This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.
636 vulnerabilities with CWE-290
CVE-2026-8644
CRITICAL
IBM WebSphere Application Server 8.5 and 9.0 - Authentication Bypass by Spoofing
CVSS 9.1
CVE-2026-42674
HIGH
WordPress Advanced Access Manager plugin <= 7.1.0 - Bypass Vulnerability vulnerability
CVSS 7.5
CVE-2026-47123
HIGH
FreeScout: Agent Impersonation via Missing HMAC Verification on Notification Reply Message-ID Path
CVSS 7.5
CVE-2026-44649
CRITICAL
SillyTavern: Authentication Bypass via SSO Header Injection
CVSS 9.8
CVE-2026-46414
HIGH
Microsoft UFO WebSocket role spoofing allows authenticated peer task hijacking
CVSS 8.8
CVE-2026-8676
HIGH
Silabs.com Simplicity SDK < 2024.12.0 - Authentication Bypass by Spoofing
CVSS 8.8
CVE-2026-39309
MEDIUM
Trilium Notes: macOS TCC Bypass via Prompt Spoofing
CVSS 5.5
CVE-2026-8963
HIGH
Firefox < 151.0.0 and Thunderbird < 151.0.0 - Authentication Bypass by Spoofing in Web Speech Component
CVSS 7.5
CVE-2026-8961
MEDIUM
Firefox and Thunderbird < 140.11 and >=151 - Authentication Bypass by Spoofing in Form Autofill
CVSS 6.5
CVE-2026-8960
HIGH
Firefox < 151.0.0 and Thunderbird < 151.0.0 - Authentication Bypass by Spoofing via WebExtensions
CVSS 7.5
CVE-2026-8951
MEDIUM
Spoofing issue in the Toolbar component in Firefox for Android
CVSS 6.5
CVE-2026-7507
HIGH
Org.keycloak/keycloak-services: session fixation in oidc login flow that can lead to account takeover
CVSS 7.5
CVE-2026-46356
HIGH
Fleet: IP spoofing allows bypassing API rate limiting
CVSS 7.5
CVE-2026-24899
HIGH
Fleet Windows MDM Azure AD JWT Authentication Bypass
CVSS 7.5
CVE-2026-24000
MEDIUM
Fleet <4.80.1 Client IP Headers - Rate Limit Bypass
CVSS 5.3
CVE-2026-42602
HIGH
azureauthextension Authenticate method does not validate bearer tokens, allowing auth bypass via replay
CVSS 8.1
CVE-2026-40460
MEDIUM
NGINX Plus and Open Source - Authentication Bypass via HTTP/3 QUIC Module
CVSS 6.5
CVE-2026-44183
CRITICAL
Cleanuparr: X-Forwarded-For leftmost parsing allows remote unauthenticated admin takeover when reverse-proxy mode is enabled
CVSS 9.8
CVE-2026-28954
HIGH
iOS and iPadOS < 18.7.9 and macOS < 14.8.7, < 15.7.7, < 26.5 - File Quarantine Bypass via Malicious Disk Image
CVSS 7.5
CVE-2026-45223
HIGH
Crabbox < 0.9.0 Authentication Bypass via Admin Claim Injection
CVSS 8.8
CVE-2026-42354
CRITICAL
Sentry: Improper authentication on SAML SSO process allows user identity linking
CVSS 9.1
CVE-2026-6213
CRITICAL
Remote Spark SparkView RCE
CVE-2026-44118
HIGH
OpenClaw < 2026.4.22 - Owner Context Spoofing via Bearer Token Header
CVSS 7.8
CVE-2026-39858
CRITICAL
Traefik: Forwarded alias spoofing top pre-auth decision bypass
CVSS 10.0
CVE-2026-7422
MEDIUM
MAC Address Validation Bypass in FreeRTOS-Plus-TCP IPv4 and IPv6 Packet Processing
CVSS 6.5
Details
Vulnerabilities
636