CWE-290

Authentication Bypass by Spoofing

Parent: CWE-1390 - Weak Authentication

This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.

575 vulnerabilities with CWE-290
CVE-2026-34778 MEDIUM
Electron: Service worker can spoof executeJavaScript IPC replies
CVSS 5.9
CVE-2026-33175 HIGH
OAuthenticator: Authentication Bypass in Auth0OAuthenticator via Unverified Email Claims
CVSS 8.8
CVE-2026-33654 CRITICAL
Zero-Click Indirect Prompt Injection and Authentication Bypass via Email Polling
CVSS 9.8
CVE-2026-33433 HIGH
Traefik Vulnerable to BasicAuth/DigestAuth Identity Spoofing via Non-Canonical headerField
CVSS 8.8
CVE-2026-33661 HIGH
WeChat Pay callback signature verification bypassed when Host header is localhost
CVSS 8.6
CVE-2026-33621 MEDIUM
PinchTab: Unapplied Rate Limiting Middleware Allows Unbounded Brute-Force of API Token
CVSS 4.8
CVE-2026-33223 MEDIUM
NATS Server: Incomplete Stripping of Nats-Request-Info Header Allows Identity Spoofing
CVSS 6.4
CVE-2026-30975 HIGH
Sonarr Authentication Bypass vulnerability
CVSS 8.1
CVE-2026-33246 MEDIUM
NATS: Leafnode connections allow spoofing of Nats-Request-Info identity headers
CVSS 6.4
CVE-2026-32492 MEDIUM
WordPress My Tickets plugin <= 2.1.1 - Bypass Vulnerability vulnerability
CVSS 5.3
CVE-2026-24372 HIGH
WordPress Subscriptions for WooCommerce plugin <= 1.8.10 - Bypass Vulnerability vulnerability
CVSS 7.5
CVE-2026-4728 MEDIUM
Spoofing issue in the Privacy: Anti-Tracking component
CVSS 6.5
CVE-2026-32045 MEDIUM
OpenClaw < 2026.2.21 - Authentication Bypass in HTTP Gateway Routes via Tokenless Tailscale Auth
CVSS 5.9
CVE-2026-32666 HIGH
Automated Logic WebCTRL Premium Server Authentication Bypass by Spoofing
CVSS 7.5
CVE-2026-33131 HIGH
h3 NodeRequestUrl Host Header - Middleware Bypass
CVSS 7.4
CVE-2026-32014 HIGH
OpenClaw < 2026.2.26 - Node Reconnect Metadata Spoofing via Unsigned Platform Fields
CVSS 8.0
CVE-2026-0385 MEDIUM
Microsoft Edge (Chromium-based) for Android - Spoofing
CVSS 5.0
CVE-2026-31889 HIGH
Shopware <6.6.10.15/6.7.8.1 - Auth Bypass
CVSS 8.9
CVE-2026-27478 CRITICAL
Unity Catalog <=0.4.0 - Auth Bypass
CVSS 9.1
CVE-2026-31813 MEDIUM
Supabase Auth <2.185.0 - Auth Bypass
CVSS 4.8
CVE-2026-32229 MEDIUM
JetBrains Hub <2026.1 - Auth Bypass
CVSS 6.8
CVE-2026-28480 MEDIUM
OpenClaw < 2026.2.14 - Authentication Bypass via Telegram Username Spoofing
CVSS 6.5
CVE-2026-28465 MEDIUM
OpenClaw voice-call <2026.2.3 - Auth Bypass
CVSS 5.9
CVE-2026-27700 HIGH
Hono 4.12.0-4.12.1 - IP Spoofing via X-Forwarded-For Header Mishandling
CVSS 8.2
CVE-2026-2800 CRITICAL
Firefox for Android <148 - Spoofing
CVSS 9.8
Details
Vulnerabilities 575