The SSL_CLIENT_CERT session attribute retains the EST subsystem's agent certificate, which causes downstream authorization checks to treat the request as agent-privileged. An authenticated EST user can exploit this to obtain CA-signed certificates with arbitrary subject names. |
| CVE-2026-94422 | High | 8.8 v3 | 0.7% | - | Fix available | 2026-10-02 | An incorrect implementation of message filtering in xdg-dbus-proxy versions before 0.1.9 allows an attacker to bypass the intended message filtering on the D-Bus session bus by setting a reply serial number on non-reply messages. A malicious or compromised Flatpak app could use this to achieve arbitrary code execution outside its sandbox. xdg-dbus-proxy was designed to be part of the sandbox boundary for Flatpak, but it is released as a separate project and is sometimes used by other app frameworks such as Firejail. |
| CVE-2026-104733 | High | 7.4 v4 | 0.2% | - | Fix available | 2026-10-02 | User Impersonation in ProcessOnes XMMP Server ejabberd <= 26.04 allows an attacker to impersonate arbitrary users via unvalidated authzid parameter in SASL-PLAIN mechanism. |
| CVE-2026-104445 | High | 8.2 v3 | 0.4% | - | -No fix available yet | 2026-10-02 | YesWiki before 4.6.7 contains an authentication bypass vulnerability in the ActivityPub inbox that fails to bind the verified HTTP signature signer to the activity actor. Unauthenticated attackers with any ActivityPub keypair can send signed Delete or Update activities referencing a mirrored entry's sourceUrl to delete or overwrite other actors' federated entries. |
| CVE-2026-103347 | Medium | 5.3 v3 | 0.2% | - | -No fix available yet | 2026-10-01 | Unauthenticated Bypass Vulnerability in hCaptcha for WP <= 5.3.0 versions. |
| CVE-2026-103397 | Medium | 5.6 v3 | 0.2% | - | -No fix available yet | 2026-09-30 | OpenSave before 2.4.0-beta.1 fails to validate sender identity in WAN relay requests, allowing unpaired room members to impersonate paired devices by spoofing the RelayMessage From field. Attackers who know the room code can join, read paired peer identifiers from announcements, and send forged requests to access protected sync routes including save data, snapshots, and file operations. |
| CVE-2026-97274 | Critical | 9.8 v3 | 0.3% | - | -No fix available yet | 2026-09-30 | Unauthenticated Bypass Vulnerability in OAuth Single Sign On – SSO (OAuth Client) <= 7.1.2 versions. |
| CVE-2026-97249 | Medium | 5.3 v3 | 0.2% | - | -No fix available yet | 2026-09-30 | Unauthenticated Bypass Vulnerability in Paid Member Subscriptions <= 3.0.9 versions. |
| CVE-2026-96825 | Medium | 4.2 v3 | 0.2% | - | -No fix available yet | 2026-09-30 | Subscriber Bypass Vulnerability in All In One WP Security & Firewall <= 5.4.8 versions. |
| CVE-2026-92899 | Medium | 4.8 v3 | 0.5% | - | Fix available | 2026-09-30 | Apache WSS4J remembers the Nonce of each UsernameToken it accepts, so a captured token cannot be reused. It stored the Nonce as raw base64 text, but authentication decodes that text and uses the bytes.The same bytes can be written as base64 in several ways. An attacker who captured an authenticated request could re-send it with a space added to the Nonce: the password digest still verified, but the token no longer matched the remembered one, so the replay was accepted. Since a UsernameToken does not cover the message body, the captured token could then be reused on requests of the attacker's choosing until it expired. Affects deployments with a nonce replay cache configured, as Apache CXF has by default, and only tokens using a password digest. The cache is now keyed on the decoded Nonce. |
| CVE-2026-101280 | High | 7.3 v3 | 0.4% | - | -No fix available yet | 2026-09-29 | A vulnerability was detected in Trusted Domain Project OpenDMARC up to 1.4.2. Affected is the function opendmarc_policy_query_dmarc of the component Multi-Record Set Handler. The manipulation results in authentication bypass by spoofing. The attack can be executed remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. |
| CVE-2026-93538 | High | 7.1 v3 | 0.2% | - | Fix available | 2026-09-28 | A cross-tenant authorization issue was discovered in SUSE Rancher Fleet. During agent-initiated cluster registration, cluster labels supplied by the registering agent, including labels in the reserved management.cattle.io/ namespace such as the cluster display name label, were applied to the resulting upstream Cluster object. Because Fleet resolves GitRepo and Bundle targets from those cluster labels, a party able to register a cluster into a Fleet workspace namespace shared with other tenants could cause its own cluster to satisfy targeting rules that administrators intended for a different cluster. This affects SUSE Rancher Fleet 0.16 before 0.16.1, 0.15 before 0.15.6, 0.14 before 0.14.10, 0.13 before 0.13.15, 0.12 before 0.12.19 and older versions. |
