Tag
Hard-coded Credential Vulnerability in SxDevOps
2 TTPs 1 CVESxDevOps versions 1.0 and 1.1 contain a hard-coded credential vulnerability in the ensure_default_superuser function, allowing remote attackers to bypass authentication and gain unauthorized access.
CVE-2024-31218 Authentication Bypass in Webhood
1 rule 1 TTP 1 CVEWebhood versions 0.9.0 and earlier contain a critical authentication bypass vulnerability (CVE-2024-31218) allowing unauthenticated attackers to create an administrative account via the PocketBase API.
Unauthenticated Remote Code Execution in IBM Guardium Data Protection
4 TTPs 1 CVEIBM Guardium Data Protection version 12.2 is vulnerable to a critical deserialization flaw allowing remote, unauthenticated attackers to execute arbitrary code (CVE-2026-81657).
SSRF Vulnerability in Obot via Remote MCP Server URLs
5 TTPsObot versions 0.22.1 and earlier are vulnerable to server-side request forgery (SSRF) allowing authenticated privileged users to probe internal network resources and cloud instance metadata services.
Keycloak Stateless Mode Replay Vulnerability (CVE-2026-90997)
1 TTP 1 CVEA row-count mismatch in Keycloak when using MySQL or MariaDB in stateless mode allows attackers to bypass replay protection for single-use security artifacts like JWT client assertions, DPoP proofs, or TOTP codes.
Account Takeover Vulnerability in Vendure External Authentication
2 TTPs 1 CVEVendure is vulnerable to account takeover due to the ExternalAuthenticationService allowing unverified external identity linking to existing user accounts via email matching.
Critical Vulnerabilities in Cisco Identity Services Engine and ISE-PIC
3 TTPs 2 CVEsMultiple vulnerabilities, including one actively exploited in the wild (CVE-2026-76460), allow unauthenticated attackers to bypass authentication and gain administrative control over Cisco ISE and ISE-PIC deployments.
Authentication Bypass Vulnerability in Schneider Electric PowerChute Serial Shutdown
1 TTP 1 CVESchneider Electric PowerChute Serial Shutdown version 1.5 and prior contains an improper restriction of excessive authentication attempts vulnerability (CVE-2026-13348) that may allow unauthorized account access via brute-force.
Authentication Bypass Vulnerability in Mitsubishi Electric GX Works3
1 TTP 1 CVEAn incorrect implementation of the authentication algorithm (CVE-2026-15688) in Mitsubishi Electric GX Works3 and Motion Control Settings allows local attackers to bypass block password protections and manipulate control programs.
Authentication Bypass in OpenSign getDocument Function
2 TTPs 1 CVEOpenSign versions through 2.41.3 contain an authentication bypass vulnerability allowing unauthenticated attackers to retrieve sensitive document data and download tokens when OTP verification is disabled.
Authentication Bypass in OpenNHP via Attestation Verification Manipulation
1 TTP 1 CVEOpenNHP versions up to 1.0.2 contain an authentication bypass vulnerability allowing attackers to force the use of a fallback attestation verifier via malicious input.
Authentication Bypass in Trigger.dev via GitHub App Installation Binding
1 TTP 1 CVETrigger.dev versions before 4.6.0 contain an authentication bypass vulnerability allowing attackers to hijack GitHub App installations and gain unauthorized repository access by manipulating state cookies and installation identifiers.
Unauthenticated Administrative Account Creation in UVdesk Community Skeleton
2 TTPs 1 CVEA vulnerability in UVdesk Community Skeleton versions through 1.1.8 allows unauthenticated attackers to reconfigure the database and create super administrator accounts via wizard endpoints.
CVE-2026-92717 Authentication Bypass in Covenant
1 TTP 1 CVECovenant versions 0.6 and earlier contain an authentication bypass vulnerability allowing unauthenticated remote actors to gain full operator API access via the CovenantHub SignalR hub.
Improper Authentication Vulnerability in ChangeWeDer CRM
1 TTP 1 CVEAn unauthenticated remote code execution vulnerability in the LoginUserUtil.releaseUserIdFromCookie function of ChangeWeDer CRM allows attackers to bypass authentication through cookie manipulation.
Critical Vulnerabilities in Digital Watchdog VMAX DVR and NVR Products
2 TTPsMultiple high-severity vulnerabilities in Digital Watchdog VMAX series devices allow unauthenticated remote attackers to bypass authentication, gain root access via hard-coded credentials, and execute arbitrary system commands.
Unauthenticated Information Disclosure in lamp-cloud via CVE-2026-91996
1 rule 1 TTP 1 CVEAn authentication bypass vulnerability in lamp-cloud versions 5.10.0 and earlier allows unauthenticated attackers to exfiltrate sensitive JVM system properties via insecurely whitelisted API endpoints.
Authorization Bypass in pgweb API Connect Endpoint
1 rule 1 TTP 1 CVEAn authorization bypass vulnerability in pgweb versions up to 0.17.0 allows unauthenticated attackers to supply arbitrary connection strings via the /api/connect endpoint.
Authentication Bypass in PHPGurukul Blood Donor Management System
2 TTPs 1 CVEPHPGurukul Blood Donor Management System 1.0 is vulnerable to an authentication bypass in the admin dashboard, allowing remote attackers to gain unauthorized administrative access.
Authentication Bypass in goproxy CONNECT Requests (CVE-2026-91143)
1 TTP 1 CVEThe goproxy package through version 15.3 fails to enforce authentication on CONNECT tunnel requests, allowing unauthorized network relay via the proxy.
Authentication Bypass in Krayin CRM Inbound Parse Endpoint
1 rule 1 TTPAn authentication bypass vulnerability in Krayin CRM version 2.2.6 and earlier allows unauthenticated attackers to inject arbitrary, forged email messages into the CRM inbox via the /admin/mail/inbound-parse endpoint.
Hard-coded JWT Secret in Crawlab Vulnerability
2 TTPs 1 CVECrawlab versions 0.6.3 and earlier utilize a hard-coded HMAC-SHA256 secret for JWT signing, enabling unauthenticated attackers to forge administrative tokens and achieve remote code execution.
Authentication Bypass in Cheshire Cat AI via Custom Auth Handler
1 TTP 1 CVEAn unauthenticated remote code execution vulnerability in Cheshire Cat AI version 1.9.2 and earlier stems from improper validation of the user_id argument within the custom authentication handler.
Authentication Bypass in WARP-Clash-API via SECRET_KEY Manipulation
1 TTP 1 CVEA publicly disclosed vulnerability in the WARP-Clash-API authorized function allows remote unauthenticated access by manipulating the SECRET_KEY argument.
Prowler SAML Domain Claiming Enables Cross-Tenant Account Takeover
2 TTPsProwler versions through 5.30.0 contain an improper authentication vulnerability where the SAML ACS finish flow incorrectly derives the target tenant from an asserted email domain, enabling cross-tenant account takeover.
Unauthenticated Endpoint Spoofing in WeenyGenius
3 TTPs 1 CVEWeenyGenius by Howyar Technologies contains a missing authentication vulnerability allowing unauthenticated network-adjacent attackers to spoof teacher or student roles and achieve remote control of student workstations.
Active Exploitation of JFrog Artifactory Vulnerabilities
3 TTPs 3 CVEsAttackers are actively exploiting a chain of three critical vulnerabilities (CVE-2026-42016, CVE-2026-42018, and CVE-2026-82329) in JFrog Artifactory to bypass authentication and achieve full administrative control.
SigV4 Authentication Bypass in rclone serve s3
4 TTPs 1 CVEA critical authentication bypass vulnerability in rclone's S3 serving mode allows unauthenticated attackers to spoof identity via forged SigV4 signatures when '--auth-proxy' is used without '--auth-key'.
Authentication Bypass in passport-saml-encrypted via Unsigned SAML Assertions
2 TTPs 1 CVEThe passport-saml-encrypted library versions up to 0.1.13 contain a critical vulnerability where SAML signature verification is skipped if a specific configuration is omitted, allowing attackers to forge and inject arbitrary authentication assertions.
Open WebUI Same-Origin XSS via Terminal Port Preview
3 rules 5 TTPs 1 CVEAn insecure sandbox configuration in the Open WebUI terminal port preview feature allows authenticated users to execute arbitrary JavaScript in the application's origin, leading to session token theft and account takeover.
CyberPanel Authentication Bypass via API
1 TTP 1 CVECyberPanel versions prior to 3.0.5 contain an authentication bypass vulnerability where two-factor authentication is not enforced on API endpoints, allowing credential-derived token misuse.
Hardcoded Session Encryption Key in MaxSite CMS
2 TTPs 1 CVEMaxSite CMS versions 109.6 and earlier contain a hardcoded encryption key in application/config/config.php, enabling unauthenticated attackers to forge administrator session cookies.
Authentication Bypass in Parse Server LDAP Adapter (CVE-2026-87806)
1 CVEParse Server versions before 8.6.88 and 9.10.1-alpha.7 contain an authentication bypass vulnerability in the LDAP adapter that allows attackers to perform account takeover via zero-length credentials.
Remote Code Execution in FireBox WooCommerce Plugin
2 TTPs 1 CVEThe FireBox WordPress plugin is vulnerable to authenticated Remote Code Execution via an insufficiently validated blacklist and improper input sanitization in the firebox_meta REST endpoint.
Arbitrary Command Execution in Snipe-IT Backup Restoration
1 rule 14 TTPs 1 CVESnipe-IT versions prior to 8.7.0 are vulnerable to OS command injection when a superadministrator restores a crafted backup archive, allowing arbitrary command execution via the MySQL client.
XenForo OAuth2 Authorization Code Reuse Vulnerability
3 rules 3 TTPs 1 CVEXenForo versions prior to 2.3.13 contain an OAuth2 authorization code reuse vulnerability (CVE-2026-73311) that allows attackers to obtain unauthorized token pairs by submitting previously used codes.
Authentication Bypass in 389 Directory Server via SELFDN ACI
1 TTP 1 CVEAn authentication bypass vulnerability in 389 Directory Server allows unauthenticated LDAP clients to bypass access control rules by exploiting an error in the SELFDN ACI bind-rule evaluator.
Authentication Bypass in 389 Directory Server via SASL Bind State Confusion
1 TTP 1 CVEA vulnerability in 389 Directory Server allows unauthenticated attackers to elevate privileges by exploiting state confusion during SASL authentication, leading to unauthorized Directory Manager access.
Unauthenticated Administrative Compromise in FreeIPA via OTP ACI Flaw
3 TTPs 3 CVEsAn unauthenticated remote attacker can exploit a flaw in FreeIPA's self-managed OTP token access control instructions to create arbitrary Kerberos principals and grant them administrator group membership.
Authentication Bypass in Tenda AC9 Web Management
1 TTPA critical authentication bypass vulnerability, CVE-2026-86300, exists in the Tenda AC9 firmware version 15.03.05.14, allowing remote attackers to circumvent security controls via the Web Management interface.
Authentication Bypass in SourceCodester Simple Traffic Offense System
1 rule 1 TTP 1 CVEAn authentication bypass vulnerability in SourceCodester Simple Traffic Offense System 1.0 allows remote, unauthenticated attackers to manipulate user creation via the saveuser.php script.
SQL Injection Vulnerability in Mstfakts College-Management-System
1 rule 2 TTPs 1 CVEA remote SQL injection vulnerability in Mstfakts College-Management-System allows unauthenticated attackers to execute arbitrary database commands via the book search handler.
Authentication Bypass in HivePress Authentication Plugin
1 TTP 1 CVEThe HivePress Authentication plugin for WordPress through version 1.1.4 is vulnerable to authentication bypass via improper validation of Facebook OAuth tokens, allowing unauthenticated attackers to impersonate arbitrary users.
Cross-Site Scripting Vulnerability in AVideo YPTSocket Plugin
9 TTPs 1 CVEAn unauthenticated XSS vulnerability in the AVideo YPTSocket plugin allows attackers to execute arbitrary JavaScript in victim browsers via crafted websocket callback messages.
Authentication Bypass in Cua computer-server via Environment Variable Misconfiguration
1 rule 2 TTPs 1 CVECua computer-server versions prior to 0.3.42 contain an authentication bypass vulnerability triggered when the CONTAINER_NAME environment variable is unset, allowing unauthenticated remote command execution on TCP port 8000.
Authentication Bypass in Mstore Api Plugin for WordPress via JWT Forgery
1 TTP 1 CVEThe Mstore Api plugin for WordPress (<= 4.20.0) is vulnerable to authentication bypass via JWT forgery, allowing unauthenticated attackers to impersonate any user by crafting illegitimate Firebase Phone Auth tokens.
CVE-2022-22978 Authorization Bypass in Spring Security
1 rule 1 TTP 1 CVEAn authorization bypass vulnerability in Spring Security allows unauthenticated attackers to access restricted endpoints by injecting URL-encoded newline or carriage return characters into request paths protected by RegexRequestMatcher.
OpenChoreo Cluster-Gateway Authentication Bypass and RCE
3 TTPs 1 CVEThe OpenChoreo cluster-gateway fails to authenticate callers to internal management APIs, allowing unauthorized actors to perform arbitrary Kubernetes API mutations and access Secrets across connected data planes.
Authorization Bypass in ntopng REST v2 Handlers
2 rules 2 TTPs 1 CVEAn authorization bypass vulnerability in ntopng prior to version 6.7.260717 allows authenticated non-administrator users to delete notification endpoints and recipients, disrupting alerting services.
Authentication Bypass in QAnything 2.0.0
1 rule 1 TTP 1 CVEQAnything 2.0.0 contains an authentication bypass vulnerability in multiple API endpoints that allows unauthenticated attackers to exfiltrate sensitive uploaded documents and knowledge base files.
Authentication Bypass and SSRF in FastChat /register_worker Endpoint
1 rule 2 TTPs 1 CVEAn authentication bypass vulnerability in FastChat allows unauthenticated attackers to register arbitrary workers, enabling server-side request forgery and the interception of model prompts and responses.
Authentication Bypass in Aim Remote Tracking Server
2 TTPs 1 CVEThe Aim remote tracking server version 3.29.1 contains an authentication bypass vulnerability allowing unauthenticated attackers to execute arbitrary methods and perform unauthorized data access or deletion.
Unauthenticated SSRF in Openpanel Site Checker
1 rule 8 TTPs 1 CVEOpenpanel versions before 2.3.0 are vulnerable to an unauthenticated server-side request forgery (SSRF) flaw in the /tools/site-checker endpoint that allows internal network probing and cloud metadata access.
Information Disclosure in SiYuan Kernel Enabling Offline Password Cracking
4 rules 8 TTPs 1 CVEAn information disclosure vulnerability in SiYuan's API allows unauthorized remote readers to retrieve cryptographic material necessary for offline, unthrottled GPU-based cracking of encrypted notebook master passwords.
CVE-2026-85440: Heap Overflow in MOOS core-moos
5 TTPs 1 CVEA pre-authentication heap overflow vulnerability in the MOOSCommPkt packet handling of MOOS core-moos versions up to 10.4.0 allows remote unauthenticated attackers to perform arbitrary memory writes via crafted packets.
Authentication Bypass via HMAC Key Confusion in python-jose
2 CVEsThe python-jose library version 3.5.0 and earlier fails to validate asymmetric keys during HMAC initialization, allowing attackers with a public key to forge HS256 JWT tokens.
