CWE-289

CWE-289 · 4 records · 2 with a public proof-of-concept

Records the NVD classes under CWE-289, highest CVSS first.

  1. CRITICAL 9.8CVE-2026-76183

    Authentication Bypass by Alternate Name vulnerability in Apache Tomcat allowed the security constraints for any WebSocket endpoint to be bypassed. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.25, from 10.1.0-M1 through 10.1.59, from 9.0.0.M…

    AI risk analysis on Exploit-DB.ai →

  2. MEDIUM 6.8CVE-2026-57176public PoC

    Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the Vend OAuth2 backend used only the numeric Vend user_id as the social-auth UID. When multiple Vend shops authenticate through the same application, users from diff…

    AI risk analysis on Exploit-DB.ai →

  3. MEDIUM 5.3CVE-2026-95514

    Unauthenticated Bypass Vulnerability in Netgsm <= 2.10.0 versions.

    AI risk analysis on Exploit-DB.ai →

  4. MEDIUM 5.3CVE-2026-73511public PoC

    Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy normally matches the raw request path, while servlet backends such as Apache Tomcat strip semicolon matrix parameters fro…

    AI risk analysis on Exploit-DB.ai →