| CVE-2026-100390 | High | 7.4 v3 | 0.3% | - | -No fix available yet | 2026-09-25 | Zoraxy versions 3.2.3 through 3.3.4 fail to properly parse IPv6 addresses in the RemoteAddr field when setting forwarded headers. Unauthenticated attackers connecting over IPv6 can supply arbitrary X-Forwarded-For values to spoof their source IP and bypass authorization provider IP-based access controls. |
| CVE-2026-84465 | High | 7.1 v4 | 0.1% | - | -No fix available yet | 2026-09-25 | Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, when Zammad checks the digital signature on an incoming S/MIME-signed email, it does not verify that the signing certificate is genuinely trusted, it only checks whether a certificate with a matching name is already stored in the system. An attacker can create their own certificate using the name of a real, previously trusted sender and use it to send a forged email. Zammad will display that email with the same "validly signed" indicator as a genuine message from the real sender, even though the attacker never had access to that sender's actual certificate or private key. This issue is fixed in version 7.1.2. |
| CVE-2026-94416 | Medium | 6.8 v3 | 0.5% | - | -No fix available yet | 2026-09-24 | An authorization bypass was found in the Ansible Automation Platform (AAP) gateway. The gateway API allows an authenticated administrator to create a new service key for the Controller service cluster. Because service-key creation is not restricted to the installer-provisioned provisioning path, an administrator-issued key is cryptographically indistinguishable from a legitimate one and can be used to forge a service-authentication token that impersonates the Controller service. Combined with the gateway OIDC workload-identity endpoint (enabled via FEATURE_OIDC_WORKLOAD_IDENTITY_ENABLED), the attacker can drive the gateway to sign Workload Identity Tokens (WITs) for arbitrary Controller workloads. A downstream resource server such as HashiCorp Vault that trusts the gateway OIDC key will ac |
| CVE-2026-95524 | Medium | 5.3 v3 | 0.3% | - | -No fix available yet | 2026-09-23 | Unauthenticated Bypass Vulnerability in WP User Frontend <= 4.3.11 versions. |
| CVE-2026-95523 | Medium | 6.5 v3 | 0.3% | - | -No fix available yet | 2026-09-23 | Subscriber Bypass Vulnerability in WP User Frontend <= 4.3.11 versions. |
| CVE-2026-94457 | Medium | 4.8 v3 | 0.2% | - | -No fix available yet | 2026-09-23 | Unauthenticated Bypass Vulnerability in Captcha Code <= 3.32 versions. |
| CVE-2026-93511 | Medium | 5.3 v3 | 0.2% | - | -No fix available yet | 2026-09-23 | The Premium Packages WordPress plugin before 7.2.1 does not verify PayPal's webhook signature before processing payment and subscription notifications, allowing unauthenticated attackers to forge payment confirmations and subscription-cancellation events against any order whose transaction id they know. |
| CVE-2026-92929 | Medium | 5.3 v3 | 0.4% | - | -No fix available yet | 2026-09-23 | OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 trusts an X-Forwarded-For header supplied by an arbitrary client when determining the request source address. An unauthenticated remote attacker can spoof a loopback address to bypass local-connection-only security controls exposed on the affected non-TLS web interfaces and disclose configuration information. The underlying design has been present since at least firmware 2.2.3.4. Upgrade to version 3.5.4. |
| CVE-2026-37604 | Medium | 6.5 v3 | 0.4% | - | -No fix available yet | 2026-09-22 | pH7Software pH7Builder (pH7 Social Dating CMS) through 18.2.0 resolves the client IP address in _protected/framework/Ip/Ip.class.php from the HTTP_CLIENT_IP and HTTP_X_FORWARDED_FOR headers without verifying the request comes from a trusted proxy. Because the admin login attempt counter and lockout are keyed on this value, a remote unauthenticated attacker bypasses IP-based throttling by sending a different X-Forwarded-For value per request |
| CVE-2026-55210 | High | 7.4 v3 | 0.5% | - | -No fix available yet | 2026-09-21 | Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.2, Joplin Server's UserModel.ssoLogin() returns an existing account matched by an IdP-asserted email without checking the account's is_external flag. In deployments using mixed local and SAML authentication, an attacker whose IdP session can assert a local user's email can pass POST /api/saml, receive a session for that local account, and access or modify the victim's notes, files, and settings without knowing the local password. This issue is fixed in version 3.7.2. |
