Improper Certificate Validation

CWE-295 · 27 records · 17 with a public proof-of-concept

Records the NVD classes as Improper Certificate Validation (CWE-295), highest CVSS first.

  1. CRITICAL 9.4CVE-2026-93291

    Omni C20 lacks proper certificate validation which could allow an attacker to perform a man-in-the-middle attack which could allow them to execute arbitrary code.

    AI risk analysis on Exploit-DB.ai →

  2. HIGH 8.3CVE-2026-100551public PoC

    OpenClaw for iOS versions >= 2026.7.1 and < 2026.8.11 do not enforce saved Gateway TLS pins in the Control UI. While native connections enforced the saved Gateway fingerprint, the authenticated Terminal and session Dashboard WebViews omitted it. If a user had …

    AI risk analysis on Exploit-DB.ai →

  3. HIGH 8.3CVE-2026-82157

    Dell ThinOS 10, versions prior to SecurityAddon_2605.10.2766_T10, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Protection mechanism …

    AI risk analysis on Exploit-DB.ai →

  4. HIGH 7.9CVE-2026-91812

    A vulnerability in Foxit PDF Editor/Reader’s update mechanism allows man-in-the-middle attackers to bypass certificate validation and package integrity checks, potentially enabling arbitrary code execution with system privileges.

    AI risk analysis on Exploit-DB.ai →

  5. HIGH 7.5CVE-2026-100665public PoC

    Netty versions from 4.2.11.Final before 4.2.18.Final contain an incomplete hostname verification fix in the QUIC certificate verification path when using a plain X509TrustManager. The BoringSSLCertificateVerifyCallback discards the SSLEngine for plain trust ma…

    AI risk analysis on Exploit-DB.ai →

  6. HIGH 7.5CVE-2026-65118public PoC

    NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause improper certificate validation. A successful exploit of this vulnerability might lead to information disclosure, data tampering, and denial of service.

    AI risk analysis on Exploit-DB.ai →

  7. HIGH 7.4CVE-2026-101916public PoC

    @grpc/grpc-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. Prior to 1.13.6 and 1.14.5, getAuthContext does not distinguish authorized from unauthorized peer certificates when server credentials set requireClientCertifica…

    AI risk analysis on Exploit-DB.ai →

  8. HIGH 7.4CVE-2026-100835public PoC

    Contrast before 1.16.0 is susceptible to remote attestation relay attacks. Contrast accepted any TEE attestation report that verified correctly and contained the expected firmware patch levels and software measurements, regardless of which machine produced it,…

    AI risk analysis on Exploit-DB.ai →

  9. MEDIUM 6.8CVE-2026-73587

    Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Informa…

    policy manager for secure connect gateway

    AI risk analysis on Exploit-DB.ai →

  10. MEDIUM 6.8CVE-2026-81447

    Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Information disclosur…

    AI risk analysis on Exploit-DB.ai →

  11. MEDIUM 6.7CVE-2026-65129public PoC

    NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause improper certificate validation. A successful exploit of this vulnerability might lead to information disclosure, data tampering, and denial of service.

    AI risk analysis on Exploit-DB.ai →

  12. MEDIUM 6.5CVE-2026-81868public PoC

    Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. Prior to 4.3.0, Steeltoe.Security.Authorization.Certificate deployments using AddOrgAndSpacePolicies() and UseCertificateAuthorization(…

    AI risk analysis on Exploit-DB.ai →

  13. MEDIUM 6.2CVE-2026-83964

    Adobe Connect is affected by an Improper Certificate Validation vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue does not require user i…

    connect · macos · windows · connect for mobile

    AI risk analysis on Exploit-DB.ai →

  14. MEDIUM 6.1CVE-2026-16792

    An improper certificate validation vulnerability was reported in multiple Lenovo XClarity Orchestrator (LXCO) 2.2.0 microservices that could allow an adjacent network attacker to intercept sensitive communications by performing a machine-in-the-middle attack a…

    AI risk analysis on Exploit-DB.ai →

  15. MEDIUM 5.9CVE-2026-100701public PoC

    Nodemailer versions 5.0.0 through 10.0.1 use a process-global DNS cache that is keyed only by the DNS host, while each cache entry also stores the caller-specific TLS servername. When two direct TLS/SMTPS transports (secure: true) resolve the same non-IP host …

    AI risk analysis on Exploit-DB.ai →

  16. MEDIUM 5.9CVE-2026-77707

    Improper certificate validation vulnerability in HAVELSAN Inc. Liman Render Engine allows Adversary in the Middle (AiTM). This issue affects Liman Render Engine: from 1.0 before 1.2-75.

