When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
4,570 vulnerabilities with CWE-287
CVE-2026-37270
CRITICAL
Trueview T18161-AF 4.9.60.0 - Unauthenticated Auth Bypass via Hardcoded Creds & Improper Validation
CVSS 9.8
CVE-2026-55075
HIGH
Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass
CVSS 7.4
CVE-2026-53483
CRITICAL
Dell PowerProtect Data Domain - Improper Authentication
CVSS 9.8
CVE-2026-55727
HIGH
Genetec Security Center - Improper Authentication
CVSS 7.5
CVE-2026-40139
CRITICAL
BeyondTrust Remote Support - Unauthenticated Access Control Bypass
CVSS 9.8
CVE-2026-40138
HIGH
BeyondTrust Remote Support and PRA - Unauthenticated Access Control Bypass
CVSS 8.1
CVE-2026-53913
CRITICAL
Apache Camel Keycloak 4.18.3 and 4.21.0 - Remote Code Execution
CVSS 9.8
CVE-2026-14714
MEDIUM
zhayujie chatgpt-on-wechat CowAgent wx Endpoint common.py verify_server missing authentication
CVSS 6.5
CVE-2026-14627
MEDIUM
NousResearch hermes-agent Discord Platform Integration discord.py DiscordAdapter._is_allowed_user improper authentication
CVSS 5.6
CVE-2026-12196
HIGH
HestiaCP Admin Takeover
CVE-2026-14622
HIGH
jairiidriss restaurant-website-php-mysql AJAX Endpoint ajax_files missing authentication
CVSS 7.3
CVE-2026-58423
HIGH
Gitea 1.23.0-1.26.2 LFS - Unauthorized Repository Read via SSH Sub-Verb
CVSS 7.7
CVE-2026-52830
CRITICAL
fast-mcp-telegram: Bearer token path traversal bypasses reserved Telegram session protection
CVSS 9.4
CVE-2026-58029
MEDIUM
Full Account Takeover from BotPasswords and OAuth via action=changeauthenticationdata
CVSS 6.5
CVE-2026-58399
HIGH
@acastellon/auth has an authentication bypass via spoofable headers in validateToken()
CVE-2026-11387
CRITICAL
SMS Alert <= 3.9.5 - Unauthenticated Privilege Escalation via Arbitrary Password Reset
CVSS 9.8
CVE-2026-56219
HIGH
Capgo - Unauthenticated RBAC Bindings and Email Disclosure via get_org_user_access_rbac NULL-auth Bypass
CVSS 7.5
CVE-2026-10560
HIGH
Unauthenticated Access to Private Flow Build Events and Cancellation in Langflow OSS
CVSS 8.2
CVE-2026-55955
MEDIUM
Apache Tomcat: EncryptInterceptor not protected against replay attacks
CVSS 6.5
CVE-2026-41896
HIGH
Coolify: Unauthenticated Deployment Trigger via Webhook HMAC Bypass with Null Secret
CVSS 7.5
CVE-2026-13546
HIGH
Feehi CMS REST API Endpoint articles missing authentication
CVSS 7.3
CVE-2026-13543
MEDIUM
Documenso Google OAuth Login handle-oauth-callback-url.ts improper authentication
CVSS 5.6
CVE-2026-49869
CRITICAL
Kestra: Unauthenticated Remote Code Execution via Authentication Bypass in `AuthenticationFilter`
CVSS 10.0
CVE-2026-55962
MEDIUM
TLS 1.3 post-handshake authentication: server accepts Finished without client Certificate/CertificateVerify
CVSS 6.5
CVE-2026-11703
HIGH
Missing SNI/ALPN binding on stateful (session-ID) TLS session resumption
CVSS 7.5
Details
Vulnerabilities
4,570
Exploit Likelihood
High