| CVE-2026-63329 | Medium | 4.9 v3 | 0.3% | - | -No fix available yet | 2026-09-21 | Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.25.6, copy_server_request in warpgate-protocol-http/src/proxy.rs forwards a client-supplied x-warpgate-username header before inject_own_headers appends the authenticated username. Because the request builder preserves repeated values, a proxied backend that trusts the first x-warpgate-username value can authorize an authenticated attacker as another user. The same forwarding policy also accepts the reserved x-warpgate-authentication-type header, and warpgate-common/src/http_headers.rs does not exclude either reserved identity header. This issue is fixed in version 0.25.6. |
| CVE-2026-62987 | Medium | 5.8 v3 | 0.2% | - | -No fix available yet | 2026-09-21 | Fabio is an HTTP(S) and TCP router for deploying applications managed by consul. From 1.6.6 until 1.7.2, the CVE-2025-48865 fix in proxy/http_headers.go uses protectHeaders for a hardcoded set of forwarded headers but omits the operator-configured ClientIPHeader, TLSHeader, and RequestID names. In proxy/http_proxy.go, HTTPProxy.ServeHTTP calls addHeaders to set these trust headers before Go ReverseProxy processes the inbound Connection header, allowing an unauthenticated client to name and remove the configured headers before the request reaches the backend. Deployments that enable the corresponding proxy.header options can therefore lose client-IP, TLS-termination, or request-correlation signals used by backend authorization and auditing; the options are empty by default, and the hardcode |
| CVE-2026-85751 | Critical | 9.8 v3 | 0.6% | - | -No fix available yet | 2026-09-21 | Mailu is a mail server distributed as a set of Docker images. From Mailu 2.0 until 2024.06.55 and prior to Mailu helm-charts 2.7.3, deployments with PROXY_AUTH_WHITELIST configured but REAL_IP_HEADER unset trusted a client-controlled X-Forwarded-By header for header-based proxy authentication. The proxy_hide_header directive in the nginx template at core/nginx/conf/proxy.conf hid the header from upstream responses but did not overwrite the incoming request value in this configuration. An unauthenticated remote attacker could therefore spoof the trusted proxy identity and bypass authentication. This issue is fixed in Mailu 2024.06.55 and Mailu helm-charts 2.7.3. |
| CVE-2026-61682 | Critical | 9.9 v3 | 0.4% | - | -No fix available yet | 2026-09-18 | kcp is a Kubernetes-like control plane for form-factors and use-cases beyond Kubernetes and container workloads. Prior to 0.31.4 and 0.32.2, the kcp front-proxy does not remove inbound X-Remote-User, X-Remote-Group, or X-Remote-Extra-* identity headers before forwarding requests to shards. Any authenticated tenant can inject X-Remote-Group: system:masters, authorization.kcp.io/warrant, authentication.kcp.io/scopes, or a group used for per-workspace required-group gating, and the shard trusts these values as authenticated identity assertions. This allows cross-workspace impersonation, authorization bypass, and arbitrary reading, writing, or deletion of resources, secrets, RBAC data, APIExports, APIBindings, and LogicalClusters. This issue is fixed in versions 0.31.4 and 0.32.2. |
| CVE-2026-85511 | Medium | 4.2 v3 | 0.3% | - | Fix available | 2026-09-18 | A flaw was found in EAP's Elytron. An EAP application whose security domain is backed by an Elytron token-realm with oauth2-introspection would allow parameter substitution due to missing URL encoding. |
- HighCVSS 7.5 v4·EPSS -·No fix yet
Vikunja is an open-source self-hosted task management platform. In versions 1.0.0 through 2.3.0, when an administrator enables the per-provider `emailfallback` option on an OpenID Connect provider, Vikunja links an SSO login to a pre-existing local (username+password) account using only the `email` claim from the IdP. The fallback never checks an `email_verified` (or Microsoft `xms_edov`) signal and never requires the matched account's password. An attacker who can obtain a token from the configured issuer carrying a victim's email logs in as that victim with a full session, with no consent or interaction from the victim. Version 2.4.0 fixes the issue.
Published 2026-10-09
- HighCVSS 7.5 v3·EPSS -·No fix yet
Authentication Bypass by Spoofing vulnerability in WPMU DEV Forminator forminator allows Identity Spoofing.This issue affects Forminator: from n/a through 1.57.2.
