CWE-347

CWE-347 · 3 records · 0 with a public proof-of-concept

Records the NVD classes under CWE-347, highest CVSS first.

  1. HIGH 7.4CVE-2026-16443

    A flaw was found in the SAML metadata import functionality of the keycloak-services component, which is the core engine for identity brokering in Red Hat Build of Keycloak. When importing identity provider metadata that lacks specific usage attributes for keys

    build of keycloak

    AI risk analysis on Exploit-DB.ai →

  2. MEDIUM 6.6CVE-2026-86109

    The VeloCloud Edge software update workflow may accept update bundles without properly validating their signatures because the workflow does not restrict the digest algorithm used for artifact verification. An attacker with either sufficient privileges to uplo

    AI risk analysis on Exploit-DB.ai →

  3. UNSCOREDCVE-2026-86585

    The lack of signature verification of firmware update packages in VEO and VEO-XS Wi-Fi monitors, in versions prior to 01.48.001, allows an attacker who controls the delivery of an update to install unauthorised firmware.

    AI risk analysis on Exploit-DB.ai →