CWE-347
CWE-347 · 3 records · 0 with a public proof-of-concept
Records the NVD classes under CWE-347, highest CVSS first.
- HIGH 7.4CVE-2026-16443
A flaw was found in the SAML metadata import functionality of the keycloak-services component, which is the core engine for identity brokering in Red Hat Build of Keycloak. When importing identity provider metadata that lacks specific usage attributes for keys…
build of keycloak
- MEDIUM 6.6CVE-2026-86109
The VeloCloud Edge software update workflow may accept update bundles without properly validating their signatures because the workflow does not restrict the digest algorithm used for artifact verification. An attacker with either sufficient privileges to uplo…
- UNSCOREDCVE-2026-86585
The lack of signature verification of firmware update packages in VEO and VEO-XS Wi-Fi monitors, in versions prior to 01.48.001, allows an attacker who controls the delivery of an update to install unauthorised firmware.