This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.
636 vulnerabilities with CWE-290
CVE-2026-13143
MEDIUM
WP Travel < 11.8.1 - Unauthenticated Payment Bypass via Forged PayPal IPN
CVSS 5.3
CVE-2026-11870
MEDIUM
Hide My WP Ghost < 7.0.05 - IP Address Spoofing via Trusted Proxy Headers Leading to Protection Mechanism Bypass
CVSS 5.4
CVE-2026-28900
MEDIUM
macOS < 14.8.8, < 15.7.8 - Unprotected File Execution via Gatekeeper Bypass in Malicious ZIP Archive
CVSS 5.5
CVE-2026-28849
MEDIUM
macOS < 14.8.8 and < 15.7.8 - Gatekeeper Bypass via Maliciously Crafted ZIP Archive
CVSS 5.5
CVE-2026-11922
MEDIUM
Rate-limit Bypass in zenml-io/zenml
CVSS 6.5
CVE-2026-64875
MEDIUM
Regular Labs GeoIP for Joomla 1.0.0-6.3.8 - Client IP Spoofing
CVSS 6.5
CVE-2026-64797
HIGH
Regular Labs IP Login for Joomla 1.0.0-6.2.5 - Client IP Spoofing
CVSS 7.5
CVE-2026-63683
HIGH
Regular Labs Joomla Extensions - Client IP Spoofing via Forwarded Headers
CVSS 7.5
CVE-2026-54478
LOW
DNS Cookie bypass when combined with proxy-protocol use
CVSS 3.7
CVE-2026-61217
MEDIUM
Oracle Security Service - Improper Access Control
CVSS 6.4
CVE-2026-50755
CRITICAL
next-ai-draw-io 0.4.13 - Authentication Bypass by Spoofing via X-Forwarded-For Header
CVSS 9.8
CVE-2026-16404
HIGH
Mozilla Firefox for Android - Spoofing
CVSS 7.4
CVE-2026-3183
HIGH
Zohocorp ManageEngine ADSelfService Plus - Multi Factor Auth Bypass
CVSS 7.1
CVE-2026-15812
MEDIUM
Kronosnet: kronosnet: access control list bypass via link id spoofing on unencrypted dynamic links
CVSS 4.8
CVE-2026-16076
MEDIUM
AstrBotDevs AstrBot API open_api.py OpenApiRoute.chat_send authentication spoofing
CVSS 6.3
CVE-2026-62224
MEDIUM
OpenClaw MS Teams < 2026.5.12 Authorization Bypass
CVSS 5.4
CVE-2026-55652
CRITICAL
Wekan < 9.46 Header Login - X-Forwarded-For Authentication Bypass
CVSS 9.8
CVE-2026-49353
HIGH
9Router: Local-Only Access Gate Bypass in 9router via Host Header SpoofING
CVSS 7.5
CVE-2026-12382
HIGH
Aap-gateway: missing requestheaderstoremove allows mtls bypass via subject header spoofing
CVSS 8.2
CVE-2026-47737
HIGH
Puma PROXY Protocol v1 Accepts Repeated Protocol Headers on Persistent Connections
CVSS 7.5
CVE-2026-45063
CRITICAL
Symfony: Identity Spoofing via Unanchored DN Regex in X509Authenticator
CVSS 9.1
CVE-2026-45074
HIGH
Symfony: Cas2Handler Derives CAS service URL from Client Host Header → Cross-Service Ticket Replay
CVSS 8.1
CVE-2026-62644
MEDIUM
Roundcube Webmail - Authentication Bypass by Spoofing
CVSS 6.4
CVE-2026-55954
CRITICAL
Missing ID token claim validation in ueberauth_apple allows account takeover
CVE-2026-58488
MEDIUM
HedgeDoc: Rate-limit bypass via CF-Connecting-IP header spoofing
Details
Vulnerabilities
636