The product uses an authentication mechanism to restrict access to specific users or identities, but the mechanism does not sufficiently prove that the claimed identity is correct.
86 vulnerabilities with CWE-1390
CVE-2026-59554
HIGH
WordPress Ziina plugin <= 1.2.21 - Broken Authentication vulnerability
CVSS 7.5
CVE-2026-50756
HIGH
next-ai-draw-io 0.4.13 - Unauthenticated Sensitive Information Disclosure via x-ai-provider Header
CVSS 7.5
CVE-2026-55040
CRITICAL
Microsoft SharePoint Server Security Feature Bypass Vulnerability
CVSS 9.1
CVE-2026-10714
HIGH
Rockwell Automation FactoryTalk® Services Platform FTSP - Weak Authentication via JWT Validation Bypass
CVE-2026-57352
MEDIUM
WordPress ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce plugin <= 2.2.0 - Broken Authentication vulnerability
CVSS 4.8
CVE-2026-0274
CRITICAL
Cortex XSOAR: Improper Validation of Credentials in CommvaultSecurityIQ integration
CVSS 9.1
CVE-2026-6274
CRITICAL
Authentication Bypass in DTS Electronics' Redline WR3200
CVSS 9.8
CVE-2026-44237
HIGH
FreePBX: Authenticated Access can lead to Subsequent OAuth2 Authentication Bypass in API Module
CVSS 8.1
CVE-2026-49323
MEDIUM
Indian Scout Bobber 2025 WCM-to-ECM weak authentication
CVSS 4.3
CVE-2026-49322
MEDIUM
Indian Scout Bobber 2025 WCM - Weak PIN Authentication
CVSS 4.3
CVE-2026-40417
HIGH
Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability
CVSS 7.8
CVE-2026-0204
HIGH
SonicWall SonicOS <=6.5.5.1-6n - Auth Bypass
CVSS 8.0
CVE-2026-6886
CRITICAL
BorG Technology Corporation|Borg SPM 2007 - Authentication Bypass
CVSS 9.8
CVE-2026-4924
HIGH
Devolutions Server <=2026.1.11 - Auth Bypass
CVSS 8.2
CVE-2026-4828
HIGH
Devolutions Server <=2026.1.11 - Auth Bypass
CVSS 8.2
CVE-2026-32497
MEDIUM
WordPress User Verification plugin <= 2.0.45 - Email Verification Bypass vulnerability
CVSS 5.3
CVE-2026-27478
CRITICAL
Unity Catalog <=0.4.0 - Auth Bypass
CVSS 9.1
CVE-2026-28710
CRITICAL
Acronis Cyber Protect 17 - Info Disclosure
CVSS 9.8
CVE-2026-1693
HIGH
PcVue 12.0.0-16.3.3 - Credential Theft via Obsolete OAuth ROPC Flow
CVSS 7.5
CVE-2025-70994
HIGH
Yadea T5 Electric Bicycles 2024 - Auth Bypass
CVSS 7.3
CVE-2025-62844
MEDIUM
QNAP QuRouter < 2.6.2.007 - Weak Authentication Information Disclosure
CVSS 5.5
CVE-2025-15595
HIGH
Inno Setup <=6.2.1 - Privilege Escalation
CVSS 7.8
CVE-2025-30412
CRITICAL
Acronis Cyber Protect - Info Disclosure
CVSS 10.0
CVE-2025-30411
CRITICAL
Acronis Cyber Protect - Info Disclosure
CVSS 10.0
CVE-2025-57713
HIGH
File Station 5 <5.5.6.5166 - Info Disclosure
CVSS 7.5
Details
Vulnerabilities
86