CWE-290

Authentication Bypass by Spoofing

Parent: CWE-1390 - Weak Authentication

This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.

636 vulnerabilities with CWE-290
CVE-2026-13143 MEDIUM
WP Travel < 11.8.1 - Unauthenticated Payment Bypass via Forged PayPal IPN
CVSS 5.3
CVE-2026-11870 MEDIUM
Hide My WP Ghost < 7.0.05 - IP Address Spoofing via Trusted Proxy Headers Leading to Protection Mechanism Bypass
CVSS 5.4
CVE-2026-28900 MEDIUM
macOS < 14.8.8, < 15.7.8 - Unprotected File Execution via Gatekeeper Bypass in Malicious ZIP Archive
CVSS 5.5
CVE-2026-28849 MEDIUM
macOS < 14.8.8 and < 15.7.8 - Gatekeeper Bypass via Maliciously Crafted ZIP Archive
CVSS 5.5
CVE-2026-11922 MEDIUM
Rate-limit Bypass in zenml-io/zenml
CVSS 6.5
CVE-2026-64875 MEDIUM
Regular Labs GeoIP for Joomla 1.0.0-6.3.8 - Client IP Spoofing
CVSS 6.5
CVE-2026-64797 HIGH
Regular Labs IP Login for Joomla 1.0.0-6.2.5 - Client IP Spoofing
CVSS 7.5
CVE-2026-63683 HIGH
Regular Labs Joomla Extensions - Client IP Spoofing via Forwarded Headers
CVSS 7.5
CVE-2026-54478 LOW
DNS Cookie bypass when combined with proxy-protocol use
CVSS 3.7
CVE-2026-61217 MEDIUM
Oracle Security Service - Improper Access Control
CVSS 6.4
CVE-2026-50755 CRITICAL
next-ai-draw-io 0.4.13 - Authentication Bypass by Spoofing via X-Forwarded-For Header
CVSS 9.8
CVE-2026-16404 HIGH
Mozilla Firefox for Android - Spoofing
CVSS 7.4
CVE-2026-3183 HIGH
Zohocorp ManageEngine ADSelfService Plus - Multi Factor Auth Bypass
CVSS 7.1
CVE-2026-15812 MEDIUM
Kronosnet: kronosnet: access control list bypass via link id spoofing on unencrypted dynamic links
CVSS 4.8
CVE-2026-16076 MEDIUM
AstrBotDevs AstrBot API open_api.py OpenApiRoute.chat_send authentication spoofing
CVSS 6.3
CVE-2026-62224 MEDIUM
OpenClaw MS Teams < 2026.5.12 Authorization Bypass
CVSS 5.4
CVE-2026-55652 CRITICAL
Wekan < 9.46 Header Login - X-Forwarded-For Authentication Bypass
CVSS 9.8
CVE-2026-49353 HIGH
9Router: Local-Only Access Gate Bypass in 9router via Host Header SpoofING
CVSS 7.5
CVE-2026-12382 HIGH
Aap-gateway: missing requestheaderstoremove allows mtls bypass via subject header spoofing
CVSS 8.2
CVE-2026-47737 HIGH
Puma PROXY Protocol v1 Accepts Repeated Protocol Headers on Persistent Connections
CVSS 7.5
CVE-2026-45063 CRITICAL
Symfony: Identity Spoofing via Unanchored DN Regex in X509Authenticator
CVSS 9.1
CVE-2026-45074 HIGH
Symfony: Cas2Handler Derives CAS service URL from Client Host Header → Cross-Service Ticket Replay
CVSS 8.1
CVE-2026-62644 MEDIUM
Roundcube Webmail - Authentication Bypass by Spoofing
CVSS 6.4
CVE-2026-55954 CRITICAL
Missing ID token claim validation in ueberauth_apple allows account takeover
CVE-2026-58488 MEDIUM
HedgeDoc: Rate-limit bypass via CF-Connecting-IP header spoofing
Details
Vulnerabilities 636