Topic
Authentication Bypass
21 reports tagged Authentication Bypass, spanning news and vulnerability coverage.
Articles tagged Authentication Bypass
-
NewsExploited Cisco SD-WAN Manager flaw gives attackers admin API access
CISA added a critical Cisco Catalyst SD-WAN Manager authentication bypass to its KEV catalog with a three-day federal deadline and a required compromise check.
-
VulnerabilitySAML Single Sign On – SSO Login Authentication Bypass (CVE-2026-15981)
CVE-2026-15981 is a CVSS 9.8 authentication bypass in the MiniOrange SAML SSO WordPress plugin allowing login as any user, reported exploited by VulnCheck.
-
VulnerabilityN-able N-central Authentication Bypass (CVE-2026-86207)
CVE-2026-86207 is an authentication bypass affecting internal APIs in N-able N-central RMM software, per VulnCheck alone.
-
VulnerabilityNewfold WP Plugin Web Authentication Bypass (CVE-2026-80099)
CVE-2026-80099 is a CVSS 8.8 authentication bypass in Newfold WordPress plugins, reported exploited by VulnCheck alone.
-
VulnerabilityownCloud Authentication Bypass (CVE-2023-49105)
CVE-2023-49105 is a CVSS 9.8 authentication bypass in ownCloud core allowing unauthenticated file access via pre-signed URLs, confirmed exploited per CISA KEV.
-
VulnerabilityRed Hat Build of Keycloak Authentication Bypass (CVE-2026-18963)
CVE-2026-18963 is a CVSS 9.1 flaw in Red Hat Build of Keycloak letting attackers force password resets without email verification, per VulnCheck.
-
VulnerabilityWPMU DEV Dashboard Authentication Bypass (CVE-2026-76581)
CVE-2026-76581 is a CVSS 9.8 authentication bypass in the WPMU DEV Dashboard plugin allowing administrator session forgery, reported exploited by VulnCheck.
-
VulnerabilityCisco Identity Services Engine Authentication Bypass (CVE-2026-76460)
CVE-2026-76460 is a CVSS 10.0 unauthenticated API authentication bypass in Cisco ISE and ISE-PIC, CISA KEV-listed Sept. 16, 2026, with no vendor workaround.
-
VulnerabilityIssabel Framework Authentication Bypass (CVE-2026-89026)
CVE-2026-89026 is a CVSS 9.8 hard-coded JWT signing key in Issabel Framework, VulnCheck KEV-listed Sept. 15, 2026; CISA has not listed it as of our data.
-
VulnerabilityJFrog Artifactory Authentication Bypass (CVE-2026-82329)
CVE-2026-82329 is a CVSS 9.8 authentication flaw letting an unauthenticated attacker gain JFrog Artifactory admin rights. Added to CISA KEV Sept. 2, 2026.
-
VulnerabilityKestra OSS Authentication Bypass (CVE-2026-49869)
CVE-2026-49869 is a CVSS 10.0 authentication-filter bypass in Kestra OSS, KEV-listed Sept. 2, 2026 as exploited. NVD reports fixes in 1.0.45 and 1.3.21.
-
Vulnerability10 CVEs: vLLM & vLLM Hardware Plugin for Intel Gaudi (CVE-2026-73560)
Ten 2026 vLLM CVEs assessed against NVD, GitHub Advisory, and CVE.org data: an SSRF and file-read flaw, a cross-user data leak, and an OpenAI API auth bypass.
-
VulnerabilityJFrog Artifactory Self-Hosted Authentication Bypass (CVE-2026-42018)
CVE-2026-42018 can leak an internal anonymous-user token to unauthenticated callers in JFrog Artifactory even when anonymous access is disabled. Added to CISA KEV Sept. 11, 2026.
-
VulnerabilityAuthen::SASL::Perl Authentication Bypass (CVE-2026-86219)
CVE-2026-86219 is a CVSS 9.8 critical authentication bypass in the Perl Authen::SASL::Perl::DIGEST_MD5 module, letting a captured response be replayed to authenticate as another user.
-
Vulnerabilitycurl Authentication Bypass (CVE-2026-13608)
CVE-2026-13608 is a CVSS 7.4 high-severity flaw letting a man-in-the-middle attacker bypass libcurl SASL/LDAP authentication via an incomplete handshake.
-
VulnerabilityBerriAI LiteLLM Authentication Bypass (CVE-2026-59822)
CVE-2026-59822 lets attackers bypass LiteLLM key validation via a fabricated Authorization header, reaching MCP tooling unauthenticated. Added to CISA KEV Sept. 2, 2026.
-
VulnerabilityCisco Secure Firewall Management Center Authentication Bypass (CVE-2026-20079)
CVE-2026-20079 is a maximum-severity CVSS 10 authentication bypass in Cisco Secure Firewall Management Center, added to CISA KEV Sept. 9, 2026 as actively exploited.
-
VulnerabilityAdobe Commerce Authentication Bypass (CVE-2026-75650)
CVE-2026-75650 is a maximum-severity CVSS 10 template injection flaw in Adobe Commerce and Magento, added to CISA KEV Sept. 8, 2026 as actively exploited.
-
VulnerabilityCitrix NetScaler ADC Authentication Bypass (CVE-2026-19490)
CVE-2026-19490 is a critical CVSS 9.8 authentication bypass in Citrix NetScaler ADC and Gateway, added to CISA's KEV catalog Sept. 9, 2026 as actively exploited.
-
VulnerabilityTenda AC9 15.03.05.14 Authentication Bypass (CVE-2026-86300)
CVE-2026-86300 is a CVSS 7.3 high-severity improper-authentication flaw in Tenda AC9 router firmware's web management component, with public exploit code available.
-
VulnerabilityMojoX::Authentication Authentication Bypass (CVE-2026-86304)
CVE-2026-86304 is a CVSS 9.8 critical SAML authentication bypass in the Perl MojoX::Authentication module, letting an attacker forge a self-signed SAML response to log in as any user.