CWE-345

Insufficient Verification of Data Authenticity

Parent: CWE-693 - Protection Mechanism Failure

The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

657 vulnerabilities with CWE-345
CVE-2026-41577 HIGH
authentik: SAML source does not validate Conditions, timing, or audience on assertions
CVSS 7.5
CVE-2026-47123 HIGH
FreeScout: Agent Impersonation via Missing HMAC Verification on Notification Reply Message-ID Path
CVSS 7.5
CVE-2026-47696 MEDIUM
WWBN AVideo: Authenticated wallet credit bypass in AuthorizeNet processPayment endpoint
CVSS 4.3
CVE-2026-9189 MEDIUM
Contact Form 7 PayPal & Stripe Add-on <= 2.4.9 - Payment Bypass
CVSS 5.3
CVE-2026-45058 CRITICAL
electerm: Import unsafe bookmark data could lead to unsafe operation when click local type bookmark
CVE-2026-46538 MEDIUM
Microsoft UFO accepts cross-device TASK_END messages by session_id only, allowing peer task-result injection
CVSS 5.9
CVE-2026-45022 HIGH
go-git: Improper parsing of specially crafted objects may lead to inconsistent interpretation compared to upstream Git
CVSS 7.5
CVE-2026-3012 HIGH
Samba: group policy certificate enrollment uses http:// without validation
CVSS 8.0
CVE-2026-47202 CRITICAL
Kavita: Pre-Auth Account Takeover
CVE-2026-41164 MEDIUM
nuts-node: JWT type confusion in v1 access token introspection allows VP replay as access token
CVSS 4.4
CVE-2026-39969 MEDIUM
TypeBot: WhatsApp Webhook Endpoint Missing Signature Verification
CVSS 6.5
CVE-2026-25602 MEDIUM
Mesalvo Meona Client Launcher <= 19.06.2020 & Server <= 2025.04 - Data Authenticity Verification Bypass
CVSS 4.4
CVE-2026-33233 HIGH
AutoGPT Platform: Remote Code Execution via Unsafe Pickle Deserialization of Redis Cache Entries
CVSS 7.6
CVE-2026-32323 HIGH
Mullvad VPN for macOS: Local Privilege Escalation via unverified bundle path in installer
CVSS 7.3
CVE-2026-44592 CRITICAL
Gradient: Unauthenticated worker on /proto → arbitrary NAR write / cache poisoning
CVSS 9.4
CVE-2026-44523 CRITICAL
Note Mark: JWT Secret Weakness allows Full Account Takeover via token forgery
CVSS 10.0
CVE-2026-44308 MEDIUM
Spring Cloud AWS: Missing SNS message signature verification allows spoofing of HTTP/HTTPS endpoint notifications
CVE-2026-45055 HIGH
CubeCart: Pre-Authenticated Password Reset Link Poisoning via HTTP Host Header
CVSS 8.1
CVE-2026-44999 MEDIUM
OpenClaw < 2026.4.20 - Improper Trust Labeling in Isolated Cron Awareness Events
CVSS 5.3
CVE-2026-42575 HIGH
apko doesn't verify downloaded apk packages against APKINDEX checksum (package substitution possible)
CVSS 7.5
CVE-2026-41432 HIGH
New API: Stripe Webhook Signature Bypass via Empty Secret Enables Unlimited Quota Fraud
CVSS 7.1
CVE-2026-42206 MEDIUM
Roadiz OpenID Connect nonce generated but never validated — ID token replay attack
CVE-2026-31835 MEDIUM
Vaultwarden WebAuthn credential metadata tampered before signature verification
CVSS 5.4
CVE-2026-43534 CRITICAL
OpenClaw < 2026.4.10 - Unsanitized External Input in Agent Hook Events
CVSS 9.1
CVE-2026-7689 LOW
Dolibarr ERP CRM Online Signature security.lib.php dol_verifyHash signature verification
CVSS 3.7
Details
Vulnerabilities 657