    AI risk analysis on Exploit-DB.ai →

  17. LOW 3.7CVE-2026-18173

    IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to improper enforcement of mutual TLS authentication.

    AI risk analysis on Exploit-DB.ai →

  18. UNSCOREDCVE-2026-93302public PoC

    MatchTrustedPeer ignores the public key used, leading to forged CA clones passing verification. Affected builds are any that enable the macro WOLFSSL_TRUST_PEER_CERT and load CA certificates with wolfSSL_CTX_trust_peer_cert() or wolfSSL_trust_peer_cert(). The …

    AI risk analysis on Exploit-DB.ai →

  19. UNSCOREDCVE-2026-89135public PoC

    A failed X509_verify_cert call permanently plants an unverified attacker CA in the shared CertManager, bypassing certificate validation in every type-blind sibling consumer (native TLS, OCSP, CRL, direct CM verify). This affects version 5.8.4 through 5.9.2 of …

    AI risk analysis on Exploit-DB.ai →

  20. UNSCOREDCVE-2026-89134public PoC

    A certificate with no dNSName SAN but another SAN type present (e.g. registeredID or iPAddress) bypassed the Subject CN dNSName name-constraint check. The CN-as-DNS fallback was gated on cert->subjectCN != NULL && cert->altNames == NULL && !cert->isCA instead …

    AI risk analysis on Exploit-DB.ai →

  21. UNSCOREDCVE-2026-89133public PoC

    wolfSSL versions 5.9.2 and earlier contain a flaw in the X.509 certificate validation logic where it fails to properly enforce NameConstraints extensions when there is an unconstrained CA tier between a name-constrained intermediate CA and the leaf certificate…

    AI risk analysis on Exploit-DB.ai →

  22. UNSCOREDCVE-2026-89102public PoC

    In wolfSSL versions 5.7.2 through 5.9.2 there is a client-side implementation flaw in RFC 6961, multiple OCSP response stapling, which can lead to certificate forgery. When a wolfSSL client enables OCSP stapling with the HAVE_CERTIFICATE_STATUS_REQUEST_V2 feat…

    AI risk analysis on Exploit-DB.ai →

  23. UNSCOREDCVE-2026-84465public PoC

    Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, when Zammad checks the digital signature on an incoming S/MIME-signed email, it does not verify that the signing certificate is genuinely trusted, it only checks whether a cert…

    AI risk analysis on Exploit-DB.ai →

  24. UNSCOREDCVE-2026-67404public PoC

    RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, When no CA bundle is available, ssl_options/1 falls back to [{verify, verify_none}] with no warning. An attacker in a man-in-the-middle position can forg…

    AI risk analysis on Exploit-DB.ai →

  25. UNSCOREDCVE-2026-67231public PoC

    RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, The trust-store plugin installs a verify_fun that overrides {bad_cert, unknown_ca} / {bad_cert, selfsigned_peer} when the presented cert "matches" a whit…

    AI risk analysis on Exploit-DB.ai →

  26. UNSCOREDCVE-2026-63374public PoC

    AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio. Prior to 4.14.2, connect_tcp() and TLSStream.wrap() can validate internationalized host names after the standard library converts them with IDN…

    AI risk analysis on Exploit-DB.ai →

  27. UNSCOREDCVE-2026-86474

    The lack of TLS certificate validation when downloading firmware updates in VEO and VEO-XS Wi-Fi monitors, in versions prior to 01.48.001, allows an attacker to perform man-in-the-middle attacks on the update channel.

    AI risk analysis on Exploit-DB.ai →