The requirements for the product dictate the use of an established authentication algorithm, but the implementation of the algorithm is incorrect.
96 vulnerabilities with CWE-303
CVE-2026-59309
CRITICAL
Vmware Cloud Foundation < 9.1.x.x - Authentication Bypass
CVSS 9.8
CVE-2026-66028
MEDIUM
Ekushey Project Manager CRM 5.0 Missing Uniqueness Constraint via Client Email
CVSS 6.7
CVE-2026-57852
MEDIUM
Authentication Bypass via Null Short-Circuit in Grav CMS Scheduler Webhook Token Check
CVSS 5.6
CVE-2026-47300
HIGH
Microsoft .NET 10.0 - ASP.NET Core Elevation of Privilege Vulnerability
CVSS 8.8
CVE-2026-50360
HIGH
Microsoft Windows 10 Version 21H2 - Windows SMB Server Elevation of Privilege Vulnerability
CVSS 8.8
CVE-2026-41053
HIGH
Over-inclusive team membership expansion in GitHub App authentication provider for Rancher
CVSS 8.8
CVE-2026-12773
HIGH
BerriAI litellm MCP Proxy user_api_key_auth_mcp.py UserAPIKeyAuth improper authentication
CVSS 7.3
CVE-2026-50627
CRITICAL
Apache CXF: OAuth2: Missing JWT Audience and Issuer Validation in Access Token Validator
CVSS 9.1
CVE-2026-46389
CRITICAL
UDS Identity Config 0.11.0-0.26.0 - Client Authentication Bypass
CVSS 10.0
CVE-2026-46595
CRITICAL
Invoking VerifiedPublicKeyCallback permissions skip enforcement in golang.org/x/crypto/ssh
CVSS 10.0
CVE-2026-8922
MEDIUM
Org.keycloak/keycloak-services: keycloak: org.keycloak.protocol.oidc: security flaw in org.keycloak/keycloak-services
CVSS 5.4
CVE-2026-41103
CRITICAL
Microsoft SSO Plugin for Jira & Confluence Elevation of Privilege Vulnerability
CVSS 9.1
CVE-2026-43640
HIGH
Bitwarden Server < 2026.4.1 Authentication Bypass via SCIM API Key
CVSS 8.1
CVE-2026-35579
CRITICAL
CoreDNS TSIG authentication bypass on gRPC, QUIC, DoH, and DoH3 transports
CVSS 9.8
CVE-2026-33190
HIGH
CoreDNS TSIG authentication bypass on encrypted DNS transports
CVSS 7.5
CVE-2026-0073
HIGH
Google Android <16-qpr2 - Auth Bypass
CVSS 8.8
CVE-2026-33557
CRITICAL
Apache Kafka: Missing JWT token validation in OAUTHBEARER authentication
CVSS 9.1
CVE-2026-27656
MEDIUM
Account Takeover via Substring Matching in OpenID Connect Authentication
CVSS 5.7
CVE-2026-32953
MEDIUM
Tillitis TKey Client <1.3.0 User Secrets - Protocol Implementation Error
CVSS 4.6
CVE-2026-29515
CRITICAL
MiCode FileExplorer - Unauthenticated Authentication Bypass in SwiFTP FTP Server
CVSS 9.8
CVE-2026-28446
CRITICAL
OpenClaw < 2026.2.2 - Authentication Bypass via Empty Caller ID or Suffix Matching
CVSS 9.4
CVE-2026-0999
MEDIUM
Mattermost 11.1.x-11.1.2 - Auth Bypass
CVSS 5.4
CVE-2025-14510
HIGH
ABB Ability OPTIMAX <6.3.1-251120, <6.4.1-251120 - Incorrect Implem...
CVSS 8.1
CVE-2025-4676
HIGH
ABB WebPro SNMP Card PowerValue <1.1.8.K - Auth Bypass
CVSS 8.8
CVE-2025-14273
HIGH
Mattermost <11.1.0, 10.12.3, 10.11.7 - Auth Bypass
CVSS 7.2
Details
Vulnerabilities
96