CWE-636

CWE-636 · 8 records · 6 with a public proof-of-concept

Records the NVD classes under CWE-636, highest CVSS first.

  1. CRITICAL 9.1CVE-2026-95848public PoC

    Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, when a configured authenticator or authorizator class cannot be loaded, Server.initializeAuthenticator and Server.initializeAuthorizatorPolicy treat the failure as though no custom class was configur…

    moquette

    AI risk analysis on Exploit-DB.ai →

  2. HIGH 8.1CVE-2026-77560public PoC

    Tinyauth is an authentication and authorization server. Prior to 5.1.2, Tinyauth compares forwarded hostnames case-sensitively while reverse proxies route equivalent hostnames case-insensitively, allowing an authenticated low-privilege user to bypass per-app a…

    AI risk analysis on Exploit-DB.ai →

  3. HIGH 7.7CVE-2026-61595public PoC

    djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, `djust.tenants` isolation was enforced only on the HTTP path. The current tenant was stored in `threading.local()` and set ex…

    AI risk analysis on Exploit-DB.ai →

  4. HIGH 7.4CVE-2026-61788public PoC

    DBHub is a database MCP server for Postgres, MySQL, SQL Server, Oracle, MariaDB, SQLite. Prior to version 0.22.6, setting `readonly = true` on the `execute_sql` tool does not make the connection read-only. The connectors are written to set PostgreSQL `default_…

    AI risk analysis on Exploit-DB.ai →

  5. MEDIUM 5.5CVE-2026-100860public PoC

    heym before 0.0.105 does not act on the result of the credential authorization lookup in the Redis workflow node (backend/app/services/node_execution/nodes/redis_node.py). When _get_accessible_credential returns None — because the credential ID does not exist …

    AI risk analysis on Exploit-DB.ai →

  6. MEDIUM 5.3CVE-2026-100304public PoC

    TDuck survey form 6.0 contains an information disclosure vulnerability in FormAuthUtils.hasPermission that fails open when a form does not exist, allowing authenticated users to access deleted form submissions. Attackers can read orphaned submission data inclu…

    AI risk analysis on Exploit-DB.ai →

  7. MEDIUM 5.3CVE-2026-88831

    BusyBox httpd IP deny rules with invalid CIDR prefix lengths fail open, leaving a parsed IP with a zeroed mask so the rule matches no clients.

    AI risk analysis on Exploit-DB.ai →

  8. UNSCOREDCVE-2026-95676

    A missing/improper authentication vulnerability in the WatchGuard AuthPoint Gateway's LDAP Sync first-factor authentication allows a remote attacker to bypass single-factor password verification under non-default operating conditions. Additional authentication…

    AI risk analysis on Exploit-DB.ai →