Authentication Bypass in vhr PUT /hr/pass Endpoint
1 TTP 1 CVEAn authentication flaw in the vhr application through commit 03abbd3 allows authenticated attackers to perform unauthorized password changes for arbitrary accounts by manipulating the account ID in PUT requests.
Authentication Bypass in CRMEB via SystemRoleServices.php
1 CVECRMEB contains an authentication bypass vulnerability in the verifyAuth() method of SystemRoleServices.php, allowing unprivileged accounts to access restricted administrative endpoints.
Authentication Bypass in Mendix SAML Module
1 CVEAn authentication bypass vulnerability (CVE-2026-80465) in multiple Mendix SAML module versions allows unauthenticated attackers to hijack user sessions via improper SAML response signature validation.
Command Injection Vulnerability in Coolify
4 TTPs 1 CVECoolify versions before 4.2.0 are vulnerable to command injection via environment variable keys, allowing authenticated attackers to execute arbitrary commands on the underlying host server.
Authentication Bypass in Team Password Manager via Password Reset Flow
1 TTP 1 CVETeam Password Manager versions prior to 14.184.308 contain a critical authentication bypass vulnerability in the local account password reset workflow that allows unauthenticated attackers to perform account takeovers.
Authentication Bypass in Proxmox Virtual Environment
1 rule 1 TTP 1 CVECVE-2023-54391 allows unauthenticated remote attackers to bypass authentication in Proxmox VE 7.0-8.0 by providing a crafted tfa-challenge parameter to the API login endpoint.
VMware Tanzu Spring Security Authentication Bypass Vulnerability
1 CVEA vulnerability in VMware Tanzu Spring Security allows a remote, unauthenticated attacker to bypass security restrictions, potentially leading to unauthorized access to sensitive information.
Authentication Bypass in Support Genix WordPress Plugin
2 TTPs 1 CVEThe Support Genix WordPress plugin is vulnerable to authentication bypass and administrator account takeover due to a weak cryptographic implementation in the guest ticket login feature.
Authentication Bypass in cu silicon
1 CVEAn unauthenticated remote code execution vulnerability (CVE-2026-82919) exists in the cu silicon library versions 0.1.5 and earlier due to missing authentication controls in the create_app function.
Authentication Bypass Vulnerability in Pangolin
1 TTP 1 CVEPangolin versions prior to 1.22.0 are vulnerable to an authentication bypass in the share-link endpoint, allowing unauthenticated access to arbitrary resources.
Critical Authentication Bypass in Tenda AC18 Telnet Handler
1 TTP 1 CVEA critical authentication bypass vulnerability in the Tenda AC18 router allows remote, unauthenticated attackers to gain unauthorized access via the Telnet service.
ToolJet Multi-Tenancy Broken Access Control
4 TTPs 1 CVEToolJet versions prior to 3.16.208 are vulnerable to broken access control, allowing authenticated builder-role users to perform unauthorized database operations across tenant boundaries.
Authorization Bypass in Soarkey StudentManagement
1 rule 1 CVEA vulnerability in the Administrative Servlet of Soarkey StudentManagement and 学生信息管理系统 allows remote attackers to bypass authorization via manipulation of the action argument in AdminDao.doGet.
WWBN AVideo SSRF Filter Bypass via NAT64 Hex Encoding
7 rules 15 TTPs 1 CVEWWBN AVideo is vulnerable to a Server-Side Request Forgery (SSRF) bypass in the isSSRFSafeURL function due to improper normalization of hex-encoded NAT64 addresses.
Authentication Bypass in MyHome Core Plugin for WordPress
1 rule 1 TTP 1 CVEThe MyHome Core plugin for WordPress is vulnerable to authentication bypass via insecure AJAX handlers, allowing unauthenticated attackers to hijack arbitrary user accounts.
Authentication Bypass in SAML Single Sign On - SSO Login Plugin for WordPress
1 TTP 1 CVEAn unauthenticated authentication bypass vulnerability in the SAML Single Sign On - SSO Login plugin allows attackers to overwrite the IdP signing certificate and forge administrative sessions.
Authentication Bypass in pac4j-oidc via Token Forgery
1 TTP 1 CVEAn authorization bypass vulnerability in pac4j-oidc versions prior to 6.5.6 allows attackers to forge OIDC access tokens by exploiting the library's failure to validate token signatures, issuers, audiences, and expiration.
Omnivore API Authentication Bypass via JWT Algorithm Confusion
1 TTP 1 CVEThe Omnivore API improperly validates Apple sign-in tokens, allowing attackers to perform algorithm confusion attacks to bypass authentication and impersonate users.
Information Disclosure Vulnerability in IBM Administration Runtime Expert for i
1 TTP 1 CVEIBM Administration Runtime Expert for i 1R1M0 contains an improper authentication enforcement vulnerability allowing a remote authenticated attacker to access sensitive information.
Gophish API Authentication Middleware Bypass
1 TTP 1 CVEGophish versions through 0.12.1 contain a vulnerability in the API authentication middleware that fails to enforce account lockout and password change requirements, allowing attackers with valid API keys to maintain persistent unauthorized access.
SpringBlade Privilege Escalation via Hardcoded JWT Key and Unprotected Endpoint
2 TTPs 1 CVESpringBlade versions 2.7.3 through 3.5.0 allow authenticated attackers to forge administrative tokens using a hardcoded JWT signing key and escalate privileges via an unprotected internal endpoint.
9router Authentication Bypass and SSRF via Host Header Spoofing
2 rules 2 TTPs 1 CVEAn authentication bypass in 9router 0.4.80 and earlier allows remote attackers to spoof the 'Host' header, gaining unauthorized access to API proxy endpoints, enabling quota theft via AI relay and server-side request forgery (SSRF).
Unauthenticated Admin Takeover in Portainer Initialization
3 TTPs 1 CVEAn authentication bypass vulnerability in Portainer allows unauthenticated attackers to hijack uninitialized instances via the /api/restore and /api/users/admin/init endpoints.
Authentication Bypass in WPMU DEV Dashboard Plugin
1 TTP 1 CVEAn authentication bypass vulnerability in the WPMU DEV Dashboard WordPress plugin allows unauthenticated attackers to forge an administrator session by exploiting flawed HMAC validation in the Hub SSO flow.
Authentication Bypass in APITable InternalUserController
1 rule 2 TTPs 1 CVEAPITable versions up to 1.13.0-beta.1 contain an authentication bypass vulnerability in the InternalUserController, allowing unauthenticated attackers to permanently delete user accounts currently in a cooling-off period.
Critical Vulnerabilities in Xiiaozet LK100W
2 TTPsXiiaozet LK100W devices running firmware prior to v2.1.240 are vulnerable to multiple high-severity flaws, including OS command injection and authentication bypass, which could allow remote attackers to achieve full device compromise.
Unauthenticated Configuration Manipulation in NebulaGraph
1 rule 1 TTP 1 CVENebulaGraph versions 3.8.0 and earlier contain an authentication bypass in the internal HTTP web service that allows unauthenticated remote attackers to read sensitive configuration and modify daemon behavior at runtime.
Authentication Bypass in Alluxio S3 REST Proxy
1 rule 1 TTP 1 CVEAlluxio versions 2.9.5 and earlier contain a critical authentication vulnerability that allows unauthenticated attackers to spoof identity and perform unauthorized operations by failing to verify AWS Signature Version 4 requests.
CVE-2026-49757: AshAuthentication OAuth2/OIDC Account Takeover
1 TTP 1 CVEAshAuthentication incorrectly uses email addresses to link OAuth2/OIDC identities to local accounts, enabling unauthenticated account takeover via identity providers that allow unverified or reclaimed emails.
Arbitrary File Write Vulnerability in PraisonAI Agents
5 TTPs 1 CVEThe FileMemory component in praisonaiagents versions 1.6.52 and earlier fails to sanitize user-supplied identifiers, enabling path traversal attacks that result in arbitrary JSON file creation or overwriting.
Authentication Bypass and Privilege Escalation in rConfig
1 rule 1 TTPrConfig versions 8.0.0 through 8.2.12 contain a logic flaw in route configuration that enables unauthenticated registration of administrator-privileged accounts, facilitating full system compromise.
Authentication Bypass in open-wearables
1 rule 1 CVEAn unauthenticated remote code execution vulnerability (CVE-2026-78154) in open-wearables versions 0.6.2 and earlier allows attackers to bypass authentication in the invitation code redemption endpoint.
Hard-coded Credential Vulnerability in TaxHacker
1 TTP 1 CVETaxHacker versions 0.8.2 and earlier contain a hard-coded credential vulnerability in the JWT Secret Handler, allowing potential remote exploitation via the BETTER_AUTH_SECRET argument.
Authentication Bypass in AVideo via Parameter Manipulation
7 rules 13 TTPs 1 CVEAn authentication bypass vulnerability in AVideo (CVE-2026-59808) allows attackers with upload access to hijack administrative sessions via improper video ownership verification.
Authorization Bypass in Reconmap Report Preview Endpoint
1 TTP 1 CVEAn improper [AllowAnonymous] attribute in Reconmap's ReportsController allows unauthenticated remote attackers to perform enumeration of sensitive penetration testing engagement data by walking sequential project IDs.
Authentication Bypass in ArchitectPanel Web Admin Panel
1 TTP 1 CVEAn Execution After Redirect (EAR) vulnerability in ArchitectPanel Web Admin Panel allows unauthenticated attackers to bypass authentication and gain unauthorized access.
NocoBase Authenticated Remote Code Execution via File Write and LFI Chain
1 rule 2 TTPsAn authenticated admin can achieve remote code execution in NocoBase prior to v2.1.5 by chaining arbitrary file uploads via storage root manipulation with a local file inclusion vulnerability in the plugin manager.
Critical Vulnerabilities in Citrix NetScaler ADC and Gateway
2 CVEsCitrix has released patches for critical vulnerabilities including CVE-2026-19490, an authentication bypass, and CVE-2026-19489, a memory overflow vulnerability affecting NetScaler ADC and Gateway appliances.
Information Exposure in phpMyFAQ Password Reset Mechanism
2 rules 4 TTPs 1 CVEVersions of phpMyFAQ prior to 4.1.7 store password reset tokens in a publicly accessible file when user tracking is enabled, allowing unauthenticated attackers to hijack accounts.
Critical Authentication Bypass in Red Hat Build of Keycloak
1 TTP 1 CVEA critical vulnerability (CVE-2026-18963) in the keycloak-services component allows unauthenticated attackers to hijack user accounts by bypassing password reset verification requirements.
Authentication Bypass and Privilege Escalation in ArcadeDB
1 rule 5 TTPs 1 CVEArcadeDB versions before 26.8.1 contain a vulnerability in the gRPC transaction executor that allows authenticated readers to execute arbitrary JavaScript, leading to server-wide privilege escalation.
Authentication Bypass in Bastillion via Path Prefix Misrouting
1 rule 2 TTPs 1 CVEAn authentication bypass vulnerability (CVE-2026-75627) in Bastillion versions 5.1.0 and earlier allows unauthenticated attackers to access administrative controllers via path prefix manipulation, enabling full control over managed SSH infrastructure.
Arbitrary Code Execution in openssl_encrypt Library
1 rule 8 TTPs 1 CVEThe openssl_encrypt library before version 1.4.0 contains a vulnerability in its Whirlpool hash implementation that allows arbitrary code execution via untrusted shared object loading.
Authentication Bypass in Tenda AC10 Router
1 TTP 1 CVEAn improper authentication vulnerability in the Tenda AC10 router's httpd component allows remote, unauthenticated attackers to gain unauthorized access to the device.
Authentication Bypass in 6Storage Rentals WordPress Plugin
1 rule 1 TTP 1 CVEThe 6Storage Rentals WordPress plugin contains a critical authentication bypass vulnerability (CVE-2026-15303) that allows unauthenticated attackers to impersonate any user, including administrators, via the six_storage_create_wp_user AJAX handler.
Authorizer Zero-Click Account Takeover via OAuth Identity Linking
2 TTPsAuthorizer suffers from a zero-click account takeover vulnerability (CVE-2026-35511) where attackers can link OAuth identities to unverified accounts, gaining persistent password access to victim accounts.
Hardcoded Authentication Token in IBM Storage Scale GUI
2 TTPs 1 CVEIBM Storage Scale versions 5.2.3.0 through 5.2.3.8 and 6.0.0.0 through 6.0.1.0 contain a hardcoded token used for inter-node communication and REST API authentication, allowing potential unauthenticated access to the GUI.
Authentication Bypass in SiYuan Publish API
7 rules 19 TTPs 5 CVEsSiYuan versions prior to 3.7.4 contain an authentication bypass vulnerability allowing unauthenticated remote attackers to retrieve decrypted content from encrypted notebooks.
Gunra Ransomware Gang Exploitation of Fortinet Appliances
4 TTPs 2 CVEsThe Gunra ransomware-as-a-service group is leveraging critical Fortinet vulnerabilities (CVE-2024-55591 and CVE-2025-24472) to gain initial access, hijack VDI sessions, and bypass multi-factor authentication in attacks against critical infrastructure.
Undertow AJP Authentication Bypass via CVE-2026-15554
2 TTPs 1 CVEThe Undertow AJP listener incorrectly trusts ssl_cert and is_ssl attributes within the AJP protocol without validating a shared secret, allowing unauthenticated attackers to bypass CLIENT-CERT authentication.
PicketLink Federation SAML Authentication Bypass via Forged Assertions
1 TTP 1 CVEA vulnerability in the PicketLink Federation SAML unsolicited response handler allows unauthenticated attackers to forge assertions, resulting in full authentication bypass as any principal.
Unauthenticated RCE and Data Access in Feast via Default Configuration
3 TTPs 1 CVEFeast and feast-operator contain a vulnerability due to a default 'no_auth' configuration, allowing unauthenticated attackers to achieve RCE via malicious User-Defined Functions and perform unauthorized cross-tenant data access.
Remote Code Execution in SPIP SQLite Installations via CVE-2026-66738
1 rule 1 TTP 1 CVESPIP versions prior to 4.4.18 contain a code injection vulnerability in the navigation menu endpoint that allows authenticated editors to execute arbitrary OS commands on SQLite-backed installations.
Improper Authentication in code-projects Task Management System
1 rule 2 TTPs 3 CVEsA vulnerability in code-projects Task Management System 1.0 allows remote attackers to bypass authentication via manipulation of the password argument in the login component.
Statamic CMS Account Takeover via Unverified OAuth Email Matching
1 TTPAn unauthenticated attacker can achieve account takeover by leveraging unverified OAuth email matching in Statamic CMS, allowing unauthorized authentication as existing users including administrators.
Arbitrary Password Reset Vulnerability in Craft CMS
5 TTPsAn insecure mass-assignment vulnerability in the Craft CMS user element save action allows authenticated users with specific permissions to modify passwords without requiring the current password or elevated verification.
Multiple Security Vulnerabilities in Wallix Access Manager and Bastion
1 TTPMultiple vulnerabilities in Wallix Access Manager and Bastion products allow for unauthorized privilege escalation and security policy bypass.
Authentication Bypass Vulnerability in LettaBot API
1 rule 1 TTP 1 CVE 1 IOCLettaBot version 0.2.0 contains a missing authentication vulnerability in its API Status Route, enabling remote unauthenticated access to system functions.
CVE-2026-16443: Signature Validation Bypass in Keycloak SAML Metadata Import
2 TTPs 1 CVEAn authentication bypass vulnerability in Red Hat Build of Keycloak allows unauthenticated attackers to forge SAML assertions by manipulating metadata import settings to disable signature validation.