Published 2026-10-09
- HighCVSS 7.5 v3·EPSS -·No fix yet
Authentication Bypass by Spoofing vulnerability in Liquid Web / StellarWP GiveWP give allows Identity Spoofing.This issue affects GiveWP: from n/a through 4.16.8.1.
Published 2026-10-09
- MediumCVSS 6.5 v3·EPSS 0.2%·No fix yet
Malcolm's front nginx reverse proxy defines a "Dashboards → Arkime shortcut" location using a case-insensitive regex matcher but a case-sensitive rewrite. A request whose path segment is not exact-lowercase (for example /IDDASH2ARK/...) enters the location (the matcher fires) but evades the rewrite (no redirect is issued), so nginx falls through to the location's proxy_pass to the Arkime backend. That location is the one proxied location in the shipped config that does not include the per-location authentication file, so the request reaches Arkime unauthenticated. The same location also forwards a client-supplied X-Forwarded-User header un-overwritten, and Arkime is configured to trust X-Forwarded-User as the authenticated username — so an unauthenticated network caller can reach the Arkim
Published 2026-10-08
- HighCVSS 7.5 v3·EPSS 0.1%·No fix yet
Insufficient job validation for service accounts in Jacamar CI prior to v0.30.0 allows authenticated CI users to generate arbitrary account names.
Published 2026-10-08
- MediumCVSS 6.9 v4·EPSS 0.4%·No fix yet
A vulnerability has been identified regarding insufficient validation in the Frappe Cloud/ERPNext authentication process, which allows multiple email addresses to be accepted by manipulating the email field in the /api/method/press.api.account.signup endpoint. The vulnerability occurs when an unauthenticated remote attacker adds more than one email address. The service processes the entire value as a valid list of recipients and sends the OTP code to all addresses without proper validation of all added emails (only one of them needs to be valid). Exploiting this vulnerability would allow an attacker to: * Obtain the authentication OTP; * Impersonate someone else in the registration process; * Register accounts using other people's email addresses without access to the mailbox;
Published 2026-10-08
- HighCVSS 7.1 v4·EPSS 0.7%·No fix yet
An authentication bypass and command injection vulnerability exists in the inter-switch remote execution service of Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. When processing remote command execution IPC frames across the fabric, the receiving switch processes these commands at an elevated processing level without proper verification of transmitted parameters. This allows an attacker on a single fabric-connected switch to escalate privileges and execute arbitrary root commands locally or across other managed fabric members where remote execution functionality is enabled.
Published 2026-10-08
- MediumCVSS 5.3 v4·EPSS 0.2%·No fix yet
An authentication and access control bypass vulnerability exists in the web server management interface of Brocade Fabric OS versions before 10.0.1. The web dispatcher routine evaluates internal management VLAN trust decisions using the client-supplied HTTP host header instead of the actual socket transport layer source IP address. Successful exploitation allows the attacker to bypass IP-filtering access control lists (ACLs) and obtain sensitive device metadata (such as model, serial number, hardware revision, and firmware version) without authentication.
Published 2026-10-08
- MediumCVSS 5.1 v4·EPSS 0.1%·No fix yet
An authorization logic vulnerability exists in the Brocade Fabric OS versions before 10.0.1 REST API gateway. The internal gate guarding restricted management endpoints relies exclusively on client-controlled HTTP headers. An authenticated user with any valid REST session can spoof these headers to gain unauthorized access to internal management endpoints. This allows low-privilege users to view sensitive chassis metadata, hardware memory patrolling state, and firmware integrity audit logs.
Published 2026-10-08
- MediumCVSS 6.9 v4·EPSS 0.1%·No fix yet
The firewall rules which mark VXLAN datagrams for encryption indiscriminately match both authentic VXLAN datagrams sent from the kernel and forged datagrams sent by user processes. Any packet sent from the host network namespace of a Linux Swarm node is encrypted with the overlay-network IPsec parameters which meets the following criteria: - UDP datagram - Destination port is the Swarm data-path port - Datagram starts with a VXLAN header for the VNI of an encrypted overlay network which any running container on the node is connected to
Published 2026-10-07
- MediumCVSS 6.3 v4·EPSS 0.1%·No fix yet
Authenticated users are able to manipulate both the SMTP envelope “Envelope-from” and “From” fields when sending emails through OVH mail servers. Due to OVH's default SPF configuration, which commonly includes include:mx.ovh.com, any authenticated user with a valid OVH email account can send messages that appear to originate from any OVH-hosted domains using the default SPF record. Since the SPF policy explicitly authorizes OVH mail servers (mx.ovh.com) to send mail on behalf of these domains, forged messages successfully pass SPF validation despite not being authorized by the impersonated domain owner.
