Tag
high
advisory
Crabbox Authentication Bypass via Header Spoofing (CVE-2026-8621)
2 rules 1 TTP 1 CVECrabbox prior to v0.12.0 contains an authentication bypass vulnerability (CVE-2026-8621) that allows non-admin shared-token callers to impersonate other owners or organizations by spoofing identity headers, granting unauthorized access to lease operations.
Crabbox < v0.12.0
authentication-bypass
header-spoofing
cve-2026-8621
2r
1t
1c
critical
advisory
OAuth2 Proxy Authentication Bypass via X-Forwarded-Uri Header Spoofing
2 rules 1 TTPOAuth2 Proxy is vulnerable to an authentication bypass when configured with `--reverse-proxy` and `--skip_auth_routes` or `--skip_auth_regex`; by spoofing the `X-Forwarded-Uri` header, an attacker can bypass authentication and access protected routes without a valid session.
OAuth2 Proxy
oauth2-proxy
authentication-bypass
reverse-proxy
header-spoofing
2r
1t