Authentication Bypass and RCE Vulnerabilities in Milvus
2 TTPsMilvus vector database versions prior to 2.5.27 and 2.6.10 are vulnerable to multiple authentication bypass flaws and arbitrary expression execution, allowing attackers to gain full administrative access.
Authorization Bypass Vulnerability in Odysseus Embedding Configuration
1 TTP 1 CVEAuthenticated non-admin users in Odysseus versions prior to commit bf325f6 can exploit a missing authorization vulnerability to modify server-wide embedding backend settings and intercept sensitive data.
Flowise Unauthenticated RCE via Environment Variable Bypass
6 rules 11 TTPs 8 CVEs 2 IOCsFlowise v3.1.2 and earlier are vulnerable to unauthenticated remote code execution because the CVE-2025-8943 patch relies on an incomplete environment variable blocklist, allowing attackers to inject configuration variables that force arbitrary package installation.
Krayin CRM Installer Authentication Bypass Vulnerability
1 rule 1 TTP 1 CVEKrayin CRM 2.2.4 contains a missing authentication vulnerability in the installer middleware, allowing unauthenticated remote attackers to overwrite the administrator account via crafted HTTP POST requests.
Remote Code Execution in OpenEMR Document Category Tree
8 TTPs 1 CVEOpenEMR versions 8.2.0 and earlier are vulnerable to authenticated remote code execution via SQL injection and unsafe eval() calls in the document category tree component.
ArcadeDB Privilege Escalation via JavaScript Triggers
1 rule 3 TTPs 1 CVEArcadeDB versions before 26.7.3 insecurely expose the LocalDatabase object to JavaScript triggers, allowing attackers with schema update permissions to perform unauthorized administrative actions.
Authentication Bypass in @better-auth/sso
2 TTPs 1 CVEMultiple authentication bypass vulnerabilities in @better-auth/sso allow attackers to perform account takeovers by exploiting flaws in SSO provider handling.
Authentication Bypass and RCE in Kestra OSS
1 rule 3 TTPs 1 CVE 1 IOCKestra OSS versions 1.3.20 and below are vulnerable to an authentication bypass via an incorrectly implemented filter, enabling unauthenticated remote code execution with root privileges.
NocoBase Authenticated SQL Injection to RCE
1 rule 2 TTPs 1 CVEA critical SQL injection vulnerability in NocoBase allows authenticated attackers to achieve remote code execution on the underlying PostgreSQL container via stacked statements.
Unauthenticated Remote Execution in dynatrace-mcp-server HTTP Transport
1 ruleThe dynatrace-mcp-server package v1.8.5 contains a critical authentication bypass vulnerability in its HTTP transport mode that allows unauthenticated, network-reachable attackers to invoke sensitive Model Context Protocol tools.
Pterodactyl Wings Configuration Secret Exposure via Egg Templating
1 TTP 1 CVEThe Pterodactyl Wings daemon improperly exposes its full configuration to the egg templating engine, allowing low-privileged users to exfiltrate sensitive node secrets, including daemon tokens and registry credentials, via crafted configuration placeholders.
CVE-2026-18141: mTLS Bypass in Ansible Automation Platform
1 TTP 1 CVEAn unauthenticated remote attacker can bypass mTLS authentication in the aap-gateway component of Event-Driven Ansible to inject arbitrary events and trigger automated workflows.
Critical Authentication Bypass in Spikster API
1 CVEA missing authentication vulnerability in Spikster allows unauthenticated remote attackers to access approximately 50 API endpoints, leading to full system compromise.
SolarWinds Web Help Desk SAML Authentication Bypass
1 TTP 1 CVESolarWinds Web Help Desk versions 2026.1 and prior are vulnerable to a critical authentication bypass via the SAML 2.0 implementation, allowing unauthenticated remote access.
Authentication Bypass in FTC E-Commerce Management Panel
1 CVEA missing authentication vulnerability in FTC E-Commerce Management Panel versions prior to 1.0.2 allows unauthenticated remote attackers to bypass security controls and gain unauthorized access.
Authentication Bypass Vulnerability in CentreStack
1 TTP 1 CVECentreStack versions prior to 17.2 are vulnerable to an authentication bypass that allows unauthenticated attackers to manipulate account settings and enumerate system data via exposed API endpoints.
Authentication Bypass and RCE in CentreStack via Hardcoded Cryptographic Key
1 TTP 1 CVECentreStack versions prior to 17.5 contain a hardcoded cryptographic key vulnerability, allowing unauthenticated attackers to forge authentication tokens and execute arbitrary code.
Unauthenticated Remote Access to Phoenix Contact CHARX SEC MQTT Broker
2 rules 5 TTPs 12 CVEsA critical vulnerability (CVE-2026-44090) in Phoenix Contact CHARX SEC controllers allows unauthenticated remote attackers to gain full device control by bypassing authentication on the MQTT broker.
Unauthenticated API Access in AMMOS Instrument Toolkit DSN Interface
1 TTP 1 CVEThe AMMOS Instrument Toolkit (AIT) DSN Interface prior to version 2.2.2 contains a missing authentication vulnerability in the Space Link Extension interface manager, allowing unauthenticated attackers to invoke sensitive API routes.
Authentication Bypass in AMMOS Instrument Toolkit GUI
1 TTP 1 CVEThe AMMOS Instrument Toolkit (AIT) GUI before version 2.5.1 allows unauthenticated attackers to bypass credential checks to establish sessions and issue arbitrary spacecraft commands.
Authentication Bypass in Advanced Responsive Video Embedder WordPress Plugin
1 rule 3 TTPs 1 IOCA critical authentication bypass vulnerability, CVE-2026-18072, affects version 10.8.7 of the Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … plugin for WordPress, allowing unauthenticated attackers to gain full administrative control by supplying a hardcoded token via the `_wplogin` or `_wpm` URL parameter.
IBM WebSphere Application Server Authentication Bypass Vulnerability (CVE-2026-16184)
5 TTPs 7 CVEs 5 IOCsA remote attacker can bypass authentication in IBM WebSphere Application Server versions 9.0 and 8.5 by sending a crafted unauthenticated request, potentially leading to unauthorized access and impact on confidentiality, integrity, and availability.
pytonapi Webhook Custom Path Authentication Bypass (GHSA-3fcr-jvgp-7f58)
1 rule 1 TTPThe pytonapi library, specifically version 2.2.0, contains an authentication bypass vulnerability (GHSA-3fcr-jvgp-7f58) in its TonapiWebhookDispatcher, allowing unauthenticated remote attackers to send forged payloads to custom webhook endpoints, triggering victim-defined business logic and causing integrity impact.
Authentication Bypass in WordPress SMS Alert Plugin Leads to Account Takeover (CVE-2026-15014)
1 rule 2 TTPs 1 CVEAn authentication bypass vulnerability (CVE-2026-15014) in the 'SMS Alert - SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery' WordPress plugin allows unauthenticated attackers to achieve account takeover by exploiting a flaw in the `processRegistration()` function's OTP verification, enabling authentication as any existing WordPress user with a known phone number.
Pheditor Authentication Bypass via Unverified Current Password in Forced Password Change
3 TTPsA critical authentication bypass vulnerability in Pheditor versions prior to 2.0.8 allows an unauthenticated attacker to gain full administrative access by exploiting a flaw in the forced password-change flow, enabling them to set an arbitrary new admin password and obtain an authenticated session without knowing the current one.
Budibase Unauthenticated REST Datasource Credential Theft via Cross-Origin Auth Leak
3 TTPs 4 IOCsAn unauthenticated attacker can steal REST datasource credentials, including Bearer/Basic tokens and static headers, from Budibase applications due to a critical cross-origin authentication leak (GHSA-mqhr-6j6h-74p5) where the application attaches stored credentials to outgoing requests without validating the destination host, allowing exfiltration to an attacker-controlled server.
Authentication Bypass in kin-openapi Due to Default NoopAuthenticationFunc
1 TTPAn authentication bypass vulnerability (CWE-287) exists in the `openapi3filter.ValidationHandler` component of the `getkin/kin-openapi` library (versions <= v0.143.0), where the `ValidationHandler.Load()` method silently defaults to a `NoopAuthenticationFunc` when an explicit function is not provided, allowing unauthenticated remote attackers to bypass OpenAPI security requirements and access protected endpoints in Go services.
WordPress SAML Single Sign On Plugin Authentication Bypass (CVE-2026-15981)
2 TTPs 2 CVEs 2 IOCsA critical authentication bypass vulnerability, CVE-2026-15981, affects the SAML Single Sign On - SSO Login plugin for WordPress (versions up to and including 5.4.4), allowing unauthenticated attackers to log in as any existing user, including administrators, by crafting a malformed SAMLResponse that misleads the plugin's signature validation logic.
CVE-2026-63765: Chatwoot Authentication Bypass Vulnerability in Direct Uploads Controller
1 rule 2 TTPs 1 CVEChatwoot before version 4.16.0 contains an authentication bypass vulnerability in its direct uploads controller that allows unauthenticated attackers to create arbitrary ActiveStorage blobs in any tenant account by exploiting missing authentication checks, leading to data manipulation.
Auth.js (next-auth) v5 Configuration Error Leads to Authentication Bypass
2 TTPsA critical configuration error vulnerability in `next-auth` (Auth.js) v5 applications, specifically versions v5.0.0-beta.0 through v5.0.0-beta.31, can lead to a 'fail-open' state where server-side configuration issues cause the `auth` object to be populated with an error instead of `null`, effectively bypassing authentication checks and granting unauthorized access to protected resources.
Auth.js Email Normalizer Vulnerability Allows Homoglyph Bypass Leading to Account Takeover
2 TTPsA critical vulnerability in Auth.js libraries (next-auth and @auth/core) affects the email/magic-link sign-in flow, allowing an attacker to craft an email address with a homoglyph character that bypasses validation before Unicode normalization, leading to magic links being misrouted to attacker-controlled mailboxes and enabling account takeover without victim interaction.
CVE-2026-16745: Authentication Bypass in Red Hat OpenShift AI odh-dashboard
4 TTPs 1 CVEA critical vulnerability, CVE-2026-16745, exists in the odh-dashboard web console component of Red Hat OpenShift AI (RHOAI), allowing a malicious actor within the cluster to bypass authentication by providing an arbitrary access token, leading to user impersonation and unauthorized access to the Kubernetes API, potentially resulting in arbitrary code execution, privilege escalation, and information disclosure.
Eclipse Jetty Digest Authentication Bypass via ISO-8859-1 Encoding Flaw (CVE-2026-10050)
1 TTPA vulnerability, CVE-2026-10050, in Eclipse Jetty's HTTP client `DigestAuthentication.apply()` method allows an authentication bypass by an attacker who can exploit the lossy ISO-8859-1 character encoding to forge Digest authentication response hashes for users with non-Latin-1 passwords.
LiteLLM MCP Authentication Bypass via OAuth2 Passthrough Fallback
1 TTP 1 CVEAn authentication bypass vulnerability (CVE-2026-59822) exists in LiteLLM's MCP Streamable HTTP endpoint, affecting versions prior to 1.84.0, allowing an unauthenticated attacker to exploit a fallback path that replaces failed key validation with an empty authentication object, leading to the establishment of an authenticated MCP session using arbitrary Bearer tokens, enabling access to configured MCP tools and connected services.
n8n Account Takeover via Unverified Email Claim in Token Exchange Embed Login
2 rules 7 TTPsA high-severity vulnerability in n8n's embed login feature (CVE-2026-XXXX) allows attackers to achieve full account takeover by leveraging unverified email claims in incoming tokens, enabling authentication as any existing user if the instance has embed login enabled and a trusted key source configured that emits unverified email addresses.
n8n Shared Credential Leakage via HTTP Request Pagination Vulnerability
5 TTPs 1 CVEAn authenticated n8n user with 'use-only editor access' can exploit CVE-2026-59209 in shared workflows when `N8N_EXPRESSION_ENGINE=vm` is enabled, allowing them to read sensitive HTTP Header Auth credentials from the `$request.headers` object within a paginated HTTP Request node's expression and exfiltrate them, bypassing credential domain restrictions.
Check Point SmartConsole Authentication Bypass (CVE-2026-16232) Actively Exploited
1 TTP 4 CVEs 6 IOCsCheck Point released a critical security advisory to address CVE-2026-16232, an authentication bypass vulnerability in SmartConsole, which is actively being exploited in the wild and affects Security Management, Multi-Domain Management, Firewall, and Multi-Domain Log Server products.
CVE-2026-4773: Authentication Bypass Vulnerability in Magarsus Consulting IDM-MFA
1 TTP 1 CVECVE-2026-4773 is an improper input validation vulnerability in Magarsus Consulting Ltd. Co. IDM-MFA, allowing authentication bypass in versions from 2025.11.27 before 2026.03.10.
Gitea LFS Authentication Bypass via Malformed SSH Sub-Verb
1 rule 4 TTPs 1 CVEA high-severity authentication bypass vulnerability (CVE-2026-58423) in Gitea's SSH Git LFS handling allows any authenticated SSH user to obtain valid LFS credentials for any private repository, enabling unauthorized download of all LFS objects from instances running Gitea versions 1.23.0 through 1.26.2.
Gitea Docker Images Insecure Default Allows User Impersonation via X-WEBAUTH-USER
1 rule 2 TTPs 1 CVEGitea Docker images ship with a critical misconfiguration, CVE-2026-20896, where `REVERSE_PROXY_TRUSTED_PROXIES = *` by default, enabling any client to bypass authentication and impersonate users via the `X-WEBAUTH-USER` HTTP header when reverse proxy authentication is enabled, leading to unauthorized access to user accounts, including administrative ones.
Gitea Repository Migration SSRF and Internal Git Repository Exfiltration
2 rules 9 TTPs 1 CVEA critical vulnerability in Gitea allows an authenticated, low-privileged user to exfiltrate internal Git repositories by exploiting a validation bypass, where Gitea's initial URL validation for repository migration is circumvented by the Git command-line client's default behavior of following HTTP redirects to otherwise blocked internal IP addresses, leading to server-side request forgery (SSRF) and the theft of sensitive code, credentials, and configuration into an attacker-controlled repository, with persistent exfiltration possible through pull mirrors.
CVE-2026-16242: Konnectivity Proxy-Server Authentication Bypass
4 TTPs 1 CVEA critical authentication bypass vulnerability, CVE-2026-16242, exists in the Konnectivity proxy-server configuration for hosted control planes, allowing a remote unauthenticated attacker to connect as an agent and potentially proxy, inspect, modify, or drop control-plane-to-node traffic due to improper client certificate validation.
Unauthenticated Access in Newpanjing simpleui via AjaxAdmin Endpoint (CVE-2026-16210)
1 TTP 2 CVEs 6 IOCsA high-severity authentication bypass vulnerability, CVE-2026-16210, exists in newpanjing simpleui version 2026.01.13, specifically within the `self.get_action` function of the `AjaxAdmin AJAX Endpoint` component, allowing remote attackers to perform unauthorized manipulations due to missing authentication, with a public exploit available.
CVE-2026-16209: Missing Authentication in Gerapy Project Upload Endpoint
1 TTP 1 CVE 2 IOCsA vulnerability (CVE-2026-16209) in Gerapy versions up to 0.9.13 allows remote unauthenticated access to the Project Upload Endpoint due to missing authentication, enabling attackers to manipulate files and potentially leading to data compromise, with public exploit details available.
