This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.
575 vulnerabilities with CWE-290
CVE-2026-42662
MEDIUM
WordPress Event Tickets plugin <= 5.27.5 - Bypass Vulnerability vulnerability
CVSS 6.5
CVE-2026-27089
HIGH
WordPress WpTravelly plugin <= 2.1.7 - Bypass Vulnerability vulnerability
CVSS 7.5
CVE-2026-49757
CRITICAL
OAuth2/OIDC account takeover in AshAuthentication via email-based user matching
CVE-2026-34025
MEDIUM
IP restriction bypass in Wertheim SafeController Software allows logins from unauthorized network locations
CVE-2026-53833
HIGH
OpenClaw < 2026.4.29 - Authorization Bypass via QQBot Streaming Command
CVSS 7.7
CVE-2026-53832
HIGH
OpenClaw < 2026.5.18 - Identity Header Forgery via Trusted-Proxy Configuration
CVSS 7.7
CVE-2026-53823
HIGH
OpenClaw < 2026.5.3 - Privilege Escalation via Mutable Slack Display Names in allowFrom
CVSS 8.1
CVE-2026-5792
MEDIUM
Authentication Bypass in Related Digital's Related Marketing Cloud (RMC)
CVSS 6.5
CVE-2026-53817
HIGH
OpenClaw < 2026.5.22 - Control UI Locality Spoofing in Device Pairing
CVSS 8.8
CVE-2026-53811
HIGH
OpenClaw < 2026.5.7 - Privilege Escalation via Mutable Display Names in Matrix allowFrom
CVSS 8.8
CVE-2026-6090
HIGH
Lenovo Smart Connect < 09.0.2.003.000 - Authentication Bypass by Spoofing
CVSS 7.0
CVE-2026-48567
CRITICAL
Azure HorizonDB Elevation of Privilege Vulnerability
CVSS 10.0
CVE-2026-11019
MEDIUM
Google Chrome < 149.0.7827.53 - Domain Spoofing via Payments Implementation
CVSS 6.5
CVE-2026-11001
MEDIUM
Google Chrome < 149.0.7827.53 - UI Spoofing via Payments Implementation
CVSS 6.5
CVE-2026-8644
CRITICAL
IBM WebSphere Application Server 8.5 and 9.0 - Authentication Bypass by Spoofing
CVSS 9.1
CVE-2026-42674
HIGH
WordPress Advanced Access Manager plugin <= 7.1.0 - Bypass Vulnerability vulnerability
CVSS 7.5
CVE-2026-47123
HIGH
FreeScout: Agent Impersonation via Missing HMAC Verification on Notification Reply Message-ID Path
CVSS 7.5
CVE-2026-44649
CRITICAL
SillyTavern: Authentication Bypass via SSO Header Injection
CVSS 9.8
CVE-2026-46414
HIGH
Microsoft UFO WebSocket role spoofing allows authenticated peer task hijacking
CVSS 8.8
CVE-2026-8676
HIGH
Silabs.com Simplicity SDK < 2024.12.0 - Authentication Bypass by Spoofing
CVSS 8.8
CVE-2026-39309
MEDIUM
Trilium Notes: macOS TCC Bypass via Prompt Spoofing
CVSS 5.5
CVE-2026-8963
HIGH
Firefox < 151.0.0 and Thunderbird < 151.0.0 - Authentication Bypass by Spoofing in Web Speech Component
CVSS 7.5
CVE-2026-8961
MEDIUM
Firefox and Thunderbird < 140.11 and >=151 - Authentication Bypass by Spoofing in Form Autofill
CVSS 6.5
CVE-2026-8960
HIGH
Firefox < 151.0.0 and Thunderbird < 151.0.0 - Authentication Bypass by Spoofing via WebExtensions
CVSS 7.5
CVE-2026-8951
MEDIUM
Spoofing issue in the Toolbar component in Firefox for Android
CVSS 6.5
Details
Vulnerabilities
575