Published 2026-10-07
- MediumCVSS 4.8 v4·EPSS 0.3%·No fix yet
Apache YuniKorn 1.9.0 and earlier allows bypassing the check for the user annotation by setting a secondary label on the pod. If the pod has the label 'app=yunikorn' the checks limiting the user annotation content are not run. The label is used to identify the YuniKorn application itself in the deployments. The bypass allows any user to specify an arbitrary user info annotation. The arbitrary user information could allow access to a queue that the user normally would not have access to. Quota usage for the queue might be impacted if the application runs in the incorrect queue. User based quota enforcement is also based on the user annotation. User quota tracking could be side stepped even if the application runs in the correct queue. Users are recommended to upgrade to version 1.10.0
Published 2026-10-07
- HighCVSS 8.8 v3·EPSS 0.2%·No fix yet
An unauthenticated attacker located on an adjacent private network (or any attacker routed through a reverse proxy/load balancer that forwards client headers) can forge their source IP address and gain administrative session privileges on the CV-CUE backend.
Published 2026-10-06
- CriticalCVSS 9.2 v4·EPSS 0.4%·Fix available
Payload is a free and open source headless content management system. In versions after 3.0.0 and before 3.90.0, a custom field option that maps a field to a reserved authentication claim name can place unintended values in the authentication token issued at login. This issue is fixed in version 3.90.0.
Published 2026-10-06
- MediumCVSS 4.8 v3·EPSS 0.2%·No fix yet
Unauthenticated Bypass Vulnerability in Login Lockdown <= 2.17 versions.
Published 2026-10-06
- MediumCVSS 5.3 v3·EPSS 0.4%·No fix yet
Unauthenticated Bypass Vulnerability in Captcha by BestWebSoft <= 5.2.8 versions.
Published 2026-10-06
- MediumCVSS 5.3 v3·EPSS 0.3%·No fix yet
Unauthenticated Bypass Vulnerability in Zero Spam <= 5.7.11 versions.
Published 2026-10-06
- HighCVSS 7.5 v3·EPSS 0.3%·No fix yet
Subscriber Bypass Vulnerability in WP Migration Plugin DB & Files – WP Synchro <= 1.16.1 versions.
Published 2026-10-06
- HighCVSS 7.1 v3·EPSS 0.2%·No fix yet
Langflow is a tool for building and deploying AI-powered agents and workflows. From 1.5.0 until 1.10.3, an IP spoofing vulnerability in the Model Context Protocol (MCP) configuration installation endpoint (POST /api/v1/mcp/project/{project_id}/install) allowed authenticated remote attackers to bypass the "local-only" access restriction. By sending a spoofed X-Forwarded-For: 127.0.0.1 header, an attacker could make the server treat the request as originating from localhost, letting them write/overwrite an MCP client configuration file on the server's filesystem. This vulnerability is fixed in 1.10.3.
Published 2026-10-05
- CriticalCVSS 9.1 v3·EPSS 0.4%·No fix yet
Plane is an open-source project management tool. Prior to 1.4.0, Plane trusts email addresses returned by Gitea OAuth and by self-managed GitLab OAuth deployments where email confirmation is disabled, without verifying that the provider authenticated ownership of the address. An attacker can set an OAuth identity's unverified provider email to a victim's address, which Plane matches directly to the victim's existing local account. The attacker can then log in to the victim's Plane account without knowing the victim's password. GitHub, GitLab.com, and Google are not affected because those providers return verified email addresses. This issue is fixed in 1.4.0.
Published 2026-10-05
- HighCVSS 7.5 v3·EPSS 0.3%·Fix available
mppx-condition-gate provides conditional free-access wrappers for mppx payment methods. Prior to @insumermodel/mppx-condition-gate 3.0.0 and @insumermodel/mppx-token-gate 1.0.4, the packages read a wallet address from the client-supplied credential.source, checked whether that public address met configured on-chain conditions, and returned a successful free-access receipt without invoking the wrapped payment verifier or proving that the caller controlled the wallet. An unauthenticated attacker could name any qualifying wallet and obtain content that should require payment, and cached grants could be reused for the configured cache lifetime. The corrected packages prevent free-access authorization unless payer control has been established. These issues are fixed in @insumermodel/mppx-condit
Published 2026-10-05
- MediumCVSS 5.3 v4·EPSS 0.4%·No fix yet
Perforce P4 Search prior to 2026.4.2 trusts a client-supplied address when validating certain authentication requests. An attacker holding a stolen P4 Server ticket can bypass host-based ticket restrictions and trusted-address controls, gaining access to P4 Search as the ticket's owner.
