CWE-290

Authentication Bypass by Spoofing

Parent: CWE-1390 - Weak Authentication

This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.

575 vulnerabilities with CWE-290
CVE-2026-42662 MEDIUM
WordPress Event Tickets plugin <= 5.27.5 - Bypass Vulnerability vulnerability
CVSS 6.5
CVE-2026-27089 HIGH
WordPress WpTravelly plugin <= 2.1.7 - Bypass Vulnerability vulnerability
CVSS 7.5
CVE-2026-49757 CRITICAL
OAuth2/OIDC account takeover in AshAuthentication via email-based user matching
CVE-2026-34025 MEDIUM
IP restriction bypass in Wertheim SafeController Software allows logins from unauthorized network locations
CVE-2026-53833 HIGH
OpenClaw < 2026.4.29 - Authorization Bypass via QQBot Streaming Command
CVSS 7.7
CVE-2026-53832 HIGH
OpenClaw < 2026.5.18 - Identity Header Forgery via Trusted-Proxy Configuration
CVSS 7.7
CVE-2026-53823 HIGH
OpenClaw < 2026.5.3 - Privilege Escalation via Mutable Slack Display Names in allowFrom
CVSS 8.1
CVE-2026-5792 MEDIUM
Authentication Bypass in Related Digital's Related Marketing Cloud (RMC)
CVSS 6.5
CVE-2026-53817 HIGH
OpenClaw < 2026.5.22 - Control UI Locality Spoofing in Device Pairing
CVSS 8.8
CVE-2026-53811 HIGH
OpenClaw < 2026.5.7 - Privilege Escalation via Mutable Display Names in Matrix allowFrom
CVSS 8.8
CVE-2026-6090 HIGH
Lenovo Smart Connect < 09.0.2.003.000 - Authentication Bypass by Spoofing
CVSS 7.0
CVE-2026-48567 CRITICAL
Azure HorizonDB Elevation of Privilege Vulnerability
CVSS 10.0
CVE-2026-11019 MEDIUM
Google Chrome < 149.0.7827.53 - Domain Spoofing via Payments Implementation
CVSS 6.5
CVE-2026-11001 MEDIUM
Google Chrome < 149.0.7827.53 - UI Spoofing via Payments Implementation
CVSS 6.5
CVE-2026-8644 CRITICAL
IBM WebSphere Application Server 8.5 and 9.0 - Authentication Bypass by Spoofing
CVSS 9.1
CVE-2026-42674 HIGH
WordPress Advanced Access Manager plugin <= 7.1.0 - Bypass Vulnerability vulnerability
CVSS 7.5
CVE-2026-47123 HIGH
FreeScout: Agent Impersonation via Missing HMAC Verification on Notification Reply Message-ID Path
CVSS 7.5
CVE-2026-44649 CRITICAL
SillyTavern: Authentication Bypass via SSO Header Injection
CVSS 9.8
CVE-2026-46414 HIGH
Microsoft UFO WebSocket role spoofing allows authenticated peer task hijacking
CVSS 8.8
CVE-2026-8676 HIGH
Silabs.com Simplicity SDK < 2024.12.0 - Authentication Bypass by Spoofing
CVSS 8.8
CVE-2026-39309 MEDIUM
Trilium Notes: macOS TCC Bypass via Prompt Spoofing
CVSS 5.5
CVE-2026-8963 HIGH
Firefox < 151.0.0 and Thunderbird < 151.0.0 - Authentication Bypass by Spoofing in Web Speech Component
CVSS 7.5
CVE-2026-8961 MEDIUM
Firefox and Thunderbird < 140.11 and >=151 - Authentication Bypass by Spoofing in Form Autofill
CVSS 6.5
CVE-2026-8960 HIGH
Firefox < 151.0.0 and Thunderbird < 151.0.0 - Authentication Bypass by Spoofing via WebExtensions
CVSS 7.5
CVE-2026-8951 MEDIUM
Spoofing issue in the Toolbar component in Firefox for Android
CVSS 6.5
Details
Vulnerabilities 575