CWE-290
CWE-290 · 22 records · 12 with a public proof-of-concept
Records the NVD classes under CWE-290, highest CVSS first.
- CRITICAL 9.8CVE-2026-85751public PoC
Mailu is a mail server distributed as a set of Docker images. From Mailu 2.0 until 2024.06.55 and prior to Mailu helm-charts 2.7.3, deployments with PROXY_AUTH_WHITELIST configured but REAL_IP_HEADER unset trusted a client-controlled X-Forwarded-By header for …
- CRITICAL 9.8CVE-2026-86863public PoC
pgAdmin 4's Webserver authentication source is intended to accept an identity asserted by the web server or reverse proxy in front of pgAdmin, delivered through the WSGI/CGI environment. WebserverAuthentication.get_user() read config.WEBSERVER_REMOTE_USER from…
pgadmin 4
- CRITICAL 9.8CVE-2026-62108
Unauthenticated Broken Authentication in Headless Single Sign On <= 1.7.0 versions.
- CRITICAL 9.1CVE-2026-92395public PoC
@fastify/proxy-addr is a Fastify plugin that determines a request's client address behind trusted reverse proxies, and it backs Fastify request.ip and request.ips. In versions 3.0.0 through 5.1.0, a trust subnet written in IPv4-mapped IPv6 notation with an IPv…
- HIGH 8.2CVE-2026-86039public PoC
libp2p is a JavaScript implementation of the libp2p networking stack. From 8.0.0 until 12.0.24, @libp2p/peer-store in packages/peer-store/src/index.ts uses consumePeerRecord to verify a RecordEnvelope signature but does not require PeerRecord.peerId in the sig…
- HIGH 7.4CVE-2026-100390public PoC
Zoraxy versions 3.2.3 through 3.3.4 fail to properly parse IPv6 addresses in the RemoteAddr field when setting forwarded headers. Unauthenticated attackers connecting over IPv6 can supply arbitrary X-Forwarded-For values to spoof their source IP and bypass aut…
- HIGH 7.4CVE-2026-55210public PoC
Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.2, Joplin Server's UserModel.ssoLogin() returns an existing account matched by an IdP-asserted email without checking the account's is_extern…
- HIGH 7.3CVE-2026-101280
A vulnerability was detected in Trusted Domain Project OpenDMARC up to 1.4.2. Affected is the function opendmarc_policy_query_dmarc of the component Multi-Record Set Handler. The manipulation results in authentication bypass by spoofing. The attack can be exec…
- HIGH 7.1CVE-2026-93538public PoC
A cross-tenant authorization issue was discovered in SUSE Rancher Fleet. During agent-initiated cluster registration, cluster labels supplied by the registering agent, including labels in the reserved management.cattle.io/ namespace such as the cluster display…
- MEDIUM 6.8CVE-2026-94416public PoC
An authorization bypass was found in the Ansible Automation Platform (AAP) gateway. The gateway API allows an authenticated administrator to create a new service key for the Controller service cluster. Because service-key creation is not restricted to the inst…
- MEDIUM 6.5CVE-2026-95523
Subscriber Bypass Vulnerability in WP User Frontend <= 4.3.11 versions.
- MEDIUM 5.8CVE-2026-62987public PoC
Fabio is an HTTP(S) and TCP router for deploying applications managed by consul. From 1.6.6 until 1.7.2, the CVE-2025-48865 fix in proxy/http_headers.go uses protectHeaders for a hardcoded set of forwarded headers but omits the operator-configured ClientIPHead…
- MEDIUM 5.3CVE-2026-95524
Unauthenticated Bypass Vulnerability in WP User Frontend <= 4.3.11 versions.
- MEDIUM 5.3CVE-2026-93511
The Premium Packages WordPress plugin before 7.2.1 does not verify PayPal's webhook signature before processing payment and subscription notifications, allowing unauthenticated attackers to forge payment confirmations and subscription-cancellation events agai…
- MEDIUM 5.3CVE-2026-92929
OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 trusts an X-Forwarded-For header supplied by an arbitrary client when determining the request source address. An unauthenticated remote attacker can spoof a loopback address to bypass local-connectio…
- MEDIUM 4.9CVE-2026-63329public PoC
Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.25.6, copy_server_request in warpgate-protocol-http/src/proxy.rs forwards a client-supplied x-warpgate-username header before inject_own_headers appends the authenticated userna…
- MEDIUM 4.8CVE-2026-94457
Unauthenticated Bypass Vulnerability in Captcha Code <= 3.32 versions.
- LOW 3.8CVE-2026-89327
The FluentBoards WordPress plugin before 2.0.15 does not verify that a board member submitting a comment is the user the comment is attributed to, allowing any board member to post comments that appear to be authored by another user, including administrators.
- UNSCOREDCVE-2026-84465public PoC
Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, when Zammad checks the digital signature on an incoming S/MIME-signed email, it does not verify that the signing certificate is genuinely trusted, it only checks whether a cert…
- UNSCOREDCVE-2026-91039public PoC
Authentication Bypass by Spoofing vulnerability in team-alembic ash_authentication allows an attacker who operates one identity-provider connection of a dynamic_oidc strategy to be signed in as a local user established through a different connection. The stra…
- UNSCOREDCVE-2026-40854
WNC T-Mobile 5G Box IDU router contains an authentication bypass vulnerability in the portal.cgi component. The session verification mechanism improperly validates the sessionid cookie by checking for the existence of a corresponding file in /tmp/login_user. A…
- UNSCOREDCVE-2026-15640
Under certain conditions a valid SAML IdP response may be used to impersonate another Secret Server user.