Published 2026-10-05
- CriticalCVSS 9.1 v3·EPSS 0.3%·No fix yet
ZITADEL before 3.4.14 and 4.x before 4.16.2 contains an authentication bypass in the hosted Login V1 UI because the 'external account not found' registration endpoint trusts client-supplied external identity fields without a completed IdP callback. Unauthenticated attackers can submit forged IDPConfigID and ExternalUserID values to pre-create an account bound to a victim's external IdP identity, which the victim's later genuine external login then signs into.
Published 2026-10-04
- HighCVSS 8.1 v3·EPSS 0.2%·No fix yet
A flaw was found in Dogtag PKI (pki-core). The CMCAuthForEST authentication plugin fails open when an EST fullcmc enrollment request is submitted via BasicAuth without an end-user TLS client certificate. The SSL_CLIENT_CERT session attribute retains the EST subsystem's agent certificate, which causes downstream authorization checks to treat the request as agent-privileged. An authenticated EST user can exploit this to obtain CA-signed certificates with arbitrary subject names.
Published 2026-10-02
- HighCVSS 8.8 v3·EPSS 0.7%·Fix available
An incorrect implementation of message filtering in xdg-dbus-proxy versions before 0.1.9 allows an attacker to bypass the intended message filtering on the D-Bus session bus by setting a reply serial number on non-reply messages. A malicious or compromised Flatpak app could use this to achieve arbitrary code execution outside its sandbox. xdg-dbus-proxy was designed to be part of the sandbox boundary for Flatpak, but it is released as a separate project and is sometimes used by other app frameworks such as Firejail.
Published 2026-10-02
- HighCVSS 7.4 v4·EPSS 0.2%·Fix available
User Impersonation in ProcessOnes XMMP Server ejabberd <= 26.04 allows an attacker to impersonate arbitrary users via unvalidated authzid parameter in SASL-PLAIN mechanism.
Published 2026-10-02
- HighCVSS 8.2 v3·EPSS 0.4%·No fix yet
YesWiki before 4.6.7 contains an authentication bypass vulnerability in the ActivityPub inbox that fails to bind the verified HTTP signature signer to the activity actor. Unauthenticated attackers with any ActivityPub keypair can send signed Delete or Update activities referencing a mirrored entry's sourceUrl to delete or overwrite other actors' federated entries.
Published 2026-10-02
- MediumCVSS 5.3 v3·EPSS 0.2%·No fix yet
Unauthenticated Bypass Vulnerability in hCaptcha for WP <= 5.3.0 versions.
Published 2026-10-01
- MediumCVSS 5.6 v3·EPSS 0.2%·No fix yet
OpenSave before 2.4.0-beta.1 fails to validate sender identity in WAN relay requests, allowing unpaired room members to impersonate paired devices by spoofing the RelayMessage From field. Attackers who know the room code can join, read paired peer identifiers from announcements, and send forged requests to access protected sync routes including save data, snapshots, and file operations.
Published 2026-09-30
- CriticalCVSS 9.8 v3·EPSS 0.3%·No fix yet
Unauthenticated Bypass Vulnerability in OAuth Single Sign On – SSO (OAuth Client) <= 7.1.2 versions.
Published 2026-09-30
- MediumCVSS 5.3 v3·EPSS 0.2%·No fix yet
Unauthenticated Bypass Vulnerability in Paid Member Subscriptions <= 3.0.9 versions.
Published 2026-09-30
- MediumCVSS 4.2 v3·EPSS 0.2%·No fix yet
Subscriber Bypass Vulnerability in All In One WP Security & Firewall <= 5.4.8 versions.
Published 2026-09-30
- MediumCVSS 4.8 v3·EPSS 0.5%·Fix available
Apache WSS4J remembers the Nonce of each UsernameToken it accepts, so a captured token cannot be reused. It stored the Nonce as raw base64 text, but authentication decodes that text and uses the bytes.The same bytes can be written as base64 in several ways. An attacker who captured an authenticated request could re-send it with a space added to the Nonce: the password digest still verified, but the token no longer matched the remembered one, so the replay was accepted. Since a UsernameToken does not cover the message body, the captured token could then be reused on requests of the attacker's choosing until it expired. Affects deployments with a nonce replay cache configured, as Apache CXF has by default, and only tokens using a password digest. The cache is now keyed on the decoded Nonce.
