CWE-295

Improper Certificate Validation

Parent: CWE-287 - Improper Authentication

The product does not validate, or incorrectly validates, a certificate.

1,453 vulnerabilities with CWE-295
CVE-2026-8497 HIGH
Devolutions Password Manager < 2026.2.2 - Improper Certificate Validation
CVSS 7.4
CVE-2026-18257 MEDIUM
Improper Certificate Validation in S2OPC
CVSS 5.6
CVE-2026-58162 CRITICAL
Apache Traffic Server: Certifier plugin trusts client SNI when generating certificates
CVSS 10.0
CVE-2026-65325 MEDIUM
Apache Traffic Server: HTTP/2 multiplexed origin sessions are reused without certificate re-verification
CVSS 4.8
CVE-2026-16107 MEDIUM
IBM TS4500 CLI Tool 0.1.31-1.12.0.0 - Improper TLS Certificate Validation
CVSS 5.9
CVE-2026-54342 HIGH
TLS Certificate Verification Disabled on CXF Transport Clients in epa4all
CVSS 8.1
CVE-2026-48021 CRITICAL
epa4all Security Incident: Implement keystore based on Telematik TSL, implement hostname check and certificate check for lib-vau
CVSS 9.1
CVE-2026-52688 HIGH
PowerDNS Recursor - DNSSEC Wildcard Validation Bypass
CVSS 7.5
CVE-2026-56820 HIGH
Netty: Missing CertificateID Validation in OCSP Response Allows Replay Attacks
CVSS 7.4
CVE-2026-60648 HIGH
Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0 - Authenticated Remote Code Execution via Web Content Management
CVSS 8.0
CVE-2026-56624 HIGH
Apache MINA SSHD: SSH certificate options lack validations
CVSS 7.3
CVE-2026-46428 CRITICAL
lettre has TLS hostname verification disabled when using Boring TLS backend
CVE-2026-13410 HIGH
Dancer::Plugin::Auth::Google versions through 0.07 for Perl have TLS verification disabled
CVSS 8.2
CVE-2026-38974 MEDIUM
Dulwich <= 1.1.0 - Unauthenticated Remote Code Execution via Missing SSH Host Key Verification in Paramiko Vendor Module
CVSS 5.3
CVE-2026-13385 CRITICAL
Asus Router - Improper Certificate Validation
CVE-2026-50302 MEDIUM
Microsoft Windows 10 Version 21H2 - Windows Cryptographic Services Security Feature Bypass Vulnerability
CVSS 4.2
CVE-2026-55001 HIGH
Microsoft Windows 10 Version 1607 - Active Directory Domain Services Elevation of Privilege Vulnerability
CVSS 7.8
CVE-2026-47632 HIGH
Azure Monitor Agent Metrics Extension Elevation of Privilege Vulnerability
CVSS 8.8
CVE-2026-59836 HIGH
Fortinet FortiClientEMS - Improper Certificate Validation
CVSS 7.5
CVE-2026-15683 HIGH
Lorex 2K Indoor Wi-Fi Security Camera Device Management Server Improper Certificate Validation Vulnerability
CVSS 7.5
CVE-2026-22093 CRITICAL
EVbee Service Android App - Improper Certificate Validation
CVE-2026-54919 HIGH
cpp-httplib: TLS certificate chain verification bypassed for IP-literal hosts on Mbed TLS and wolfSSL backends
CVSS 7.4
CVE-2026-0277 MEDIUM
Prisma Access Agent: Improper Certificate Validation on iOS
CVSS 5.9
CVE-2026-59818 MEDIUM
etcd: gRPC client listener does not enforce `--client-crl-file` certificate revocation
CVSS 6.5
CVE-2026-55436 HIGH
Coder's AI Bridge Proxy skips TLS certificate verification in default configuration
CVSS 7.4
Details
Vulnerabilities 1,453