The product uses an authentication mechanism to restrict access to specific users or identities, but the mechanism does not sufficiently prove that the claimed identity is correct.
81 vulnerabilities with CWE-1390
CVE-2026-0274
HIGH
Cortex XSOAR: Improper Validation of Credentials in CommvaultSecurityIQ integration
CVE-2026-6274
CRITICAL
Authentication Bypass in DTS Electronics' Redline WR3200
CVSS 9.8
CVE-2026-44237
HIGH
FreePBX: Authenticated Access can lead to Subsequent OAuth2 Authentication Bypass in API Module
CVSS 8.1
CVE-2026-49323
MEDIUM
Indian Scout Bobber 2025 WCM-to-ECM weak authentication
CVSS 4.3
CVE-2026-49322
MEDIUM
Indian Scout Bobber 2025 WCM - Weak PIN Authentication
CVSS 4.3
CVE-2026-40417
HIGH
Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability
CVSS 7.8
CVE-2026-0204
HIGH
SonicWall SonicOS <=6.5.5.1-6n - Auth Bypass
CVSS 8.0
CVE-2026-6886
CRITICAL
BorG Technology Corporation|Borg SPM 2007 - Authentication Bypass
CVSS 9.8
CVE-2026-4924
HIGH
Devolutions Server <=2026.1.11 - Auth Bypass
CVSS 8.2
CVE-2026-4828
HIGH
Devolutions Server <=2026.1.11 - Auth Bypass
CVSS 8.2
CVE-2026-32497
MEDIUM
WordPress User Verification plugin <= 2.0.45 - Email Verification Bypass vulnerability
CVSS 5.3
CVE-2026-27478
CRITICAL
Unity Catalog <=0.4.0 - Auth Bypass
CVSS 9.1
CVE-2026-28710
CRITICAL
Acronis Cyber Protect 17 - Info Disclosure
CVSS 9.8
CVE-2026-1693
HIGH
PcVue 12.0.0-16.3.3 - Credential Theft via Obsolete OAuth ROPC Flow
CVSS 7.5
CVE-2025-70994
HIGH
Yadea T5 Electric Bicycles 2024 - Auth Bypass
CVSS 7.3
CVE-2025-62844
MEDIUM
QNAP QuRouter < 2.6.2.007 - Weak Authentication Information Disclosure
CVSS 5.5
CVE-2025-15595
HIGH
Inno Setup <=6.2.1 - Privilege Escalation
CVSS 7.8
CVE-2025-30412
CRITICAL
Acronis Cyber Protect - Info Disclosure
CVSS 10.0
CVE-2025-30411
CRITICAL
Acronis Cyber Protect - Info Disclosure
CVSS 10.0
CVE-2025-57713
HIGH
File Station 5 <5.5.6.5166 - Info Disclosure
CVSS 7.5
CVE-2025-40554
CRITICAL
SolarWinds Web Help Desk < 2026.1 - Authentication Bypass
CVSS 9.8
CVE-2025-40552
CRITICAL
SolarWinds Web Help Desk < 2026.1 - Authentication Bypass
CVSS 9.8
CVE-2025-63807
CRITICAL
University-BBS <9e06bab430bfc729f27b4284ba7570db3b11ce84 - Auth Bypass
CVSS 9.8
CVE-2025-12871
CRITICAL
aenrich a+HRD < 7.5 - Unauthenticated Authentication Abuse via Crafted Administrator Token
CVSS 9.8
CVE-2025-12870
CRITICAL
a+HRD < 7.5 - Unauthenticated Authentication Abuse via Crafted Packets
CVSS 9.8
Details
Vulnerabilities
81