Published 2026-09-30
- HighCVSS 7.3 v3·EPSS 0.4%·No fix yet
A vulnerability was detected in Trusted Domain Project OpenDMARC up to 1.4.2. Affected is the function opendmarc_policy_query_dmarc of the component Multi-Record Set Handler. The manipulation results in authentication bypass by spoofing. The attack can be executed remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Published 2026-09-29
- HighCVSS 7.1 v3·EPSS 0.2%·Fix available
A cross-tenant authorization issue was discovered in SUSE Rancher Fleet. During agent-initiated cluster registration, cluster labels supplied by the registering agent, including labels in the reserved management.cattle.io/ namespace such as the cluster display name label, were applied to the resulting upstream Cluster object. Because Fleet resolves GitRepo and Bundle targets from those cluster labels, a party able to register a cluster into a Fleet workspace namespace shared with other tenants could cause its own cluster to satisfy targeting rules that administrators intended for a different cluster. This affects SUSE Rancher Fleet 0.16 before 0.16.1, 0.15 before 0.15.6, 0.14 before 0.14.10, 0.13 before 0.13.15, 0.12 before 0.12.19 and older versions.
Published 2026-09-28
- HighCVSS 7.4 v3·EPSS 0.3%·No fix yet
Zoraxy versions 3.2.3 through 3.3.4 fail to properly parse IPv6 addresses in the RemoteAddr field when setting forwarded headers. Unauthenticated attackers connecting over IPv6 can supply arbitrary X-Forwarded-For values to spoof their source IP and bypass authorization provider IP-based access controls.
Published 2026-09-25
- HighCVSS 7.1 v4·EPSS 0.1%·No fix yet
Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, when Zammad checks the digital signature on an incoming S/MIME-signed email, it does not verify that the signing certificate is genuinely trusted, it only checks whether a certificate with a matching name is already stored in the system. An attacker can create their own certificate using the name of a real, previously trusted sender and use it to send a forged email. Zammad will display that email with the same "validly signed" indicator as a genuine message from the real sender, even though the attacker never had access to that sender's actual certificate or private key. This issue is fixed in version 7.1.2.
Published 2026-09-25
- MediumCVSS 6.8 v3·EPSS 0.5%·No fix yet
An authorization bypass was found in the Ansible Automation Platform (AAP) gateway. The gateway API allows an authenticated administrator to create a new service key for the Controller service cluster. Because service-key creation is not restricted to the installer-provisioned provisioning path, an administrator-issued key is cryptographically indistinguishable from a legitimate one and can be used to forge a service-authentication token that impersonates the Controller service. Combined with the gateway OIDC workload-identity endpoint (enabled via FEATURE_OIDC_WORKLOAD_IDENTITY_ENABLED), the attacker can drive the gateway to sign Workload Identity Tokens (WITs) for arbitrary Controller workloads. A downstream resource server such as HashiCorp Vault that trusts the gateway OIDC key will ac
Published 2026-09-24
- MediumCVSS 5.3 v3·EPSS 0.3%·No fix yet
Unauthenticated Bypass Vulnerability in WP User Frontend <= 4.3.11 versions.
Published 2026-09-23
- MediumCVSS 6.5 v3·EPSS 0.3%·No fix yet
Subscriber Bypass Vulnerability in WP User Frontend <= 4.3.11 versions.
Published 2026-09-23
- MediumCVSS 4.8 v3·EPSS 0.2%·No fix yet
Unauthenticated Bypass Vulnerability in Captcha Code <= 3.32 versions.
Published 2026-09-23
- MediumCVSS 5.3 v3·EPSS 0.2%·No fix yet
The Premium Packages WordPress plugin before 7.2.1 does not verify PayPal's webhook signature before processing payment and subscription notifications, allowing unauthenticated attackers to forge payment confirmations and subscription-cancellation events against any order whose transaction id they know.
Published 2026-09-23
- MediumCVSS 5.3 v3·EPSS 0.4%·No fix yet
OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 trusts an X-Forwarded-For header supplied by an arbitrary client when determining the request source address. An unauthenticated remote attacker can spoof a loopback address to bypass local-connection-only security controls exposed on the affected non-TLS web interfaces and disclose configuration information. The underlying design has been present since at least firmware 2.2.3.4. Upgrade to version 3.5.4.