QueryWeaver Authentication Bypass via Signup Request (CVE-2026-10130)
3 TTPs 1 CVECVE-2026-10130 describes an authentication bypass vulnerability in QueryWeaver, enabling unauthenticated attackers to obtain valid session tokens for existing user accounts by submitting a crafted signup request with a known victim's email address, leveraging a Cypher MERGE operation that unconditionally links a new token before checking for existing accounts.
IBM Langflow OSS Remote Code Execution via Deserialization
1 rule 5 TTPs 7 CVEs 1 IOCIBM Langflow OSS versions 1.0.0 through 1.10.0 contain a critical deserialization vulnerability (CVE-2026-8476) in its disk-based caching mechanism, which uses Python's unsafe `pickle.loads()` function without proper validation, allowing attackers to process malicious pickle payloads and achieve arbitrary code execution with the privileges of the Langflow server process, leading to complete system compromise.
meta-ads-mcp Authentication Bypass via X-Pipeboard-Token Header
3 TTPsAn authentication bypass vulnerability in `meta-ads-mcp` version 1.0.113 allows unauthenticated network callers to gain unauthorized access by sending an arbitrary value in the `X-Pipeboard-Token` HTTP header, leading to the reuse of the server operator's `META_ACCESS_TOKEN` for full read and write access to Meta Ads data.
Open Event Server Authentication Bypass for Member Roster Export (CVE-2026-63101)
2 rules 4 TTPs 1 CVEAn authentication bypass vulnerability, CVE-2026-63101, in Open Event Server through version 1.19.1 allows unauthenticated attackers to export the complete member roster of any group by exploiting unauthenticated CSV export and task status endpoints, leading to the exfiltration of sensitive data like email addresses, names, and roles.
Authentication Bypass Vulnerability in Vimesoft Enterprise Video Platform (CVE-2026-12691)
1 TTP 1 CVECVE-2026-12691 describes a critical authentication bypass vulnerability in Vimesoft Inc.'s Enterprise Video Platform versions from 3.11.0.0 before 3.25.0, allowing unauthenticated attackers to bypass security mechanisms for critical functions and potentially gain unauthorized access to sensitive information, with a CVSS v3.1 base score of 7.5.
CVE-2026-12692: Unverified Password Change Vulnerability in Vimesoft Enterprise Video Platform
1 TTP 2 CVEs 1 IOCAn unverified password change vulnerability (CVE-2026-12692) exists in Vimesoft Inc.'s Enterprise Video Platform, affecting versions from 3.11.0.0 up to, but not including, 3.25.0, which allows an attacker to bypass authentication mechanisms, potentially leading to unauthorized access to the platform by changing user passwords without proper verification.
OpenClaw Race Condition Bypasses Authorization via DNS Rebinding Timing Window (CVE-2026-62212)
1 CVEA race condition exists in OpenClaw versions before 2026.5.28 within the MS Teams safeFetch DNS rebinding check, allowing a lower-trust caller to exploit a timing window between the DNS validation check and its use, potentially bypassing authorization or policy checks if the affected feature is enabled and reachable.
MCP Python SDK Authentication Bypass Vulnerability (CVE-2026-52869)
1 TTP 1 CVEA high-severity authentication bypass vulnerability, CVE-2026-52869, exists in affected versions of the MCP Python SDK's HTTP transports, allowing an attacker who obtains or guesses a session ID to send JSON-RPC messages to an existing session without verifying the authenticated principal, thereby bypassing per-client isolation and potentially injecting messages.
Authentication Bypass in miniOrange SAML SSO Login Plugin for WordPress (CVE-2026-15013)
3 TTPs 1 CVEA critical authentication bypass vulnerability (CVE-2026-15013) exists in the SAML Single Sign On - SSO Login plugin for WordPress, affecting all versions up to and including 5.4.3, enabling unauthenticated attackers to forge SAML assertions and achieve full administrator-level account takeover due to signature algorithm confusion.
CVE-2026-12382 - AAP Gateway Envoy Proxy Authentication Bypass
2 TTPs 1 CVEA critical authentication bypass vulnerability (CVE-2026-12382) exists in the AAP Gateway Envoy proxy configuration within Red Hat Ansible Automation Platform 2 where the non-mTLS route to EDA event streams fails to remove the Subject HTTP header from client requests, allowing an unauthenticated remote attacker to inject a spoofed Subject header matching a legitimate client certificate DN to bypass mTLS authentication and inject arbitrary events into protected EDA event streams.
MantisBT SOAP API Authentication Bypass and Privilege Escalation (CVE-2026-47156)
2 TTPsA critical authentication bypass vulnerability, CVE-2026-47156, exists in the SOAP API's mci_check_login() function of MantisBT versions 2.28.3 and earlier, allowing an unauthenticated attacker to impersonate any user, including an administrator, by knowing a valid cookie_string and the target username, without needing the target's password, which can lead to full administrator access, extensive data exfiltration, and destructive operations when default self-registration is enabled.
Authentication Bypass in PraisonAI Call API via Host Header Spoofing (CVE-2026-61435)
1 rule 2 TTPs 1 CVEPraisonAI versions prior to 4.6.78 contain an authentication bypass vulnerability in the Call API agent invocation endpoints when PRAISONAI_CALL_AUTH=disabled is configured, allowing an unauthenticated attacker to remotely list and invoke registered agents by sending a spoofed 'Host: 127.0.0.1' HTTP header.
PraisonAI MCP HTTP-Stream Authentication Bypass (CVE-2026-61427)
1 rule 3 TTPs 1 CVEPraisonAI versions prior to 4.6.78 contain an authentication bypass vulnerability, CVE-2026-61427, in the MCP HTTP-stream transport, allowing unauthenticated clients to establish sessions, enumerate tools, and invoke tools, potentially leading to remote code execution if the server is bound to a network-accessible address.
Critical JWT Authentication Bypass in Siemens Opcenter X (CVE-2026-56451)
3 TTPs 1 CVEA critical vulnerability, CVE-2026-56451, in Siemens Opcenter X versions prior to V2604 allows unauthenticated remote attackers to forge arbitrary JSON Web Tokens (JWTs) due to improper algorithm validation, leading to full authentication bypass, user impersonation including administrative accounts, and complete unauthorized access to the application.
FacturaScripts: Account takeover of any 2FA-enabled user due to authentication bypass
1 rule 3 TTPsAn authentication bypass vulnerability (CVE-2026-47677) in FacturaScripts' `/login?action=two-factor-validation` endpoint allows unauthenticated attackers to conduct a brute-force attack against Time-based One-Time Passwords (TOTP) for any 2FA-enabled user, including administrators, due to the absence of password verification, CSRF protection, and rate-limiting, leading to complete account takeover with high confidentiality and integrity impact, as well as potential denial of service via account lockout.
Apollo ConfigService Authentication Bypass via Raw Config File AppId Parsing
2 TTPsAn authentication bypass vulnerability (CVE-2026-59955) in Apollo ConfigService allows unauthenticated remote attackers to read raw configuration data by exploiting an incorrect appId parsing logic for the raw config file endpoint, affecting versions prior to 2.5.2.
CVE-2026-15557: Improper Authentication Vulnerability in waooAI waoowaoo
1 rule 2 TTPs 1 CVEA high-severity improper authentication vulnerability, CVE-2026-15557, exists in waooAI waoowaoo up to version 0.4.1, allowing remote attackers to bypass authentication and gain unauthorized access by manipulating the 'x-internal-user-id' request argument in the Internal Task Header Handler component, with a public exploit available.
CVE-2026-15537: SQL Injection Vulnerability in SourceCodester Online Book Store System 1.0
1 TTP 1 CVEA remote SQL injection vulnerability (CVE-2026-15537) has been identified in SourceCodester Online Book Store System 1.0. The flaw is located in the `admin/login.php` file, specifically impacting the 'Username' argument, and allows for authentication bypass. This vulnerability can be exploited remotely, and a public exploit is available.
Capgo Email Change Vulnerability Bypasses Authentication (CVE-2026-56308)
2 TTPs 1 CVE 2 IOCsA vulnerability (CVE-2026-56308) in Capgo before version 12.128.2 allows an attacker with an authenticated session to change a user's email address without re-authentication or verification of the existing email, leading to account takeover through recovery mechanisms and multi-factor authentication bypass.
Flowise Authentication Bypass via Hardcoded JWT Secrets (CVE-2026-56271)
2 TTPs 1 CVEFlowise versions 3.0.13 and earlier are vulnerable due to hardcoded default JWT secrets ('auth_token', 'refresh_token') and default audience/issuer values ('AUDIENCE', 'ISSUER'), allowing an attacker to forge valid JWTs and impersonate any user, including administrators, leading to an authentication bypass if environment variables are not explicitly set.
CVE-2026-61428: PraisonAI AgentMail Webhook Signature Bypass
3 TTPs 1 CVEPraisonAI AgentMail versions before 4.6.78 are vulnerable to CVE-2026-61428, an authentication bypass flaw in webhook mode that allows unauthenticated attackers to inject messages with spoofed sender addresses, enabling them to trigger replies to attacker-controlled addresses and bypass email filtering.
CVE-2026-14262: WordPress Simple JWT Login Plugin Authentication Bypass to Privilege Escalation
1 rule 1 TTP 1 CVEAn authentication bypass vulnerability (CVE-2026-14262) exists in the WordPress Simple JWT Login plugin, affecting all versions up to and including 3.6.6, which allows authenticated attackers with subscriber-level access or higher to escalate privileges to Administrator by injecting crafted identity claims into the `payload` parameter of a JWT token.
TSDProxy Internal Authentication Token Vulnerability Leading to Management API Escalation
1 rule 4 TTPs 1 IOCA critical vulnerability in TSDProxy allows its internal per-process authentication token to be unconditionally forwarded to proxied backend services when `identityHeaders` is enabled, enabling an attacker with code execution on a co-located backend to replay the token to the local TSDProxy management API (port 8080) and bypass authentication, leading to full management API control.
miniOrange WordPress Plugin Authentication Bypass via OTP Weakness
4 TTPs 1 CVEAn authentication bypass vulnerability (CVE-2026-12761) in the miniOrange Social Login and Register WordPress plugin, affecting versions up to 7.7.0, allows unauthenticated attackers to trigger an OTP email to an arbitrary admin's address, offline crack the weak OTP from a leaked hash, and gain full administrator access by logging in as the target user.
FileBrowser Authentication Bypass via Forged Proxy Authentication Header
1 rule 3 TTPsAn unauthenticated attacker can impersonate any user, including administrators, or automatically create new user accounts in FileBrowser by forging the `X-Remote-User` HTTP header when the server is configured for proxy authentication and is directly reachable, leading to full administrative control and unauthorized access to data.
Capgo Information Disclosure in get_orgs_v7 RPC Function (CVE-2026-56279)
1 rule 4 TTPs 1 CVECapgo versions prior to 12.128.2 are vulnerable to an information disclosure flaw in the `get_orgs_v7(userid)` RPC function, allowing unauthenticated attackers to retrieve sensitive foreign user and organization data by supplying arbitrary user UUIDs.
CVE-2026-59818 etcd: gRPC client listener does not enforce certificate revocation
1 CVEThe etcd gRPC client listener is affected by CVE-2026-59818, a vulnerability where it fails to properly enforce Certificate Revocation Lists (CRLs) when the `--client-crl-file` flag is used, potentially allowing clients with revoked certificates to bypass authentication and gain unauthorized access to etcd instances.
CVE-2026-12598: LoginPress Pro WordPress Plugin Authentication Bypass
2 TTPs 1 CVEAn authentication bypass vulnerability (CVE-2026-12598) exists in the LoginPress Pro plugin for WordPress, affecting versions up to and including 6.2.3 within the Spotify Social Login addon, enabling unauthenticated attackers to log in as any existing WordPress user, including administrators, by registering a Spotify account with the target's email.
CVE-2026-58122: Hermes WebUI Authentication Bypass via Spoofed X-Forwarded-For Header
1 rule 4 TTPs 1 CVECVE-2026-58122 describes an authentication bypass vulnerability in Hermes WebUI before version 0.51.307, allowing unauthenticated remote attackers to bypass local-origin IP restrictions on onboarding endpoints by spoofing the X-Forwarded-For header with a loopback address, leading to server-side request forgery (SSRF), API key overwrites, and persistent access token acquisition.
CVE-2026-14245 - miniOrange OTP WordPress Plugin Authentication Bypass
3 TTPs 1 CVEA critical authentication bypass vulnerability, CVE-2026-14245, exists in the miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress, affecting all versions up to 5.5.1, allowing unauthenticated attackers to obtain a password-reset URL for an arbitrary Administrator account and achieve full account takeover due to a lack of server-side OTP verification and reliance on a publicly exposed `form_nonce`.
NL Portal IDOR Vulnerability Allows Tampering and Data Leakage of Other Users' Tasks (CVE-2026-49464)
2 TTPsAn Insecure Direct Object Reference (IDOR) vulnerability, CVE-2026-49464, in NL Portal's Taak V2 implementation (versions 1.5.0 through 3.0.0) allows authenticated attackers to mark other users' tasks as complete, overwrite submitted data, and leak personal information by exploiting an authorization bypass in the `submitTaakV2` GraphQL endpoint.
CVE-2026-0283: Authentication Bypass in Palo Alto Networks PAN-OS Large Scale VPN (LSVPN)
1 TTPAn authentication bypass vulnerability, CVE-2026-0283, in Palo Alto Networks PAN-OS software allows an unauthenticated attacker with network access to establish an unauthorized site-to-site VPN connection when LSVPN functionality with configured satellites is enabled, leading to potential access to internal network resources.
CVE-2026-14495: DoLogin Security Plugin Authentication Bypass via Insufficient Randomness
2 TTPs 1 CVEThe DoLogin Security plugin for WordPress, in all versions up to and including 4.3, is vulnerable to authentication bypass (CVE-2026-14495) due to insufficient randomness in magic-link token generation, allowing unauthenticated attackers to brute-force and reconstruct valid passwordless login tokens for any user, including administrators, and gain full control.
Better Auth OAuth Refresh Token Replay via Missing Client Authentication (CVE-2026-53512)
1 TTPThe legacy `oidcProvider` and `mcp` plugins in the `better-auth` library versions prior to 1.6.11 are vulnerable to CVE-2026-53512, an OAuth refresh-token replay attack where the plugins fail to verify the `client_secret` of confidential clients during the `refresh_token` grant, allowing an attacker who obtains a valid `refresh_token` and `client_id` to indefinitely mint new access tokens and impersonate the client for unauthorized resource access.
Multiple Vulnerabilities in Digi International PortServer TS and Digi One SP IA Devices
2 TTPs 2 CVEsMultiple vulnerabilities, including CVE-2026-12352 (incorrect authorization) and CVE-2026-12948 (stored cross-site scripting), affect Digi International PortServer TS, Digi One SP, Digi One SP IA, and Digi One IA devices with firmware prior to 2025, allowing unauthenticated bypass, access to restricted resources, credential acquisition, and client-side script execution in critical infrastructure environments.
CVE-2026-14476: SSSD AD GPO Provider Path Traversal to Root File Write and Authentication Bypass
5 TTPs 1 CVEA path traversal vulnerability (CVE-2026-14476) in SSSD's Active Directory Group Policy Object (AD GPO) provider allows an authenticated attacker with AD GPO management access to write arbitrary files outside the GPO cache directory with root privileges, leading to Kerberos configuration injection and potential authentication bypass on Red Hat Enterprise Linux systems.
