CWE-294
High likelihoodAuthentication Bypass by Capture-replay
Parent: CWE-1390 - Weak Authentication
A capture-replay flaw exists when the design of the product makes it possible for a malicious user to sniff network traffic and bypass authentication by replaying it to the server in question to the same effect as the original message (or with minor changes).
241 vulnerabilities with CWE-294
CVE-2026-53431
CRITICAL
Boruta accepts expired JWT client assertions due to missing exp claim validation
CVE-2026-15614
HIGH
Logto - IdP-initiated SAML Sessions Not Reliably Invalidated (replay)
CVSS 7.5
CVE-2026-47133
MEDIUM
ClearanceKit's signed policy tables lack monotonic counter, allowing replay of older legitimately-signed snapshots
CVE-2026-16083
MEDIUM
Sipeed PicoClaw LINE Webhook line.go webhook.ParseRequest authentication replay
CVSS 5.3
CVE-2026-56453
MEDIUM
HCL DFXAnalytics is affected by an Account Takeover via Response Manipulation vulnerability.
CVSS 5.5
CVE-2026-35141
LOW
HCL DFXAnalytics is affected by a Login Replay Attack vulnerability
CVSS 2.6
CVE-2026-35149
HIGH
HCL DFXServer is affected by an Authentication Bypass vulnerability via server response manipulation.
CVSS 8.2
CVE-2026-57574
HIGH
Misskey: TOTP tokens can be reused
CVE-2026-55370
MEDIUM
Logto: TOTP code can be replayed within the RFC 6238 validity window (one-time use violation)
CVSS 6.4
CVE-2026-28564
CRITICAL
Apache IoTDB: REST Basic Authentication Accepts Stale Cached Credentials
CVSS 9.8
CVE-2026-51597
CRITICAL
MERCURY MIPC252W 1.0.5 Build 230306 - Unauthenticated Authentication Bypass via RTSP Digest Nonce Replay
CVSS 9.1
CVE-2026-54783
HIGH
CoreWCF WS-Security - SOAP Message Replay
CVSS 7.4
CVE-2026-54779
MEDIUM
CoreWCF: SAML token replay protection is inoperative
CVSS 5.9
CVE-2026-26232
CRITICAL
Gitea OAuth2 authorization codes lack expiry and reuse enforcement
CVSS 9.1
CVE-2026-20779
HIGH
Gitea TOTP single-use enforcement defect allows OTP replay
CVSS 7.1
CVE-2026-8927
CRITICAL
curl - Env-Set Cross-Proxy Digest Auth State Leak
CVSS 9.1
CVE-2026-11856
CRITICAL
curl - Cross-Origin Digest Auth State Leak
CVSS 9.8
CVE-2026-44946
HIGH
SAML Authentication Replay in Rancher
CVSS 7.4
CVE-2026-49319
MEDIUM
Alps Electric Co., Ltd. R53R0 Remote Keyless Entry System (RKES) Replay Attack
CVSS 6.5
CVE-2026-56130
LOW
Apache Shiro: Remember-me cookie isn't checked for expiry on the server
CVE-2026-55759
HIGH
Rocket.Chat: Apple Sign-In skips JWT claims validation, allowing expired and cross-audience token replay
CVSS 7.4
CVE-2026-47341
MEDIUM
Apache APISIX 3.11.0-3.16.0 hmac-auth - Session Replay
CVSS 6.5
CVE-2026-34021
HIGH
Lack of cryptographic protection in Wertheim SafeController 5400 enables RS-485 message sniffing and replay
CVE-2026-41000
LOW
WSS4J validation does not use configured replay cache
CVSS 3.7
CVE-2026-49322
MEDIUM
Indian Scout Bobber 2025 WCM - Weak PIN Authentication
CVSS 4.3
Details
Vulnerabilities
241
Exploit Likelihood
High