CWE-290

Authentication Bypass by Spoofing

Parent: CWE-1390 - Weak Authentication

This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.

535 vulnerabilities with CWE-290
CVE-2026-39858 HIGH
Traefik: Forwarded alias spoofing top pre-auth decision bypass
CVE-2026-7422 MEDIUM
MAC Address Validation Bypass in FreeRTOS-Plus-TCP IPv4 and IPv6 Packet Processing
CVSS 6.5
CVE-2026-25660 CRITICAL
Authentication bypass for certain API calls
CVSS 9.8
CVE-2026-40575 CRITICAL
OAuth2 Proxy has an Authentication Bypass via X-Forwarded-Uri Header Spoofing
CVSS 9.1
CVE-2026-6762 MEDIUM
Spoofing issue in the DOM: Core & HTML component
CVSS 6.3
CVE-2026-22734 HIGH
Cloud Foundry UAA SAML 2.0 Signature Bypass
CVSS 8.6
CVE-2026-34457 CRITICAL
OAuth2 Proxy: Health Check User-Agent Matching Bypasses Authentication in auth_request Mode
CVSS 9.1
CVE-2026-39419 LOW
MaxKB: Sandbox Result Validation Bypass via Tool Output Spoofing
CVSS 3.1
CVE-2026-35656 MEDIUM
OpenClaw < 2026.3.22 - XFF Loopback Spoofing Bypass in Canvas Authentication and Rate Limiter
CVSS 6.5
CVE-2026-35622 MEDIUM
OpenClaw < 2026.3.22 - Improper Authentication Verification in Google Chat Webhook
CVSS 5.9
CVE-2026-39959 HIGH
Tmds.DBus: malicious D-Bus peers can spoof signals, exhaust file descriptor resources, and cause denial of service
CVSS 7.1
CVE-2026-39411 MEDIUM
LobeHub has an unauthenticated authentication bypass on `webapi` routes via forgeable `X-lobe-chat-auth` header
CVSS 5.0
CVE-2026-3902 HIGH
ASGI header spoofing via underscore/hyphen conflation
CVSS 7.5
CVE-2026-34778 MEDIUM
Electron: Service worker can spoof executeJavaScript IPC replies
CVSS 5.9
CVE-2026-33175 HIGH
OAuthenticator: Authentication Bypass in Auth0OAuthenticator via Unverified Email Claims
CVSS 8.8
CVE-2026-33654 CRITICAL
Zero-Click Indirect Prompt Injection and Authentication Bypass via Email Polling
CVSS 9.8
CVE-2026-33433 HIGH
Traefik Vulnerable to BasicAuth/DigestAuth Identity Spoofing via Non-Canonical headerField
CVSS 8.8
CVE-2026-33661 HIGH
WeChat Pay callback signature verification bypassed when Host header is localhost
CVSS 8.6
CVE-2026-33621 MEDIUM
PinchTab: Unapplied Rate Limiting Middleware Allows Unbounded Brute-Force of API Token
CVSS 4.8
CVE-2026-33223 MEDIUM
NATS Server: Incomplete Stripping of Nats-Request-Info Header Allows Identity Spoofing
CVSS 6.4
CVE-2026-30975 HIGH
Sonarr Authentication Bypass vulnerability
CVSS 8.1
CVE-2026-33246 MEDIUM
NATS: Leafnode connections allow spoofing of Nats-Request-Info identity headers
CVSS 6.4
CVE-2026-32492 MEDIUM
WordPress My Tickets plugin <= 2.1.1 - Bypass Vulnerability vulnerability
CVSS 5.3
CVE-2026-24372 HIGH
WordPress Subscriptions for WooCommerce plugin <= 1.8.10 - Bypass Vulnerability vulnerability
CVSS 7.5
CVE-2026-4728 MEDIUM
Spoofing issue in the Privacy: Anti-Tracking component
CVSS 6.5
Details
Vulnerabilities 535