Eclipse Jetty: Multiple Vulnerabilities Including Arbitrary Code Execution
2 TTPsAn authenticated remote attacker can exploit multiple vulnerabilities in Eclipse Jetty to achieve arbitrary code execution, bypass security measures, or perform an HTTP cache poisoning attack, necessitating immediate patching and enhanced monitoring of Jetty instances.
CVE-2026-14622 — Jairiidriss restaurant-website-php-mysql Authentication Bypass
1 rule 1 TTP 1 CVEA high-severity authentication bypass vulnerability (CVE-2026-14622) exists in the jairiidriss restaurant-website-php-mysql web application's AJAX Endpoint, specifically affecting the /admin/ajax_files component, allowing remote unauthenticated attackers to gain unauthorized access to sensitive functionalities, with public exploit code increasing immediate risk.
Centrifugo JWKS Cache Authentication Bypass
2 TTPsA critical authentication bypass vulnerability exists in Centrifugo v6's dynamic JWKS endpoint feature, allowing an attacker to bypass JWT authentication for one tenant by leveraging a valid token from another tenant due to incorrect JWKS key caching indexed only by the `kid`.
joserfc: HS256/HS384/HS512 verify accepts empty/nil HMAC key (CVE-2026-49852)
1 TTPA critical vulnerability, CVE-2026-49852, exists in the Python `joserfc` library (versions `<= 1.6.7`) where HMAC-signed JSON Web Tokens can be forged, leading to complete authentication bypass, if the application is configured to verify tokens with an empty or `None` HMAC key.
SimpleSAMLphp HTTP-Artifact Authentication Bypass via TLS Validator Confusion (CVE-2026-49283)
1 TTPA critical vulnerability (CVE-2026-49283) in SimpleSAMLphp's HTTP-Artifact receive path allows a malicious or lower-trust Identity Provider (IdP) to bypass authentication and impersonate users from a higher-trust IdP by leveraging a flaw where `SOAPClient::validateSSL()` fails to properly validate TLS public keys for unsigned SAML Responses.
SimpleSAMLphp SP IdP Bypass Vulnerability (CVE-2026-49284)
3 TTPsSimpleSAMLphp's Service Provider (SP) does not properly enforce the expected Identity Provider (IdP) for an SP-initiated login when a response from a different IdP is received, allowing an attacker to exploit CVE-2026-49284 in multi-IdP deployments to bypass authentication and authorization controls by substituting a lower-trust IdP's response for a higher-trust one, potentially gaining unauthorized access or elevating privileges if application authorization relies on the specific IdP used.
motionEye Partial Authentication Bypass: Unauthenticated Admin Credential Theft via Path Traversal
1 rule 5 TTPsUnauthenticated attackers can exploit a path traversal vulnerability in motionEye versions prior to 0.44.0 to read the application's configuration file, steal the admin SHA-1 password hash, and achieve full administrative access, leading to remote code execution.
Unauthenticated Access to backpropagate UI via Authentication Bypass (CVE-2026-48797)
7 TTPs 1 CVE 3 IOCsAn authentication bypass vulnerability in `backpropagate` versions >= 1.1.0 and < 1.2.0 allows unauthenticated attackers to gain full control over the Reflex web UI, even when HTTP Basic authentication is ostensibly enabled via the `--auth` flag, permitting data exfiltration, arbitrary training runs, HuggingFace Hub push, disk-fill DoS, and sensitive path discovery.
CVE-2026-56081: Cap-go Authentication Logic Flaw Leading to Account Takeover
2 rules 2 TTPsAn authentication logic flaw in Cap-go versions prior to 12.128.2 allows attackers to register an account with a victim's unverified email address, then enable two-factor authentication on this pre-registered account to gain full control, read/modify data, enforce organization-level policies, and deny the legitimate user access.
CVE-2026-56073: Cap-go OTP Verification Authentication Bypass
2 rules 2 TTPsCap-go versions prior to 12.128.2 are susceptible to an authentication bypass vulnerability (CVE-2026-56073) in OTP verification that allows attackers to manipulate server responses to falsely mark verification successful, leading to unauthorized 2FA enablement and subsequent account takeover.
Critical Azure AD Improper Authentication Vulnerability (CVE-2026-45480)
2 rules 2 TTPsA critical improper authentication vulnerability, CVE-2026-45480, in Microsoft Azure Active Directory allows an unauthorized attacker to bypass authentication mechanisms and elevate privileges over a network, potentially leading to full administrative control of Azure AD and associated resources.
PHP JWT Framework Algorithm Confusion Vulnerability (TOCTOU)
2 rules 2 TTPsA Time-of-Check/Time-of-Use (TOCTOU) vulnerability exists in the `JWSVerifier` and `JWEDecrypter` components of the `web-token/jwt-framework` and `web-token/jwt-library` PHP packages, allowing an attacker to override the integrity-protected `alg` parameter from the unprotected header, leading to authentication bypass and unauthorized access.
PraisonAI A2U Incomplete Authentication Fix (GHSA-jxcw-qp4h-6jfq)
3 rules 3 TTPsAn incomplete fix in PraisonAI's `praisonai serve a2u` command leaves the A2U Agent-to-User event stream server unauthenticated by default, potentially exposing sensitive agent event streams to any attacker who can reach the server, bypassing intended authentication mechanisms for versions `4.5.115` to `4.6.60`.
PraisonAI Authentication Bypass via PRAISONAI_CALL_AUTH=disabled
2 rules 7 TTPsA high-severity authentication bypass vulnerability in PraisonAI versions prior to 4.6.61 allows unauthenticated attackers to invoke any registered agent by setting the `PRAISONAI_CALL_AUTH=disabled` environment variable, potentially leading to arbitrary code execution or system compromise.
Praisonai-platform Critical Authentication Bypass Due to Persistent Hardcoded JWT Secret
2 rules 4 TTPs 1 IOCPraisonai-platform versions up to and including 0.1.4 are vulnerable to a critical authentication bypass stemming from a hardcoded JWT signing secret ('dev-secret-change-me') and a bypassed production guard, allowing unauthenticated attackers to forge JSON Web Tokens (JWTs) and impersonate any user, leading to complete access, privilege escalation to workspace owner, and potential resource destruction.
PraisonAI Platform Vulnerable to JWT Forgery via Hardcoded Default Secret
2 rules 4 TTPs 3 IOCsThe `praisonai-platform` package, versions 0.1.4 and below, is critically vulnerable to authentication bypass and privilege escalation due to a hardcoded default JWT signing secret (`dev-secret-change-me`) that is inadvertently enabled in default deployments, allowing an unauthenticated attacker to forge JWTs and impersonate any user.
CVE-2026-49952: Discuz! X5.0 Authentication Bypass Leading to Database Access
2 rules 6 TTPs 1 CVE 1 IOCCVE-2026-49952 is an authentication bypass vulnerability in Discuz! X5.0 versions 20260320 through 20260501, allowing unauthenticated remote attackers to gain unauthorized access to database backup and restore functionality by exploiting a shared cryptographic key, leading to potential data exfiltration and user impersonation.
CVE-2026-10288 - code-projects Hotel and Tourism Reservation System Authentication Bypass
2 rules 2 TTPs 1 CVECVE-2026-10288 is a high severity vulnerability in code-projects Hotel and Tourism Reservation System 1.0, allowing remote attackers to bypass authentication via manipulation of the Password argument in the /admin/login.php file.
CVE-2026-29000: pac4j JWT Authentication Bypass Vulnerability
2 rules 3 TTPs 1 CVE 4 IOCsA public exploit is available for CVE-2026-29000, a critical authentication bypass vulnerability in pac4j's JWT implementation, allowing attackers to forge admin tokens without a valid signature by exploiting flaws in the library's handling of unsigned tokens and JWE-wrapped tokens.
Stigmem Node Authentication Bypass Vulnerability
2 rules 1 TTPStigmem nodes configured with authentication disabled could grant broad read/write/federation capabilities if exposed outside a loopback-only local development environment, leading to privilege escalation if exposed to untrusted networks; version 0.9.0a2 addresses this issue by disabling unauthenticated operations outside of loopback environments.
CVE-2026-3655: WordPress OTP Login Plugin Authentication Bypass Vulnerability
2 rules 1 TTP 1 CVEThe OTP Login With Phone Number, OTP Verification plugin for WordPress versions 1.8.50 through 1.8.60 is vulnerable to authentication bypass due to improper validation of the Firebase session, allowing unauthenticated attackers to authenticate as arbitrary users, including administrators, by supplying a victim's phone number.
ZTE ZXHN H188A V6 Authentication Bypass Vulnerability
2 rules 1 TTPA public exploit is available for an authentication bypass vulnerability affecting ZTE ZXHN H188A V6, increasing the risk to unpatched devices.
Starlette Framework Authentication Bypass Vulnerability (CVE-2026-48710)
2 rules 1 TTP 1 CVECVE-2026-48710, also known as BadHost, is an authentication bypass vulnerability affecting the Starlette framework before version 1.0.1, and related frameworks like FastAPI, vLLM, and LiteLLM, due to a lack of input sanitization on host header paths, potentially allowing attackers to access sensitive data and steal credentials.
phpMyFAQ Authentication Bypass Vulnerability (CVE-2026-35675)
2 rules 1 TTP 1 CVEphpMyFAQ before version 4.1.3 is vulnerable to an authentication bypass in the password reset endpoint, allowing unauthenticated attackers to reset any user account password without token verification or email confirmation, potentially leading to complete account takeover, including administrative access.
Symfony X509Authenticator Identity Spoofing Vulnerability (CVE-2026-45063)
2 rules 1 TTPSymfony's X509Authenticator is vulnerable to identity spoofing due to an unanchored regex in the extraction of the user identifier from the Subject DN of client certificates, allowing attackers to authenticate as other users by crafting a certificate with a malicious CN value.
IBM Operations Analytics and SmartCloud Analytics Default Password Vulnerability (CVE-2026-7365)
2 rules 1 TTP 1 CVEIBM Operations Analytics - Log Analysis and IBM SmartCloud Analytics - Log Analysis use default passwords from the manufacturing process, potentially allowing attackers to bypass authentication.
CVE-2025-13392 - Synology DiskStation Manager (DSM) Authentication Bypass
2 rules 1 TTP 1 CVESynology DiskStation Manager (DSM) before 7.2.2-72806-5 and 7.3.1-86003-1 is vulnerable to improper checks for unusual or exceptional conditions in SSO, allowing remote attackers to bypass authentication with prior knowledge of the distinguished name (DN).
CVE-2026-8994 - WordPress Login with NEAR Plugin Authentication Bypass
2 rules 1 TTP 1 CVEThe Login with NEAR plugin for WordPress is vulnerable to authentication bypass due to the `ajaxLoginWithNear()` function issuing valid authentication cookies based on a substring check of the `account` POST parameter, allowing unauthenticated attackers to log in as existing users or create new accounts.
CVE-2026-8760: WordPress Login with OTP Plugin Authentication Bypass
2 rules 1 TTP 2 CVEsThe Login with OTP plugin for WordPress is vulnerable to authentication bypass due to an incomplete fix for CVE-2024-11178, allowing unauthenticated attackers to brute-force OTP codes and gain administrative access.
code100x Mobile API Authentication Bypass Vulnerability (CVE-2026-8890)
2 rules 2 TTPscode100x Mobile API contains an authentication bypass vulnerability (CVE-2026-8890) allowing unauthenticated attackers to impersonate arbitrary users by crafting a JSON payload in the 'g' HTTP header, skipping identity header validation and granting unauthorized access to course data.
WordPress Temporary Login Plugin Authentication Bypass Vulnerability
2 rules 1 TTPA public exploit is available for WordPress Temporary Login Plugin version 1.0.0, which demonstrates an authentication bypass vulnerability that can lead to account takeover, increasing the risk for unpatched systems.
CVE-2026-33843 Authentication Bypass in Microsoft Azure Active Directory B2C
2 rules 1 TTP 1 CVECVE-2026-33843 allows an unauthorized attacker to elevate privileges over a network in Microsoft Azure Active Directory B2C due to an authentication bypass using an alternate path or channel.
Network-AI Unauthenticated Cross-Origin MCP Tool Invocation via Empty Default Secret (CVE-2026-46701)
2 rules 1 TTPNetwork-AI is vulnerable to an unauthenticated cross-origin attack due to an empty default secret and permissive CORS configuration, allowing an attacker to lure a user to a malicious web page and invoke MCP tools like config_set, agent_spawn, and blackboard_write against a default-configured localhost server.
Fission StorageSvc Unauthenticated Archive CRUD Vulnerability
2 rules 6 TTPsThe Fission `storagesvc` component exposes unauthenticated CRUD operations on the `/v1/archive` endpoint, allowing any workload within the same Kubernetes cluster to enumerate archive IDs, download archives, upload arbitrary content, and delete archives, leading to potential code and secret exposure and function disruption.
Actively Exploited Vulnerabilities in Sparx Pro Cloud Server and Enterprise Architect
2 rules 3 TTPs 5 CVEsMultiple vulnerabilities, including a critical authentication bypass (CVE-2026-42097), affect Sparx Systems Pro Cloud Server and Enterprise Architect, potentially leading to remote code execution and data compromise; active exploitation is likely given available PoCs.
Taiko AG1000-01A SMS Alert Gateway Authentication Bypass (CVE-2026-9141)
2 rules 1 TTP 1 CVETaiko AG1000-01A SMS Alert Gateway Rev 7.3 and Rev 8 contains an authentication bypass vulnerability (CVE-2026-9141) in the embedded web configuration interface, allowing unauthenticated attackers to access internal application pages, modify alarm routing, and disrupt monitoring and control functions.
phpMyFAQ Authentication Bypass Allows Account Takeover
2 rulesAn authentication bypass vulnerability in phpMyFAQ allows an unauthenticated attacker to reset the password of any user account, including SuperAdmin accounts, by sending a PUT request with a valid username and associated email address to /api/user/password/update, resulting in complete account takeover.
MCP Gateway Authority Injection and JWT/Session Bypass via Unauthenticated Router Hairpin
2 rules 2 TTPsThe MCP router exposes an initialize method code path that bypasses the gateway JWT session validator and rewrites the upstream :authority header, gated only by a shared header value, allowing attackers to bypass authorization and access backend services.
ZKTeco CCTV Authentication Bypass Vulnerability
2 rules 1 TTP 1 IOCZKTeco CCTV cameras are vulnerable to authentication bypass due to an undocumented configuration export port that does not require authentication and exposes critical information about the camera, such as open services and account credentials, as tracked by CVE-2026-8598.
Multiple Vulnerabilities in SonicWall Firewalls Allow Remote Code Execution and Privilege Escalation
1 rule 3 TTPs 4 CVEsMultiple vulnerabilities have been disclosed in SonicWall Gen6 and Gen7 firewalls, SonicOS, and NSv that can be exploited for authentication bypass, remote code execution, and privilege escalation, specifically CVE-2024-40762, CVE-2024-53704, CVE-2024-53705, and CVE-2024-53706; a proof of concept exploit is available for CVE-2024-53704, which, if exploited, can lead to internal network access and further attacks, including ransomware deployment.
HestiaCP IP Spoofing Vulnerability (CVE-2026-43634)
2 rules 1 TTP 1 CVEHestiaCP versions 1.2.0 through 1.9.4 are vulnerable to IP spoofing (CVE-2026-43634), allowing unauthenticated remote attackers to bypass authentication security controls by manipulating the CF-Connecting-IP HTTP header to circumvent fail2ban, bypass IP allowlists, and poison authentication logs.
