CWE-294

High likelihood

Authentication Bypass by Capture-replay

Parent: CWE-1390 - Weak Authentication

A capture-replay flaw exists when the design of the product makes it possible for a malicious user to sniff network traffic and bypass authentication by replaying it to the server in question to the same effect as the original message (or with minor changes).

241 vulnerabilities with CWE-294
CVE-2026-53431 CRITICAL
Boruta accepts expired JWT client assertions due to missing exp claim validation
CVE-2026-15614 HIGH
Logto - IdP-initiated SAML Sessions Not Reliably Invalidated (replay)
CVSS 7.5
CVE-2026-47133 MEDIUM
ClearanceKit's signed policy tables lack monotonic counter, allowing replay of older legitimately-signed snapshots
CVE-2026-16083 MEDIUM
Sipeed PicoClaw LINE Webhook line.go webhook.ParseRequest authentication replay
CVSS 5.3
CVE-2026-56453 MEDIUM
HCL DFXAnalytics is affected by an Account Takeover via Response Manipulation vulnerability.
CVSS 5.5
CVE-2026-35141 LOW
HCL DFXAnalytics is affected by a Login Replay Attack vulnerability
CVSS 2.6
CVE-2026-35149 HIGH
HCL DFXServer is affected by an Authentication Bypass vulnerability via server response manipulation.
CVSS 8.2
CVE-2026-57574 HIGH
Misskey: TOTP tokens can be reused
CVE-2026-55370 MEDIUM
Logto: TOTP code can be replayed within the RFC 6238 validity window (one-time use violation)
CVSS 6.4
CVE-2026-28564 CRITICAL
Apache IoTDB: REST Basic Authentication Accepts Stale Cached Credentials
CVSS 9.8
CVE-2026-51597 CRITICAL
MERCURY MIPC252W 1.0.5 Build 230306 - Unauthenticated Authentication Bypass via RTSP Digest Nonce Replay
CVSS 9.1
CVE-2026-54783 HIGH
CoreWCF WS-Security - SOAP Message Replay
CVSS 7.4
CVE-2026-54779 MEDIUM
CoreWCF: SAML token replay protection is inoperative
CVSS 5.9
CVE-2026-26232 CRITICAL
Gitea OAuth2 authorization codes lack expiry and reuse enforcement
CVSS 9.1
CVE-2026-20779 HIGH
Gitea TOTP single-use enforcement defect allows OTP replay
CVSS 7.1
CVE-2026-8927 CRITICAL
curl - Env-Set Cross-Proxy Digest Auth State Leak
CVSS 9.1
CVE-2026-11856 CRITICAL
curl - Cross-Origin Digest Auth State Leak
CVSS 9.8
CVE-2026-44946 HIGH
SAML Authentication Replay in Rancher
CVSS 7.4
CVE-2026-49319 MEDIUM
Alps Electric Co., Ltd. R53R0 Remote Keyless Entry System (RKES) Replay Attack
CVSS 6.5
CVE-2026-56130 LOW
Apache Shiro: Remember-me cookie isn't checked for expiry on the server
CVE-2026-55759 HIGH
Rocket.Chat: Apple Sign-In skips JWT claims validation, allowing expired and cross-audience token replay
CVSS 7.4
CVE-2026-47341 MEDIUM
Apache APISIX 3.11.0-3.16.0 hmac-auth - Session Replay
CVSS 6.5
CVE-2026-34021 HIGH
Lack of cryptographic protection in Wertheim SafeController 5400 enables RS-485 message sniffing and replay
CVE-2026-41000 LOW
WSS4J validation does not use configured replay cache
CVSS 3.7
CVE-2026-49322 MEDIUM
Indian Scout Bobber 2025 WCM - Weak PIN Authentication
CVSS 4.3
Details
Vulnerabilities 241
Exploit Likelihood High