This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.
636 vulnerabilities with CWE-290
CVE-2026-33131
HIGH
h3 NodeRequestUrl Host Header - Middleware Bypass
CVSS 7.4
CVE-2026-32014
HIGH
OpenClaw < 2026.2.26 - Node Reconnect Metadata Spoofing via Unsigned Platform Fields
CVSS 8.0
CVE-2026-0385
MEDIUM
Microsoft Edge (Chromium-based) for Android - Spoofing
CVSS 5.0
CVE-2026-31889
HIGH
Shopware <6.6.10.15/6.7.8.1 - Auth Bypass
CVSS 8.9
CVE-2026-27478
CRITICAL
Unity Catalog <=0.4.0 - Auth Bypass
CVSS 9.1
CVE-2026-31813
MEDIUM
Supabase Auth <2.185.0 - Auth Bypass
CVSS 4.8
CVE-2026-32229
MEDIUM
JetBrains Hub <2026.1 - Auth Bypass
CVSS 6.8
CVE-2026-28480
MEDIUM
OpenClaw < 2026.2.14 - Authentication Bypass via Telegram Username Spoofing
CVSS 6.5
CVE-2026-28465
MEDIUM
OpenClaw voice-call <2026.2.3 - Auth Bypass
CVSS 5.9
CVE-2026-27700
HIGH
Hono 4.12.0-4.12.1 - IP Spoofing via X-Forwarded-For Header Mishandling
CVSS 8.2
CVE-2026-2800
CRITICAL
Firefox for Android <148 - Spoofing
CVSS 9.8
CVE-2026-24853
HIGH
caido < 0.55.0 - Authentication Bypass via X-Forwarded-Host Header Spoofing
CVSS 8.1
CVE-2026-25938
CRITICAL
FUXA 1.2.8-1.2.10 - Unauthenticated Remote Code Execution via Node-RED Plugin
CVSS 9.8
CVE-2026-21862
HIGH
rustfs < 1.0.0-alpha.78 - Authentication Bypass via Spoofed X-Forwarded-For Header
CVSS 7.5
CVE-2026-0834
HIGH
TP-Link Archer C20 v5/v6, AX53 v1, TL-WR841N v13 - Unauthenticated RCE via TDDP
CVSS 8.8
CVE-2026-22797
CRITICAL
OpenStack keystonemiddleware <10.7.2, 10.8, 10.9 before 10.9.1, 10....
CVSS 9.9
CVE-2026-0890
MEDIUM
Firefox < 147.0 and Thunderbird < 147.0 - Authentication Bypass by Spoofing via DOM Copy & Paste and Drag & Drop
CVSS 5.4
CVE-2026-21894
MEDIUM
n8n 0.150.0-2.2.1 - Unauthenticated Workflow Trigger via Stripe Webhook Spoofing
CVSS 6.5
CVE-2025-50328
HIGH
B1 Free Archiver 1.5.86 - Auth Bypass
CVSS 7.3
CVE-2025-59707
CRITICAL
N2W <4.3.2 - Spoofing-Based Code Execution and Credential Theft
CVSS 9.8
CVE-2025-59706
CRITICAL
N2W <4.3.2 and 4.4.0 - API Parameter Remote Code Execution
CVSS 9.8
CVE-2025-67298
HIGH
ClasroomIO <0.2.6 - Privilege Escalation
CVSS 8.1
CVE-2025-48840
MEDIUM
Fortinet FortiWeb 7.0-7.6.3 - Auth Bypass
CVSS 5.3
CVE-2025-71056
HIGH
GCOM EPON 1GE ONU C00R371V00B01 - Auth Bypass
CVSS 8.1
CVE-2025-69401
HIGH
WooODT Lite <= 2.5.2 - Authentication Bypass by Spoofing
CVSS 7.5
Details
Vulnerabilities
636