Arcane Git Repository Authentication Bypass Leads to Credential Exfiltration and GitOps Tampering (CVE-2026-45625)
2 rules 5 TTPs 1 IOCArcane's REST API lacks proper admin authorization checks on Git repository management endpoints, allowing any authenticated user to exfiltrate stored Git credentials and tamper with GitOps configurations by redirecting credential requests to an attacker-controlled host.
phpMyFAQ Unauthenticated TOTP Bypass via Brute-Force (CVE-2026-45010)
2 rules 1 TTP 1 CVEphpMyFAQ before 4.1.2 is vulnerable to improper restriction of excessive authentication attempts in the /admin/check endpoint, allowing unauthenticated attackers to brute-force any user's six-digit TOTP code and bypass two-factor authentication, potentially gaining full administrative access (CVE-2026-45010).
AVideo Meet Plugin Authorization Bypass via Filename Parameter
2 rules 2 TTPsAVideo's Meet plugin contains an authorization bypass vulnerability in the `uploadRecordedVideo.json.php` endpoint that derives `users_id` from the uploaded filename and calls passwordless `User->login()`, allowing any caller with the Meet shared secret to obtain a session as arbitrary users including admin.
WordPress Form Notify Plugin Authentication Bypass Vulnerability (CVE-2026-5229)
2 rules 1 TTP 1 CVEThe Form Notify plugin for WordPress is vulnerable to CVE-2026-5229, an authentication bypass, due to trusting user-controlled cookie data after a LINE OAuth login, allowing unauthenticated attackers to gain administrative access.
Crabbox Authentication Bypass via Header Spoofing (CVE-2026-8621)
2 rules 1 TTP 1 CVECrabbox prior to v0.12.0 contains an authentication bypass vulnerability (CVE-2026-8621) that allows non-admin shared-token callers to impersonate other owners or organizations by spoofing identity headers, granting unauthorized access to lease operations.
Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability
2 rules 2 TTPs 2 CVEs 5 IOCsA vulnerability in the peering authentication of Cisco Catalyst SD-WAN Controller and Manager (CVE-2026-20182) could allow a remote, unauthenticated attacker to bypass authentication and obtain administrative privileges by sending crafted requests.
Fleet Windows MDM Management Endpoint Authentication Bypass Vulnerability
2 rules 2 TTPs 1 IOCCVE-2026-23998 describes a vulnerability in Fleet's Windows MDM management endpoint that allows requests to be processed without proper client certificate validation, potentially allowing an attacker to impersonate a device and retrieve sensitive configuration data.
ePati Antikor NGFW 2.0.1301 Authentication Bypass Vulnerability
1 rule 1 TTPA public exploit has been published for ePati Antikor NGFW 2.0.1301, exploiting an authentication bypass vulnerability, increasing the risk to unpatched systems.
Burst Statistics WordPress Plugin Authentication Bypass (CVE-2026-8181)
1 rule 1 TTP 1 CVEThe Burst Statistics plugin for WordPress is vulnerable to authentication bypass, allowing unauthenticated attackers with knowledge of an administrator username to impersonate that administrator by supplying a random Basic Authentication password, leading to privilege escalation.
Huawei HG630 V2 Router Authentication Bypass Vulnerability (CVE-2020-37220)
2 rules 1 TTP 1 CVEHuawei HG630 V2 router contains an authentication bypass vulnerability (CVE-2020-37220) that allows unauthenticated attackers to obtain administrative access by retrieving the device serial number via the `/api/system/deviceinfo` endpoint and using the last 8 characters as the default password.
CVE-2026-0257 PAN-OS GlobalProtect Authentication Bypass Vulnerability
1 rule 1 TTPAn authentication bypass vulnerability exists in Palo Alto Networks PAN-OS GlobalProtect portal and gateway (CVE-2026-0257) when authentication override cookies are enabled, allowing an attacker to establish an unauthorized VPN connection.
CVE-2026-0265 PAN-OS Authentication Bypass with Cloud Authentication Service (CAS)
2 rules 1 TTPCVE-2026-0265 is an authentication bypass vulnerability in Palo Alto Networks PAN-OS when Cloud Authentication Service (CAS) is enabled, allowing an unauthenticated attacker with network access to bypass authentication controls, impacting confidentiality, integrity, and availability.
CVE-2026-4609: ProfileGrid WordPress Plugin Authentication Bypass Vulnerability
1 rule 1 TTP 1 CVEThe ProfileGrid WordPress plugin versions up to 5.9.8.4 contain an authentication bypass vulnerability (CVE-2026-4609) that allows authenticated users with subscriber-level privileges to add themselves or others to arbitrary groups, including paid groups, without proper authorization, leading to privilege escalation and potential financial impact.
Flowise < 3.0.5 Missing Authentication Vulnerability Exploitable
2 rules 1 TTPA missing authentication vulnerability in Flowise versions prior to 3.0.5 allows attackers to perform critical functions without authentication, and a working exploit is publicly available on Exploit-DB.
SillyTavern Authentication Bypass via HTTP Header Injection (CVE-2026-44649)
2 rules 1 TTPSillyTavern versions 1.17.0 and earlier are vulnerable to an authentication bypass (CVE-2026-44649) via HTTP header injection, where the application accepts Remote-User and X-Authentik-Username headers for SSO without proper validation, allowing attackers to impersonate any user, including administrators, if SSO is enabled.
CVE-2026-33117: Azure SDK Improper Authentication Vulnerability
2 rules 1 TTP 1 CVECVE-2026-33117 is a critical vulnerability in the Azure SDK that allows an unauthorized attacker to bypass a security feature over a network due to improper authentication.
Multiple Vulnerabilities in Red Hat Build of Keycloak
2 rules 5 TTPsMultiple vulnerabilities in Red Hat Build of Keycloak could allow an attacker to bypass authentication, gain elevated privileges, disclose sensitive information, cause a denial of service condition, execute arbitrary code, or manipulate data.
Inkeep Agents Authentication Bypass Vulnerability (CVE-2026-8321)
1 rule 1 TTP 1 CVECVE-2026-8321 is an authentication bypass vulnerability in the createDevContext function of Inkeep Agents 0.58.14, allowing remote attackers to bypass authentication via alternate channels.
OpenClaw Improper Authentication Vulnerability (CVE-2026-8305)
2 rules 1 TTP 1 CVEOpenClaw versions up to 2026.1.24 are vulnerable to improper authentication in the handleBlueBubblesWebhookRequest function, allowing remote exploitation and requiring an upgrade to version 2026.2.12 or application of patch a6653be0265f1f02b9de46c06f52ea7c81a836e6 to remediate CVE-2026-8305.
Bitwarden Server SCIM API Key Authentication Bypass (CVE-2026-43640)
2 rules 1 TTP 1 CVEBitwarden Server before v2026.4.1 allows an authenticated user with SCIM management privileges to bypass master-password re-authentication when retrieving or rotating an organization's SCIM API key, potentially leading to unauthorized access.
Unity Catalog JWT Issuer Validation Bypass Allows User Impersonation (CVE-2026-27478)
1 rule 2 TTPs 1 CVEA critical authentication bypass vulnerability exists in the Unity Catalog token exchange endpoint (CVE-2026-27478), allowing attackers to impersonate any user by forging JWTs with a self-controlled issuer and exchanging them for valid access tokens, granting unauthorized access to catalogs and other resources.
Next.js i18n Pages Router Middleware Authentication Bypass (CVE-2026-44573)
2 rules 1 TTPNext.js applications using the Pages Router with `i18n` and middleware-based authorization are vulnerable to an authentication bypass (CVE-2026-44573), allowing unauthorized access to protected page data via locale-less `/_next/data/<buildId>/<page>.json` requests.
Dozzle Cross-Site WebSocket Hijacking (CSWSH) Vulnerability
2 rules 2 TTPsDozzle is vulnerable to Cross-Site WebSocket Hijacking (CSWSH) due to a permissive CheckOrigin configuration and the use of SameSite=Lax for JWT cookies, allowing attackers on the same site to gain shell access to containers even with authentication enabled, tracked as CVE-2026-44985.
PraisonAI Legacy API Server Authentication Bypass (CVE-2026-44338)
2 rules 1 TTP 1 CVEPraisonAI ships a legacy Flask API server with authentication disabled by default, allowing any reachable caller to access `/agents` and trigger the configured `agents.yaml` workflow through `/chat` without providing a token (CVE-2026-44338).
free5GC SMF Unauthenticated UPI Access
2 rules 1 TTP 2 IOCsfree5GC's Session Management Function (SMF) UPI interface lacks authentication, allowing unauthenticated network attackers to read/write/delete UP-node and link topology data via exposed APIs.
MailEnable Enterprise Premium Authentication Bypass Vulnerability (CVE-2026-44400)
2 rules 1 TTP 1 CVEMailEnable Enterprise Premium 10.55 and earlier is vulnerable to CVE-2026-44400, an improper authorization vulnerability that allows attackers to bypass authentication checks and perform administrative actions by reusing AuthenticationToken cookies.
Open WebUI /responses Endpoint Authentication Bypass Vulnerability
2 rulesThe /responses endpoint in Open WebUI's OpenAI router lacks access control, allowing authenticated users to bypass per-model access controls and interact with any configured model, potentially leading to denial of service, model theft, and access policy bypass.
Open WebUI LDAP Empty Password Authentication Bypass
2 rules 1 TTPOpen WebUI is vulnerable to an LDAP authentication bypass where the LDAP authentication endpoint does not validate that the submitted password is non-empty before performing a Simple Bind against the LDAP server, potentially granting attackers complete account access.
OpenTelemetry Collector Azure Auth Extension Authentication Bypass
2 rules 1 TTPA server-side authentication bypass vulnerability exists in opentelemetry-collector-contrib's azureauthextension versions 0.124.0 through 0.150.0, allowing attackers with a valid Azure access token to authenticate to any OpenTelemetry receiver that uses `auth: azure_auth` due to improper JWT validation.
Nginx-UI Unauthenticated Remote Code Execution via Backup Restore
2 rules 2 TTPsNginx-UI is vulnerable to unauthenticated remote code execution (RCE) via the `POST /api/restore` endpoint, allowing attackers to inject arbitrary commands into the configuration.
Cisco Identity Services Engine Authentication Bypass Vulnerabilities
2 rules 1 TTPMultiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow a remote attacker to bypass authorization mechanisms or examine error messages to gain access to sensitive information.
WordPress Easy PayPal Events & Tickets Plugin Authentication Bypass Vulnerability
2 rules 1 TTP 1 CVE 1 IOCAn unauthenticated remote attacker can exploit a hardcoded authentication bypass vulnerability in the Easy PayPal Events & Tickets plugin for WordPress (versions 1.3 and earlier) by providing 'test' as the hash parameter, allowing retrieval of sensitive order details.
Quarkus Vertx HTTP Authorization Bypass via Matrix Parameters
2 rules 2 TTPsQuarkus Vertx HTTP versions < 3.20.6.1, >= 3.21.0 and < 3.27.3.1, >= 3.30.0 and < 3.33.1.1, and >= 3.34.0 and < 3.35.1.1 are vulnerable to an authorization bypass where appending a semicolon and arbitrary text to the request URL allows unauthorized access to protected resources.
Critical Authentication Bypass Vulnerability in MOVEit Automation (CVE-2026-4670)
2 rules 2 TTPs 2 CVEsA critical authentication bypass vulnerability (CVE-2026-4670) in Progress MOVEit Automation allows an unauthenticated remote attacker to gain administrative access, potentially leading to full control over the application and sensitive file transfer workflows.
AAP Gateway Account Hijacking Vulnerability (CVE-2026-6266)
2 rules 1 TTP 1 CVECVE-2026-6266 allows a remote attacker to hijack user accounts in AAP gateway by manipulating the IDP-provided email during the user auto-linking process, potentially gaining unauthorized access, including administrative privileges.
YunaiV yudao-cloud Authentication Bypass Vulnerability (CVE-2026-7710)
2 rules 1 TTP 1 CVEYunaiV yudao-cloud up to version 3.8.0 is vulnerable to an authentication bypass (CVE-2026-7710) due to improper handling of the mock-token argument in the JwtAuthenticationTokenFilter.java file, allowing remote attackers to bypass authentication.
InnoShop Improper Authentication Vulnerability (CVE-2026-7630)
2 rules 1 TTP 1 CVEInnoShop version 0.7.8 and earlier contains an improper authentication vulnerability in the InstallServiceProvider::boot function (CVE-2026-7630) that allows remote attackers to bypass authentication and gain unauthorized access to the installation endpoint.
WordPress User Verification Plugin Authentication Bypass Vulnerability
2 rules 1 TTP 1 CVEThe User Verification by PickPlugins plugin for WordPress is vulnerable to authentication bypass in versions up to 2.0.46 due to a loose PHP comparison, allowing unauthenticated attackers to log in as any verified user by submitting a 'true' OTP value.
WordPress Temporary Login Plugin Authentication Bypass (CVE-2026-7567)
2 rules 1 TTP 1 CVEThe Temporary Login plugin for WordPress versions up to 1.0.0 is vulnerable to authentication bypass due to improper input validation, allowing unauthenticated attackers to log in as arbitrary temporary users by sending a specially crafted GET request.
Critical Authentication Bypass Vulnerability in cPanel & WHM (CVE-2026-41940)
2 rules 1 TTP 1 CVECVE-2026-41940 is a critical authentication bypass vulnerability in cPanel & WHM, allowing unauthenticated remote attackers to gain administrative access by manipulating session data.
ABB Edgenius Management Portal Authentication Bypass Vulnerability
2 rules 1 TTP 1 CVEAn authentication bypass vulnerability in ABB Edgenius Management Portal versions 3.2.0.0 and 3.2.1.1 allows attackers to execute arbitrary code and modify application configurations by sending a specially crafted message to the system node.
ABB Ability OPTIMAX Authentication Bypass Vulnerability
2 rules 1 TTP 1 CVECVE-2025-14510 allows an attacker to bypass Azure Active Directory Single-Sign On authentication in vulnerable ABB Ability OPTIMAX versions, potentially granting unauthorized access to critical infrastructure systems.
cPanel and WHM Authentication Bypass Vulnerability (CVE-2026-41940)
2 rules 1 TTP 1 CVEAn authentication bypass vulnerability in cPanel and WHM versions prior to 11.110.0.97, 11.118.0.63, 11.126.0.54, 11.132.0.29, 11.134.0.20, and 11.136.0.5 allows unauthenticated remote attackers to gain unauthorized access to the control panel.
Multiple Vulnerabilities in Spring Boot Allow Authorization Bypass and Potential RCE
2 rules 3 TTPs 3 CVEsMultiple vulnerabilities in Spring Boot, including CVE-2026-40976, CVE-2026-40973, and CVE-2026-40972, can allow attackers to bypass authorization, hijack sessions, or achieve remote code execution, potentially leading to data breaches and system compromise.
OpenSSH Authentication Bypass Vulnerability
2 rules 1 TTPA vulnerability in OpenSSH could allow for authentication bypass, potentially granting an attacker root access to vulnerable servers running the protocol.
SmythOS sre Authentication Bypass Vulnerability (CVE-2026-7022)
2 rules 1 TTP 1 CVEA remote improper authentication vulnerability exists in SmythOS sre up to version 0.0.15, allowing attackers to bypass authentication by manipulating the X-DEBUG-RUN/X-DEBUG-INJ arguments in the HTTP Header Handler component.
