Skip to content
Threat Feed

Tag

Auth-Bypass

13 briefs RSS
high advisory

Authorization Bypass in Flowise openai-realtime Endpoints

Flowise versions prior to 3.1.4 contain an authorization flaw in the openai-realtime endpoint, enabling authenticated users to access and execute tools in unauthorized workspaces via cross-workspace ID manipulation.

Flowise vulnerability auth-bypass api-security
1c
high advisory

ZITADEL Privilege Escalation via OAuth2 Token Exchange

A vulnerability in ZITADEL's OAuth2 Token Exchange endpoint (CVE-2026-56668) allows authenticated users to exchange low-privilege tokens for highly privileged tokens by bypassing authorization and scope validation checks.

ZITADEL +1 auth-bypass privilege-escalation oauth2
1t 1c
high advisory

Authorization Bypass in Shopper Framework CollectionProducts Component

An authorization bypass vulnerability in the Shopper framework allows authenticated users with limited privileges to perform unauthorized product deletions across any collection in the database.

shopper/framework +1 web-application privilege-escalation auth-bypass web-vulnerability authorization-bypass shopper cve-2026-56828 cms
2t
critical advisory

Traefik HTTP/3 Backend Authentication Bypass via Connection Reuse

Traefik fails to isolate connection-bound NTLM and Negotiate authentication on HTTP/3 routes, allowing unrelated clients to inherit victim-authenticated backend connections.

Traefik +3 vulnerability auth-bypass webserver proxy request-smuggling authorization-bypass
1r 2t 1c
high advisory

Unauthenticated Access to ESPHome Dashboard via Ingress Interface Misconfiguration

An auth bypass in the ESPHome Home Assistant add-on allows unauthenticated LAN access to the dashboard due to improper interface binding, enabling remote code execution on the host.

esphome-device-builder auth-bypass remote-code-execution home-assistant esphome
2t
high threat

Unauthenticated Category Addition in Rizwan17 inventory-management-system

An authentication bypass vulnerability in the AJAX backend of Rizwan17 inventory-management-system allows remote attackers to execute unauthorized category additions via the userid parameter.

exploited inventory-management-system +1 web-vulnerability auth-bypass cve-2026-87922
1r 1t 1c
high advisory

Information Disclosure in SiYuan Kernel Enabling Offline Password Cracking

An information disclosure vulnerability in SiYuan's API allows unauthorized remote readers to retrieve cryptographic material necessary for offline, unthrottled GPU-based cracking of encrypted notebook master passwords.

SiYuan Kernel +5 info-disclosure cve cryptanalysis authentication-bypass webserver vulnerability session-forgery credential-disclosure +3
4r 8t 1c updated
high advisory

NoSQL Injection Vulnerability in Budibase MongoDB Integration

Budibase versions prior to 3.40.0 are vulnerable to NoSQL injection in the MongoDB datasource due to improper handling of user-supplied parameters, allowing unauthorized data access and potential server-side execution.

Budibase +2 ssrf web-vulnerability web-application privilege-escalation auth-bypass web-application-vulnerability authorization-bypass cloud-security
1r 3t 5c updated
critical advisory

Authorization Bypass in AI Copilot - Content Generator WordPress Plugin

An authorization bypass vulnerability in the AI Copilot - Content Generator WordPress plugin allows unauthenticated attackers to create administrator accounts and achieve full site takeover via malformed workflow execution.

AI Copilot – Content Generator web-application wordpress cve-2026-14526 auth-bypass
1r 2t 1c
high advisory

Authorization Bypass in Red Hat Quay

An incorrect authorization vulnerability in Red Hat Quay allows read-only superusers to view and impersonate robot account tokens, potentially leading to unauthorized repository access.

Red Hat Quay 3 privilege-escalation container-security auth-bypass
1t 1c
low advisory

Zitadel User API Verification Code Disclosure Vulnerability

An improper permission check in Zitadel's user API allows authenticated users to retrieve verification codes for arbitrary contact information, facilitating unauthorized verification of email addresses and phone numbers.

Zitadel 4.x +2 identity-management auth-bypass api-security
1t 1c
critical advisory

Rclone Unauthenticated options/set Allows Runtime Auth Bypass

Rclone is vulnerable to an unauthenticated options/set vulnerability that allows runtime authentication bypass, potentially leading to sensitive operations and command execution by setting `rc.NoAuth=true` on reachable RC servers started without global HTTP authentication.

rclone auth-bypass rc-api CVE-2026-41176 command-execution
2r 3t
high advisory

GitLab MCP Server Unauthenticated Access via SSE Transport

The @yoda.digital/gitlab-mcp-server's SSE transport lacks authentication and uses wildcard CORS, enabling unauthenticated attackers to execute arbitrary GitLab API calls using the operator's GitLab PAT, including destructive operations.

@yoda.digital/gitlab-mcp-server gitlab auth-bypass sse cors vulnerability
2r 2t