The authentication algorithm is sound, but the implemented mechanism can be bypassed as the result of a separate weakness that is primary to the authentication error.
146 vulnerabilities with CWE-305
CVE-2026-25555
CRITICAL
OpenBullet2 0.3.2 Authentication Bypass via X-Api-Key Header
CVSS 9.8
CVE-2026-9798
MEDIUM
Keycloak: keycloak: brute-force protection bypass in ciba flow
CVSS 4.3
CVE-2026-9047
HIGH
Devolutions Server < 2026.1.16.0 - Authentication Bypass by Primary Weakness
CVSS 7.6
CVE-2026-41054
HIGH
Missing exit out of permission check in haveged could lead to root exploit
CVSS 7.8
CVE-2026-6334
LOW
OAuth authorization code client binding not enforced during token redemption in Mattermost
CVSS 3.1
CVE-2026-2652
HIGH
Authentication Bypass in mlflow/mlflow
CVSS 8.6
CVE-2026-6266
HIGH
Aap-controller: aap-gateway: account hijacking and unauthorized access via unverified email linking
CVSS 8.3
CVE-2026-4670
CRITICAL
Improper Authentication vulnerability in Progress MOVEit Automation
CVSS 9.8
CVE-2026-40582
CRITICAL
ChurchCRM: Authentication Bypass in `/api/public/user/login` Allows Bypass of 2FA and Account Lockout
CVE-2026-33472
MEDIUM
Cryptomator 1.19.1 - OAuth Token Exchange HTTP Downgrade
CVSS 4.8
CVE-2026-20152
MEDIUM
Cisco Secure Web Appliance Authentication Service Traffic Bypass Vulnerability
CVSS 5.3
CVE-2026-33892
HIGH
Siemens Industrial Edge Management Pro V1 <V1.15.17 - Auth Bypass
CVSS 7.1
CVE-2026-40039
MEDIUM
Pachno 1.0.6 Open Redirection via return_to Parameter
CVSS 6.5
CVE-2026-33496
HIGH
Ory Oathkeeper <26.2.0 oauth2_introspection - Authentication Bypass
CVSS 8.1
CVE-2026-3591
MEDIUM
BIND 9 - ACL Bypass via SIG(0) Use-After-Return
CVSS 5.4
CVE-2026-30849
CRITICAL
MantisBT < 2.28.1 - Authentication Bypass via SOAP API Password Parameter
CVSS 9.8
CVE-2026-32730
HIGH
ApostropheCMS MFA/TOTP Bypass via Incorrect MongoDB Query in Bearer Token Middleware
CVSS 8.1
CVE-2026-3784
MEDIUM
curl 7.7-8.18.0 - Authentication Bypass via HTTP Proxy Connection Reuse
CVSS 6.5
CVE-2026-1965
MEDIUM
curl 7.10.6-8.19.0 - Authentication Bypass via Negotiate Connection Reuse
CVSS 6.5
CVE-2026-3047
HIGH
Keycloak SAML Broker - Authentication Bypass via Disabled IdP-Initiated Client
CVSS 8.8
CVE-2026-28536
CRITICAL
Device Authentication Module - Auth Bypass
CVSS 9.6
CVE-2026-1713
MEDIUM
IBM MQ 9.1.0.0-9.4.4.1 - Privilege Escalation
CVSS 5.0
CVE-2026-0869
HIGH
Brocade Active Support Connectivity Gateway 3.4.0 - Unauthenticated Authentication Bypass
CVSS 8.8
CVE-2026-22153
HIGH
FortiOS 7.6.0-7.6.4 - Unauthenticated Authentication Bypass via LDAP Configuration
CVSS 8.1
CVE-2026-1290
MEDIUM
Jamf Pro 11.20-11.24 - Authentication Bypass
Details
Vulnerabilities
146