Traefik ForwardAuth Authentication Bypass via Header Spoofing
2 rules 1 TTP 2 CVEsTraefik's `ForwardAuth` and snippet-based authentication middleware has a high severity authentication bypass vulnerability because it does not sanitize header aliases with underscores, allowing attackers to spoof trust context and bypass authentication on protected routes.
Multiple Vulnerabilities in Cisco Products Allow for Remote Code Execution
2 rules 4 TTPs 3 CVEsMultiple vulnerabilities in Cisco ASA, Secure Firewall Threat Defense, IOS, IOS XE, and IOS XR allow a remote attacker to bypass authentication and execute arbitrary code with administrator privileges.
OpenVPN-auth-oauth2 Authentication Bypass in Plugin Mode
2 rules 1 TTPA critical authentication bypass vulnerability exists in openvpn-auth-oauth2 versions 1.26.3 through 1.27.2 when deployed in the experimental plugin mode; clients that do not support WebAuth/SSO are incorrectly granted VPN access without completing OIDC authentication.
NVIDIA KAI Scheduler Authentication Bypass Vulnerability
2 rules 2 TTPs 1 CVECVE-2026-24177 describes an authentication bypass vulnerability in NVIDIA KAI Scheduler that could allow unauthorized access to API endpoints, leading to information disclosure.
JetBrains TeamCity Authentication Bypass and Path Traversal Vulnerabilities
2 rules 1 TTP 2 CVEsUnpatched JetBrains TeamCity servers are being actively exploited via an authentication bypass (CVE-2024-27198) and path traversal vulnerability (CVE-2024-27199), allowing attackers to perform administrative actions and potentially conduct supply-chain attacks.
Rowboatlabs Rowboat Improper Authentication Vulnerability (CVE-2026-6635)
2 rules 1 TTP 1 CVEAn improper authentication vulnerability in rowboatlabs rowboat <=0.1.67 allows remote attackers to bypass authentication by manipulating the X-Tools-JWE argument in the tool_call function, potentially leading to unauthorized access and control.
liangliangyy DjangoBlog Authentication Bypass Vulnerability (CVE-2026-6577)
2 rules 1 TTP 1 CVEA critical authentication bypass vulnerability in liangliangyy DjangoBlog up to version 2.1.0.0 (CVE-2026-6577) allows remote attackers to inject arbitrary GPS data without authentication via the logtracks endpoint, potentially leading to data manipulation and unauthorized access.
FastGPT NoSQL Injection Vulnerability (CVE-2026-40351)
2 rules 1 TTP 1 CVEFastGPT versions before 4.14.9.5 are vulnerable to NoSQL injection, allowing unauthenticated attackers to bypass authentication and gain administrative access.
Anviz CX2 Lite and CX7 Unauthenticated Debug Setting Modification
2 rules 1 TTP 1 CVEAnviz CX2 Lite and CX7 devices are vulnerable to unauthenticated POST requests that allow modification of debug settings such as enabling SSH, leading to unauthorized state changes and potential compromise.
OpenViking Authentication Bypass Vulnerability (CVE-2026-40525)
2 rules 1 TTP 1 CVEOpenViking versions prior to commit c7bb167 are vulnerable to an authentication bypass that allows remote attackers to invoke privileged bot-control functionality without authentication when the api_key configuration is unset or empty, potentially leading to unauthorized access to downstream systems and data.
Paperclip Unauthenticated API Access Vulnerability
2 rules 3 TTPsPaperclip application suffers from multiple unauthenticated API access vulnerabilities allowing attackers to access sensitive data, gather reconnaissance, and potentially bypass authentication.
Velociraptor Authentication Bypass via query() Plugin
2 rules 2 TTPs 1 CVEVelociraptor versions prior to 0.76.3 contain an authentication bypass vulnerability in the query() plugin, allowing authenticated users to access data from other organizations within the Velociraptor deployment, potentially leading to unauthorized data access and privilege escalation.
OAuth2 Proxy Authentication Bypass via User-Agent Header
2 rules 1 TTPA critical authentication bypass vulnerability (CVE-2026-34457) exists in OAuth2 Proxy when used with `auth_request`-style integration and either `--ping-user-agent` is set or `--gcp-healthchecks` is enabled, allowing unauthenticated access to protected resources.
Industrial Edge Management Authentication Bypass Vulnerability (CVE-2026-33892)
2 rules 1 TTP 1 CVECVE-2026-33892 allows an unauthenticated remote attacker to bypass authentication and impersonate a legitimate user in affected Industrial Edge Management Pro and Virtual versions by exploiting improper enforcement of user authentication on remote connections to devices, potentially enabling unauthorized access and control.
SINEC NMS Authentication Bypass Vulnerability (CVE-2026-24032)
2 rules 1 TTP 1 CVE 1 IOCAn authentication bypass vulnerability (CVE-2026-24032) exists in SINEC NMS versions prior to V4.0 SP3 due to insufficient user identity validation in the UMC component, allowing unauthenticated remote attackers to gain unauthorized access.
MinIO Unauthenticated Object Write Vulnerability
2 rules 3 TTPsTwo authentication bypass vulnerabilities in MinIO allow writing arbitrary objects to any bucket with only a valid access key, without the secret key or valid signature, impacting all MinIO deployments.
zhayujie chatgpt-on-wechat CowAgent Authentication Bypass (CVE-2026-6129)
2 rules 1 TTP 1 CVECVE-2026-6129 is a critical vulnerability in zhayujie chatgpt-on-wechat CowAgent up to version 2.0.4, allowing remote attackers to bypass authentication via manipulation of the Agent Mode Service.
zhayujie chatgpt-on-wechat CowAgent Authentication Bypass Vulnerability (CVE-2026-6126)
2 rules 1 TTP 1 CVECVE-2026-6126 is an unauthenticated remote code execution vulnerability in zhayujie chatgpt-on-wechat CowAgent 2.0.4 due to missing authentication in the Administrative HTTP Endpoint.
Laravel Passport Authentication Bypass Vulnerability (CVE-2026-39976)
2 rules 1 TTP 1 CVELaravel Passport versions 13.0.0 before 13.7.1 contain an authentication bypass vulnerability (CVE-2026-39976) where machine-to-machine tokens can authenticate as a real user due to improper validation of the JWT sub claim.
LiteLLM Authentication Bypass via Password Hash Exposure and Pass-the-Hash
2 rules 1 TTPLiteLLM versions before 1.83.0 stored user passwords as unsalted SHA-256 hashes and exposed these hashes through multiple API endpoints, enabling an authenticated user to retrieve another user's password hash and use it to log in as that user due to the /v2/login endpoint accepting the raw SHA-256 hash without re-hashing, leading to potential privilege escalation.
Totolink A8000R Authentication Bypass Vulnerability (CVE-2026-5676)
2 rules 1 TTP 1 CVEA remote, unauthenticated attacker can bypass authentication on Totolink A8000R routers running firmware version 5.9c.681_B20180413 by manipulating the `langType` argument in the `setLanguageCfg` function of the `/cgi-bin/cstecgi.cgi` file.
Mattermost Legal Hold Plugin Authentication Bypass Vulnerability
2 rules 2 TTPs 1 CVEMattermost Legal Hold plugin versions 1.1.4 and earlier allow authenticated attackers to bypass authorization checks, enabling unauthorized access and modification of legal hold data via crafted API requests.
GPT Researcher Authentication Bypass Vulnerability (CVE-2026-5632)
2 rules 1 TTP 1 CVECVE-2026-5632 is an authentication bypass vulnerability in assafelovic gpt-researcher up to version 3.4.3, affecting the HTTP REST API Endpoint and allowing remote attackers to perform actions without proper authorization.
JeecgBoot AI Chat Module Authentication Bypass Vulnerability
2 rules 1 TTP 1 CVEJeecgBoot versions 3.9.0 and 3.9.1 are vulnerable to a remote unauthenticated bypass in the AI Chat Module, specifically affecting the JeecgBizToolsProvider.java file, potentially allowing unauthorized access.
Technostrobe HI-LED-WR120-G2 Improper Authentication Vulnerability (CVE-2026-5570)
2 rules 1 TTP 1 CVECVE-2026-5570 is an improper authentication vulnerability in the index_config function of the /LoginCB file of Technostrobe HI-LED-WR120-G2 version 5.5.0.1R6.03.30, allowing remote attackers to bypass authentication.
PraisonAI Gateway Unauthenticated Access Vulnerability
2 rules 1 TTP 1 CVEPraisonAI Gateway server versions prior to 4.5.97 allow unauthenticated access to WebSocket connections and agent topology, enabling unauthorized message sending and agent enumeration.
OAuthenticator Authentication Bypass Vulnerability (CVE-2026-33175)
2 rules 1 TTPOAuthenticator versions prior to 17.4.0 contain an authentication bypass vulnerability (CVE-2026-33175) that allows an attacker with an unverified email address on an Auth0 tenant to log in to JupyterHub when email is used as the username claim, potentially leading to account takeover.
Unauthenticated Access to Administrative Endpoint (CVE-2026-32646)
2 rules 1 TTP 1 CVECVE-2026-32646 allows unauthenticated access to a specific administrative endpoint, potentially exposing device management functions, with a CVSS v3.1 score of 7.5.
Critical Authentication Bypass Vulnerability in Cisco Integrated Management Controller (CVE-2026-20093)
3 rules 3 TTPs 1 CVEAn unauthenticated remote attacker can exploit CVE-2026-20093 to bypass authentication in Cisco Integrated Management Controller (IMC), gain full administrative access, and manipulate hardware settings, potentially disrupting critical infrastructure.
OneUptime SAML SSO Authentication Bypass Vulnerability (CVE-2026-34840)
2 rules 1 TTP 1 CVEOneUptime versions prior to 10.0.42 are vulnerable to an authentication bypass due to improper SAML signature validation, allowing attackers to impersonate users by prepending unsigned assertions.
Hirschmann HiEOS HTTP(S) Management Module Authentication Bypass (CVE-2024-14034)
2 rules 1 TTP 1 CVEHirschmann HiEOS devices contain an authentication bypass vulnerability (CVE-2024-14034) in the HTTP(S) management module, allowing unauthenticated remote attackers to gain administrative access by sending specially crafted HTTP(S) requests.
goshs Authentication Bypass Vulnerability (CVE-2026-34581)
1 rule 1 TTPgoshs versions 1.1.0 to before 2.0.0-beta.2 are vulnerable to authentication bypass via Share Token, potentially allowing code execution (CVE-2026-34581).
vanna-ai vanna Authentication Bypass Vulnerability (CVE-2026-5320)
2 rules 2 TTPs 1 CVECVE-2026-5320 describes an unauthenticated remote access vulnerability in vanna-ai vanna up to version 2.0.2 via manipulation of the /api/vanna/v2/ Chat API endpoint, potentially allowing unauthorized access and actions.
IBM Verify and Security Verify Access Authentication Bypass Vulnerability
2 rules 1 TTP 1 CVECVE-2026-4101 describes an authentication bypass vulnerability in IBM Verify Identity Access Container and IBM Security Verify Access Container versions 11.0 through 11.0.2 and 10.0 through 10.0.9.1, respectively, that could allow unauthorized access under specific load conditions.
Goshs Authentication Bypass via Share Token
2 rules 3 TTPs 1 IOCGoshs is vulnerable to an authentication bypass via share tokens, allowing attackers to bypass authentication checks by using a valid share token in conjunction with other functionalities like WebSocket connections to gain unauthorized access and execute arbitrary commands on the server.
Multiple Vulnerabilities in Dovecot Mail Server
2 rules 2 TTPsMultiple vulnerabilities in Dovecot can be exploited by an attacker to perform SQL injection attacks, bypass authentication, disclose sensitive information, or cause a denial-of-service condition.
OpenClaw Feishu Webhook Authentication Bypass (CVE-2026-32974)
2 rules 1 TTPOpenClaw before 2026.3.12 is vulnerable to an authentication bypass in Feishu webhook mode when only verificationToken is configured without encryptKey, allowing unauthenticated network attackers to inject forged Feishu events and trigger downstream tool execution.
OpenBao OIDC Direct Callback Authentication Bypass Vulnerability
2 rules 1 TTPOpenBao versions before 2.5.2 lack user confirmation for OIDC direct callback mode, allowing attackers to perform remote phishing and bypass authentication.
Wecodex Hotel CMS 1.0 SQL Injection Vulnerability
2 rules 1 TTPWecodex Hotel CMS 1.0 is vulnerable to SQL injection in the admin login functionality, allowing unauthenticated attackers to bypass authentication and potentially extract sensitive database information or gain administrative access by injecting SQL code through the username parameter in POST requests to index.php with action=processlogin.
MacCMS 2025.1000.4052 Missing Authentication Vulnerability (CVE-2026-4562)
2 rules 1 TTPA missing authentication vulnerability exists in MacCMS 2025.1000.4052, specifically affecting the Timming API Endpoint component in application/api/controller/Timming.php, allowing remote attackers to bypass authentication.
Contest Gallery WordPress Plugin Authentication Bypass Vulnerability (CVE-2026-4021)
2 rules 3 TTPsCVE-2026-4021 describes an authentication bypass vulnerability in the Contest Gallery plugin for WordPress, allowing unauthenticated attackers to gain admin access by manipulating the user activation key and using an AJAX login endpoint.
Critical Vulnerabilities in Quest KACE SMA Allow System Takeover
2 rules 4 TTPsMultiple critical vulnerabilities in Quest KACE Systems Management Appliance (SMA), including authentication bypass and 2FA bypass, allow unauthenticated attackers to achieve system takeover and cause denial of service; active exploitation is reported.
Apache Artemis and ActiveMQ Artemis Authentication Bypass Vulnerability
2 rules 5 TTPsCVE-2026-27446 allows an unauthenticated remote attacker to inject malicious messages or exfiltrate data from Apache Artemis and ActiveMQ Artemis brokers due to a missing authentication check in the Core protocol.
Pelco Sarix Pro 3 Series IP Camera Authentication Bypass Vulnerability
2 rules 1 TTPAn authentication bypass vulnerability (CVE-2026-1241) in the web management interface of Pelco Sarix Pro 3 Series IP Cameras (versions <= 02.52) allows unauthenticated attackers to access sensitive device data and bypass surveillance controls.
Traefik ForwardAuth Authentication Bypass via X-Forwarded-Prefix Spoofing
2 rules 1 TTPA high-severity authentication bypass vulnerability exists in Traefik's `ForwardAuth` middleware when `trustForwardHeader=false` is configured and Traefik is deployed behind a trusted upstream proxy; Traefik fails to sanitize the `X-Forwarded-Prefix` header, allowing attackers to spoof a trusted prefix value and gain unauthorized access to protected backend routes.
Ivanti VTM Administrator Account Creation via CVE-2024-7593
2 rules 2 TTPs 1 CVEUnauthenticated remote attackers are exploiting CVE-2024-7593 in Ivanti Virtual Traffic Manager (vTM) to bypass authentication and create new administrator accounts, potentially leading to full system compromise.
OpenStack Keystone LDAP Authentication Bypass Vulnerability (CVE-2026-40683)
2 rules 3 TTPs 1 CVEOpenStack Keystone before 28.0.1 is vulnerable to an authentication bypass due to improper handling of the user enabled attribute in the LDAP identity backend when the user_enabled_invert configuration option is False, leading to disabled users being treated as enabled.