Published 2026-09-23
- MediumCVSS 6.5 v3·EPSS 0.4%·No fix yet
pH7Software pH7Builder (pH7 Social Dating CMS) through 18.2.0 resolves the client IP address in _protected/framework/Ip/Ip.class.php from the HTTP_CLIENT_IP and HTTP_X_FORWARDED_FOR headers without verifying the request comes from a trusted proxy. Because the admin login attempt counter and lockout are keyed on this value, a remote unauthenticated attacker bypasses IP-based throttling by sending a different X-Forwarded-For value per request
Published 2026-09-22
- HighCVSS 7.4 v3·EPSS 0.5%·No fix yet
Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.2, Joplin Server's UserModel.ssoLogin() returns an existing account matched by an IdP-asserted email without checking the account's is_external flag. In deployments using mixed local and SAML authentication, an attacker whose IdP session can assert a local user's email can pass POST /api/saml, receive a session for that local account, and access or modify the victim's notes, files, and settings without knowing the local password. This issue is fixed in version 3.7.2.
Published 2026-09-21
- MediumCVSS 4.9 v3·EPSS 0.3%·No fix yet
Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.25.6, copy_server_request in warpgate-protocol-http/src/proxy.rs forwards a client-supplied x-warpgate-username header before inject_own_headers appends the authenticated username. Because the request builder preserves repeated values, a proxied backend that trusts the first x-warpgate-username value can authorize an authenticated attacker as another user. The same forwarding policy also accepts the reserved x-warpgate-authentication-type header, and warpgate-common/src/http_headers.rs does not exclude either reserved identity header. This issue is fixed in version 0.25.6.
Published 2026-09-21
- MediumCVSS 5.8 v3·EPSS 0.2%·No fix yet
Fabio is an HTTP(S) and TCP router for deploying applications managed by consul. From 1.6.6 until 1.7.2, the CVE-2025-48865 fix in proxy/http_headers.go uses protectHeaders for a hardcoded set of forwarded headers but omits the operator-configured ClientIPHeader, TLSHeader, and RequestID names. In proxy/http_proxy.go, HTTPProxy.ServeHTTP calls addHeaders to set these trust headers before Go ReverseProxy processes the inbound Connection header, allowing an unauthenticated client to name and remove the configured headers before the request reaches the backend. Deployments that enable the corresponding proxy.header options can therefore lose client-IP, TLS-termination, or request-correlation signals used by backend authorization and auditing; the options are empty by default, and the hardcode
Published 2026-09-21
- CriticalCVSS 9.8 v3·EPSS 0.6%·No fix yet
Mailu is a mail server distributed as a set of Docker images. From Mailu 2.0 until 2024.06.55 and prior to Mailu helm-charts 2.7.3, deployments with PROXY_AUTH_WHITELIST configured but REAL_IP_HEADER unset trusted a client-controlled X-Forwarded-By header for header-based proxy authentication. The proxy_hide_header directive in the nginx template at core/nginx/conf/proxy.conf hid the header from upstream responses but did not overwrite the incoming request value in this configuration. An unauthenticated remote attacker could therefore spoof the trusted proxy identity and bypass authentication. This issue is fixed in Mailu 2024.06.55 and Mailu helm-charts 2.7.3.
Published 2026-09-21
- CriticalCVSS 9.9 v3·EPSS 0.4%·No fix yet
kcp is a Kubernetes-like control plane for form-factors and use-cases beyond Kubernetes and container workloads. Prior to 0.31.4 and 0.32.2, the kcp front-proxy does not remove inbound X-Remote-User, X-Remote-Group, or X-Remote-Extra-* identity headers before forwarding requests to shards. Any authenticated tenant can inject X-Remote-Group: system:masters, authorization.kcp.io/warrant, authentication.kcp.io/scopes, or a group used for per-workspace required-group gating, and the shard trusts these values as authenticated identity assertions. This allows cross-workspace impersonation, authorization bypass, and arbitrary reading, writing, or deletion of resources, secrets, RBAC data, APIExports, APIBindings, and LogicalClusters. This issue is fixed in versions 0.31.4 and 0.32.2.
Published 2026-09-18
- MediumCVSS 4.2 v3·EPSS 0.3%·Fix available
A flaw was found in EAP's Elytron. An EAP application whose security domain is backed by an Elytron token-realm with oauth2-introspection would allow parameter substitution due to missing URL encoding.
Published 2026-09-18
Free CVE lookup by TridentStack Control, automated patching for Windows, macOS, and Linux fleets. Learn more·Uses NVD data but is not endorsed or certified by the NVD. EPSS scores courtesy of FIRST.org (https://www.first.org/epss). Source: CISA KEV Catalog.