CWE-347

Improper Verification of Cryptographic Signature

Parent: CWE-345 - Insufficient Verification of Data Authenticity

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

742 vulnerabilities with CWE-347
CVE-2026-44104 CRITICAL
ControllerAgent does not perform validation of firmware
CVSS 9.8
CVE-2026-17872 MEDIUM
Google Chrome < 151.0.7922.72 - Sandbox Escape via WebAppInstalls Cryptographic Flaw on Android
CVSS 6.1
CVE-2026-13305 MEDIUM
Autel MaxiCharger AC Elite Home Software Update Improper Verification of Cryptographic Signature Arbitrary Code Execution Vulnerability
CVSS 6.4
CVE-2026-59243 CRITICAL
Apache Airflow FAB provider: FAB auth manager: JWT signature verification disabled by default for Azure AD OAuth (`verify_signature` defaults to `False`)
CVSS 9.8
CVE-2026-63237 MEDIUM
Three Learning Koollab LMS - TOTP Two-Factor Authentication Bypass Vulnerability
CVSS 4.8
CVE-2026-65616 HIGH
Potential privilege escalation to JFrog administrator privileges
CVSS 8.8
CVE-2026-14837 HIGH
Lenze c430 - SSH Enablement Signature Verification Bypass
CVSS 7.8
CVE-2026-48021 CRITICAL
epa4all Security Incident: Implement keystore based on Telematik TSL, implement hostname check and certificate check for lib-vau
CVSS 9.1
CVE-2026-52686 LOW
PowerDNS Recursor - Wildcard CNAME Proof Validation Bypass
CVSS 3.7
CVE-2026-13089 HIGH
OIDC::Lite <= 0.12.1 - ID Token Signature Verification Bypass
CVSS 7.5
CVE-2026-10723 MEDIUM
ISC BIND 9 - Incorrect Acceptance of NSEC3 Records
CVSS 6.8
CVE-2026-64623 HIGH
Network-AI before 5.13.4 Cryptographic Signature Verification Bypass
CVSS 8.6
CVE-2026-49834 MEDIUM
sigstore-go: Multi-log threshold bypass via single compromised log
CVSS 5.9
CVE-2026-49998 HIGH
Centrifugo: Dynamic JWKS key cache keyed only by `kid` allows cross-issuer JWT authentication bypass
CVSS 8.2
CVE-2026-45795 MEDIUM
Janssen Project: JWE Request Object Signature Verification Bypass in jans-auth-server
CVSS 5.3
CVE-2026-54733 CRITICAL
moodle-local_o365: Authentication bypass via unverified JWT signature in Teams SSO endpoint
CVE-2026-15013 CRITICAL
SAML Single Sign On <= 5.4.3 - Unauthenticated Authentication Bypass via 'SAMLResponse' Parameter Signature Algorithm Confusion
CVSS 9.8
CVE-2026-46684 CRITICAL
DataEase: Unauthorized Command Execution Vulnerability
CVE-2026-48815 HIGH
sigstore-js: `certificateOIDs` verification constraints are silently dropped and never enforced
CVSS 7.5
CVE-2026-48758 MEDIUM
sigstore-js: DSSE payloadType type-binding failure
CVSS 5.4
CVE-2026-48747 MEDIUM
Symfony: Mailomat Mailer Webhook Parser Reads the HMAC Algorithm from the Request: Signature Algorithm Downgrade
CVSS 5.3
CVE-2026-47212 MEDIUM
Symfony: Twilio Notifier Webhook Parser Never Verifies the X-Twilio-Signature HMAC: Unauthenticated Webhook Event Injection
CVSS 5.3
CVE-2026-47304 HIGH
Microsoft Visual Studio 2022 version 17.12 - .NET Security Feature Bypass Vulnerability
CVSS 8.1
CVE-2026-45755 MEDIUM
Symfony: Mailtrap Mailer Webhook Parser Never Verifies the X-Mt-Signature HMAC — Unauthenticated Webhook Event Injection
CVSS 5.3
CVE-2026-15265 CRITICAL
Tenable Agent Path Traversal Leading to Remote Code Execution
CVSS 9.1
Details
Vulnerabilities 742