CWE-290

Authentication Bypass by Spoofing

Parent: CWE-1390 - Weak Authentication

This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.

636 vulnerabilities with CWE-290
CVE-2026-54308 HIGH
n8n: Missing Token Validation on Microsoft Agent 365 Trigger Node
CVSS 7.2
CVE-2026-56357 MEDIUM
n8n - Webhook Forgery via Missing HMAC-SHA256 Signature Verification in GitHub Webhook Trigger
CVSS 4.0
CVE-2026-49468 CRITICAL
LiteLLM: Authentication Bypass via Host Header Injection
CVSS 9.8
CVE-2026-49231 MEDIUM
Apache APISIX 3.5.0-3.16.0 OPA Plugin - Identity Spoofing
CVSS 5.4
CVE-2026-39999 CRITICAL
Apache APISIX: JWT Algorithm Confusion allows authentication bypass
CVSS 9.1
CVE-2026-56020 HIGH
Webmin HTTP header authentication bypass
CVSS 8.1
CVE-2026-50141 HIGH
Woodpecker gRPC agent_id metadata can be spoofed- cross-tenant agent impersonation
CVE-2026-55202 HIGH
Tinyproxy - Stathost Detection Bypass via Host Header Manipulation
CVSS 8.2
CVE-2026-53857 HIGH
OpenClaw < 2026.5.3 - Mutable Display Name Binding in Zalo allowFrom Policy
CVSS 8.1
CVE-2026-53849 HIGH
OpenClaw < 2026.5.7 - Privilege Escalation via Mutable Discord Display Names in allowFrom
CVSS 8.1
CVE-2026-42662 MEDIUM
WordPress Event Tickets plugin <= 5.27.5 - Bypass Vulnerability vulnerability
CVSS 6.5
CVE-2026-27089 HIGH
WordPress WpTravelly plugin <= 2.1.7 - Bypass Vulnerability vulnerability
CVSS 7.5
CVE-2026-36537 CRITICAL
ThingsBoard 4.3.0.1 - Authentication Bypass via OAuth User Parameter Manipulation
CVSS 9.8
CVE-2026-49757 CRITICAL
OAuth2/OIDC account takeover in AshAuthentication via email-based user matching
CVE-2026-34025 MEDIUM
IP restriction bypass in Wertheim SafeController Software allows logins from unauthorized network locations
CVE-2026-53833 HIGH
OpenClaw < 2026.4.29 - Authorization Bypass via QQBot Streaming Command
CVSS 7.7
CVE-2026-53832 HIGH
OpenClaw < 2026.5.18 - Identity Header Forgery via Trusted-Proxy Configuration
CVSS 7.7
CVE-2026-53823 HIGH
OpenClaw < 2026.5.3 - Privilege Escalation via Mutable Slack Display Names in allowFrom
CVSS 8.1
CVE-2026-5792 MEDIUM
Authentication Bypass in Related Digital's Related Marketing Cloud (RMC)
CVSS 6.5
CVE-2026-53817 HIGH
OpenClaw < 2026.5.22 - Control UI Locality Spoofing in Device Pairing
CVSS 8.8
CVE-2026-53811 HIGH
OpenClaw < 2026.5.7 - Privilege Escalation via Mutable Display Names in Matrix allowFrom
CVSS 8.8
CVE-2026-6090 HIGH
Lenovo Smart Connect < 09.0.2.003.000 - Authentication Bypass by Spoofing
CVSS 7.0
CVE-2026-48567 CRITICAL
Azure HorizonDB Elevation of Privilege Vulnerability
CVSS 10.0
CVE-2026-11019 MEDIUM
Google Chrome < 149.0.7827.53 - Domain Spoofing via Payments Implementation
CVSS 6.5
CVE-2026-11001 MEDIUM
Google Chrome < 149.0.7827.53 - UI Spoofing via Payments Implementation
CVSS 6.5
Details
Vulnerabilities 636