JetBrains TeamCity Authentication Bypass Vulnerability (CVE-2024-27198)
2 rules 1 TTPExploitation of CVE-2024-27198 in JetBrains TeamCity allows unauthenticated attackers to bypass authentication and gain administrative access by sending malicious HTTP POST requests to specific API endpoints.
Dgraph Unauthenticated Admin Token Disclosure via /debug/vars
3 rules 2 TTPsDgraph versions prior to 25.3.3 expose the admin token via the `/debug/vars` endpoint, allowing unauthenticated attackers to bypass authentication and gain administrative access.
ConnectWise ScreenConnect Authentication Bypass Vulnerability Exploitation
2 rules 1 TTP 2 CVEsExploitation of CVE-2024-1709 in ConnectWise ScreenConnect allows attackers to bypass authentication via the SetupWizard.aspx endpoint, potentially leading to unauthorized administrative access and remote code execution.
@fastify/express Authentication Bypass via URL Normalization Gaps
2 rules 1 TTP 1 CVEA vulnerability exists in `@fastify/express` v4.0.4 that allows complete bypass of path-scoped authentication middleware via URL normalization gaps, specifically through duplicate slashes and semicolon delimiters, leading to unauthorized access to protected routes.
PromtEngineer localGPT Missing Authentication Vulnerability (CVE-2026-5000)
2 rules 1 TTPA missing authentication vulnerability (CVE-2026-5000) exists in PromtEngineer localGPT's API Endpoint, allowing remote attackers to bypass authentication by manipulating the BaseHTTPRequestHandler argument, potentially leading to unauthorized access and data manipulation.
PrefectHQ Prefect Authentication Bypass Vulnerability (CVE-2026-7723)
2 rules 1 TTP 1 CVEPrefectHQ Prefect versions up to 3.6.13 are vulnerable to an authentication bypass via manipulation of the /api/events/in WebSocket endpoint, potentially allowing remote attackers to execute unauthorized actions.
OAuth2 Proxy Authentication Bypass via X-Forwarded-Uri Header Spoofing
2 rules 1 TTP 2 CVEsOAuth2 Proxy is vulnerable to an authentication bypass when configured with `--reverse-proxy` and `--skip_auth_routes` or `--skip_auth_regex`; by spoofing the `X-Forwarded-Uri` header, an attacker can bypass authentication and access protected routes without a valid session.
AVideo Unauthenticated Access to Payment Log DataTables Endpoints
2 rules 2 TTPs 3 IOCsAVideo is vulnerable to unauthenticated access to multiple `list.json.php` endpoints due to missing authorization checks, allowing attackers to retrieve sensitive payment transaction records, including PayPal billing agreement IDs, Express Checkout tokens, Authorize.Net webhook payloads, and Bitcoin payment records, leading to financial data exposure and potential PII leakage.
Tandoor Recipes Authentication Bypass Vulnerability (CVE-2026-35045)
2 rules 1 TTP 1 CVETandoor Recipes before version 2.6.4 allows authenticated users within a space to modify any recipe in that space, including private ones, via the PUT /api/recipe/batch_update/ endpoint, bypassing object-level authorization checks and enabling unauthorized access and data tampering.
goshs SimpleHTTPServer SFTP Authentication Bypass Vulnerability (CVE-2026-40884)
2 rules 1 TTP 1 CVEgoshs SimpleHTTPServer prior to version 2.0.0-beta.6 contains an SFTP authentication bypass vulnerability that allows unauthenticated network attackers to access files when the server is started with specific configuration parameters.
CoreDNS TSIG Authentication Bypass Vulnerability
2 rules 1 TTPCoreDNS versions prior to 1.14.3 are vulnerable to TSIG authentication bypass on gRPC, QUIC, DoH, and DoH3 transports, allowing unauthenticated network attackers to bypass authentication and potentially access TSIG-protected zone data or submit dynamic DNS updates.
ORY Oathkeeper Authentication Bypass Vulnerability (CVE-2026-33496)
2 rules 1 TTPORY Oathkeeper before 26.2.0 is vulnerable to authentication bypass (CVE-2026-33496) due to cache key confusion in the `oauth2_introspection` authenticator, allowing attackers with a valid token to bypass authentication by reusing it with different introspection URLs.
OpenClaw Gateway Bearer Auth Bypass After Secret Rotation
2 rules 1 TTPOpenClaw versions prior to 2026.4.15 have a vulnerability where gateway HTTP and WebSocket handlers cache bearer-auth configuration at server startup, allowing a revoked token to remain valid after SecretRef rotation until restart, potentially granting unauthorized access.
AVideo Platform Unauthenticated Live Stream Control via streamerURL Manipulation
2 rules 1 TTPAVideo platform versions up to 26.0 are vulnerable to unauthenticated control of live streams due to manipulation of the `streamerURL` parameter in the `control.json.php` endpoint, enabling actions like dropping publishers or starting/stopping recordings.
Laravel Passport Authentication Bypass via Client Credentials Tokens
2 rules 1 TTPLaravel Passport before v13.7.1 allows an authentication bypass via client credentials tokens, where a client's identifier can be used to impersonate a user if `Passport::$clientUuids` is set to false or the EnsureClientIsResourceOwner middleware is in use.
Paperclip Unauthenticated Remote Code Execution via Import Authorization Bypass
2 rules 4 TTPs 1 IOCAn unauthenticated attacker can achieve remote code execution on Paperclip instances by exploiting multiple vulnerabilities, including open signup, self-approval of CLI authentication challenges, and missing authorization checks in the company import endpoint, leading to arbitrary command execution as the server's OS user.
OAuth2 Proxy Authentication Bypass Vulnerability (CVE-2026-41059)
2 rules 2 TTPs 1 CVEOAuth2 Proxy versions 7.5.0 through 7.15.1 are vulnerable to an authentication bypass (CVE-2026-41059) due to improper handling of URL fragments in conjunction with `skip_auth_routes` or `skip_auth_regex`, potentially allowing unauthenticated access to protected resources.
Network-AI Unauthenticated Access to MCP HTTP Endpoint
2 rules 1 TTP 2 IOCsNetwork-AI is vulnerable to missing authentication on the MCP HTTP endpoint, allowing unauthenticated privileged tool calls that could lead to configuration changes and agent manipulation.
Flowise Unauthenticated OAuth 2.0 Access Token Disclosure
2 rules 1 TTPFlowise versions 3.0.13 and earlier contain an authentication bypass vulnerability that allows an unauthenticated attacker to obtain OAuth 2.0 access tokens associated with a public chatflow.
Fastify/Express Middleware Path Doubling Authentication Bypass
2 rules 1 TTPA path handling bug in `@fastify/express` v4.0.4 `onRegister` function causes middleware paths to be doubled when inherited by child plugins, resulting in complete bypass of Express middleware security controls for all routes defined within child plugin scopes that share a prefix with parent-scoped middleware.
Fastify Middlie Authentication Bypass Vulnerability (CVE-2026-6270)
2 rules 1 TTP 1 CVE 1 IOCFastify middlie versions 9.3.1 and earlier do not properly register inherited middleware, leading to authentication bypass in child plugin scopes, allowing unauthenticated access.
File Browser Proxy Authentication Bypass Vulnerability (CVE-2026-35607)
2 rules 1 TTP 1 CVEFile Browser versions before 2.63.1 improperly grant execution capabilities to new users created via proxy authentication, leading to privilege escalation.
FUXA 1.2.8 Authentication Bypass and Remote Command Execution Vulnerability
2 rules 2 TTPs 1 CVEFUXA 1.2.8 and earlier is vulnerable to an authentication bypass vulnerability (CVE-2025-69985) that allows remote command execution by exploiting the /api/runscript endpoint with a crafted JavaScript payload.
Nginx-UI Unauthenticated Initial Admin Claim Vulnerability
2 rules 1 TTPAn unauthenticated network attacker can claim the initial administrator account on a fresh Nginx-UI instance during the first-run setup window by exploiting the publicly accessible /api/install endpoint.
Maddy Mail Server LDAP Filter Injection Vulnerability
2 rules 3 TTPsMaddy Mail Server is vulnerable to LDAP injection via unsanitized username in the `auth.ldap` module, enabling identity spoofing, LDAP directory enumeration, and attribute value extraction by injecting arbitrary LDAP filter expressions through the username field in SMTP submission or IMAP LOGIN interfaces.
WebPros cPanel & WHM and WP2 Authentication Bypass Vulnerability (CVE-2026-41940)
2 rules 1 TTP 1 CVECVE-2026-41940 is an authentication bypass vulnerability in WebPros cPanel & WHM and WP2 (WordPress Squared) that allows unauthenticated remote attackers to gain unauthorized access to the control panel.
Shipping System CMS 1.0 Authentication Bypass via SQL Injection
2 rules 1 TTPShipping System CMS 1.0 is vulnerable to SQL injection, allowing unauthenticated attackers to bypass authentication by injecting SQL code through the username parameter.
S3-Proxy Authentication Bypass via Percent-Encoded Slashes
2 rules 1 TTPS3-Proxy is vulnerable to an authentication bypass due to inconsistent handling of percent-encoded slashes between the authentication middleware and bucket handler, allowing unauthorized access to protected resources.
PaperCut NG/MF Improper Authentication Vulnerability (CVE-2023-27351)
2 rules 1 TTP 1 CVECVE-2023-27351 is an improper authentication vulnerability in PaperCut NG/MF that allows remote attackers to bypass authentication via the SecurityRequestFilter class, leading to potential ransomware deployment.
Note Mark OIDC Authentication Bypass via Hardcoded Password
2 rules 1 TTPA critical authentication bypass vulnerability in note-mark allows attackers to authenticate as any OIDC-registered user by submitting the password 'null' to the internal login endpoint due to a hardcoded bcrypt hash fallback, potentially leading to account takeover and persistent access.
MoreConvert Pro WordPress Plugin Authentication Bypass Vulnerability
2 rules 1 TTP 1 CVEThe MoreConvert Pro plugin for WordPress versions 1.9.14 and earlier is vulnerable to authentication bypass due to improper handling of guest waitlist verification tokens, allowing unauthenticated attackers to potentially gain administrative access.
ManageEngine Log360 Authentication Bypass Vulnerability (CVE-2026-3324)
2 rules 1 TTP 1 CVEZohocorp ManageEngine Log360 versions 13000 through 13013 are vulnerable to authentication bypass on certain actions due to improper filter configuration, potentially allowing unauthorized access.
GNUTLS RSA-PSK Authentication Bypass Vulnerability (CVE-2026-42010)
2 rules 1 TTP 1 CVEA vulnerability in GNUTLS (CVE-2026-42010) allows a remote attacker to bypass authentication on servers configured with RSA-PSK by sending a specially crafted username containing a NUL character, leading to unauthorized access.
Free5GC PCF Authentication Bypass Vulnerability
2 rules 1 TTPFree5GC PCF versions prior to 1.4.3 are vulnerable to an authentication bypass due to missing middleware, allowing unauthenticated access to SM policy handlers and disclosure of subscriber SUPI.
Flowise resetPassword Authentication Bypass Vulnerability
2 rules 1 TTPFlowise version 3.0.12 is vulnerable to an authentication bypass vulnerability due to improper implementation of the password reset mechanism, allowing an attacker to reset a user's password and gain unauthorized access.
fast-jwt Authentication Bypass Vulnerability via Empty HMAC Secret
2 rules 2 TTPsA critical vulnerability in the fast-jwt library allows attackers to forge JWTs by exploiting the acceptance of empty HMAC secrets in the async key resolver, leading to authentication bypass.
Decidim Amendment Acceptance Vulnerability
2 rules 1 TTPAn authentication bypass vulnerability in Decidim allows any registered user to accept or reject amendments, potentially granting them co-author status on affected proposals; versions 0.19.0 through 0.30.5 and 0.31.0.rc1 through 0.31.1 are affected.
changedetection.io Authentication Bypass via Flask Decorator Misordering
2 rules 4 TTPs 1 IOCchangedetection.io is vulnerable to authentication bypass due to incorrect decorator ordering in Flask routes, allowing unauthenticated access to backup functionalities and potentially leading to data exfiltration of sensitive information.
Budibase Authentication Bypass via Unanchored Regex
2 rules 1 TTP 2 IOCsBudibase versions 3.35.3 and earlier are vulnerable to an authentication bypass due to unanchored regular expressions in the public endpoint matcher, allowing unauthenticated attackers to access protected endpoints by manipulating the query string.
666ghj MiroFish REST API Authentication Bypass (CVE-2026-7042)
2 rules 1 TTP 1 CVEA missing authentication vulnerability (CVE-2026-7042) exists in 666ghj MiroFish up to version 0.1.2, allowing remote attackers to bypass authentication via manipulation of the REST API Endpoint's create_app function.
Fortinet Appliance Authentication Bypass Vulnerability (CVE-2022-40684) Exploitation
2 rules 2 TTPsExploitation of CVE-2022-40684, a Fortinet appliance authentication bypass vulnerability, allows unauthorized REST API access to modify system configurations, potentially leading to complete system compromise.
free5GC NEF Unauthenticated Callback Vulnerability
2 rules 1 TTPfree5GC NEF v4.2.1 exposes an unauthenticated callback route group, enabling attackers to forge SMF callbacks and potentially corrupt AF traffic-influence or PFD-management subscription views, leading to unauthorized policy changes.
V2Board and Xboard Authentication Bypass via Exposed Tokens
2 rules 1 TTP 1 CVEV2Board and Xboard are vulnerable to authentication bypass due to exposing authentication tokens in HTTP response bodies, allowing unauthenticated attackers to gain complete account access.
OAuth2 Proxy Authentication Bypass via X-Forwarded-Uri Spoofing
2 rules 1 TTP 1 CVEOAuth2 Proxy versions 7.5.0 through 7.15.1 are vulnerable to an authentication bypass where attackers can spoof the `X-Forwarded-Uri` header when `--reverse-proxy` is enabled alongside `--skip-auth-regex` or `--skip-auth-route`, allowing unauthorized access to protected resources.
MantisBT Authentication Bypass via SOAP API on MySQL
3 rules 1 TTPMantisBT instances running on MySQL are vulnerable to an authentication bypass in the SOAP API due to improper type checking on the password parameter, allowing attackers with a valid username to log in without the actual password.
Incus WebUI Authentication Bypass Vulnerability (CVE-2026-33898)
3 rules 1 TTPIncus versions prior to 6.23.0 are vulnerable to an authentication bypass in the `incus webui` component, allowing local attackers to gain elevated privileges or remote attackers to access system resources by exploiting the incorrect validation of authentication tokens.
CodeChecker Authentication Bypass Vulnerability
2 rules 1 TTP 1 CVEAn authentication bypass vulnerability exists in CodeChecker for certain API calls, allowing unauthenticated users to execute function calls with arbitrary arguments, potentially granting superuser permissions to an attacker.
Canias ERP Authentication Bypass Vulnerability (CVE-2026-8216)
2 rules 1 TTP 1 CVECVE-2026-8216 is a remote improper authentication vulnerability in the iasServerRemoteInterface.doAction function of the Java RMI Session Management component of Industrial Application Software IAS Canias ERP 8.03.
Axios HTTP Adapter Prototype Pollution Vulnerability
2 rules 4 TTPs 1 CVEA prototype pollution vulnerability in the Axios HTTP adapter allows an attacker to inject arbitrary HTTP headers into outgoing requests by polluting the Object prototype with specific properties, leading to potential authentication bypass and privilege escalation.