CWE-347
Improper Verification of Cryptographic Signature
The product does not verify, or incorrectly verifies, the cryptographic signature for data.
742 vulnerabilities with CWE-347
CVE-2026-44104
CRITICAL
ControllerAgent does not perform validation of firmware
CVSS 9.8
CVE-2026-17872
MEDIUM
Google Chrome < 151.0.7922.72 - Sandbox Escape via WebAppInstalls Cryptographic Flaw on Android
CVSS 6.1
CVE-2026-13305
MEDIUM
Autel MaxiCharger AC Elite Home Software Update Improper Verification of Cryptographic Signature Arbitrary Code Execution Vulnerability
CVSS 6.4
CVE-2026-59243
CRITICAL
Apache Airflow FAB provider: FAB auth manager: JWT signature verification disabled by default for Azure AD OAuth (`verify_signature` defaults to `False`)
CVSS 9.8
CVE-2026-63237
MEDIUM
Three Learning Koollab LMS - TOTP Two-Factor Authentication Bypass Vulnerability
CVSS 4.8
CVE-2026-65616
HIGH
Potential privilege escalation to JFrog administrator privileges
CVSS 8.8
CVE-2026-14837
HIGH
Lenze c430 - SSH Enablement Signature Verification Bypass
CVSS 7.8
CVE-2026-48021
CRITICAL
epa4all Security Incident: Implement keystore based on Telematik TSL, implement hostname check and certificate check for lib-vau
CVSS 9.1
CVE-2026-52686
LOW
PowerDNS Recursor - Wildcard CNAME Proof Validation Bypass
CVSS 3.7
CVE-2026-13089
HIGH
OIDC::Lite <= 0.12.1 - ID Token Signature Verification Bypass
CVSS 7.5
CVE-2026-10723
MEDIUM
ISC BIND 9 - Incorrect Acceptance of NSEC3 Records
CVSS 6.8
CVE-2026-64623
HIGH
Network-AI before 5.13.4 Cryptographic Signature Verification Bypass
CVSS 8.6
CVE-2026-49834
MEDIUM
sigstore-go: Multi-log threshold bypass via single compromised log
CVSS 5.9
CVE-2026-49998
HIGH
Centrifugo: Dynamic JWKS key cache keyed only by `kid` allows cross-issuer JWT authentication bypass
CVSS 8.2
CVE-2026-45795
MEDIUM
Janssen Project: JWE Request Object Signature Verification Bypass in jans-auth-server
CVSS 5.3
CVE-2026-54733
CRITICAL
moodle-local_o365: Authentication bypass via unverified JWT signature in Teams SSO endpoint
CVE-2026-15013
CRITICAL
SAML Single Sign On <= 5.4.3 - Unauthenticated Authentication Bypass via 'SAMLResponse' Parameter Signature Algorithm Confusion
CVSS 9.8
CVE-2026-46684
CRITICAL
DataEase: Unauthorized Command Execution Vulnerability
CVE-2026-48815
HIGH
sigstore-js: `certificateOIDs` verification constraints are silently dropped and never enforced
CVSS 7.5
CVE-2026-48758
MEDIUM
sigstore-js: DSSE payloadType type-binding failure
CVSS 5.4
CVE-2026-48747
MEDIUM
Symfony: Mailomat Mailer Webhook Parser Reads the HMAC Algorithm from the Request: Signature Algorithm Downgrade
CVSS 5.3
CVE-2026-47212
MEDIUM
Symfony: Twilio Notifier Webhook Parser Never Verifies the X-Twilio-Signature HMAC: Unauthenticated Webhook Event Injection
CVSS 5.3
CVE-2026-47304
HIGH
Microsoft Visual Studio 2022 version 17.12 - .NET Security Feature Bypass Vulnerability
CVSS 8.1
CVE-2026-45755
MEDIUM
Symfony: Mailtrap Mailer Webhook Parser Never Verifies the X-Mt-Signature HMAC — Unauthenticated Webhook Event Injection
CVSS 5.3
CVE-2026-15265
CRITICAL
Tenable Agent Path Traversal Leading to Remote Code Execution
CVSS 9.1
Details
Vulnerabilities
742