CWE-347
Improper Verification of Cryptographic Signature
The product does not verify, or incorrectly verifies, the cryptographic signature for data.
686 vulnerabilities with CWE-347
CVE-2026-42743
MEDIUM
WordPress Masteriyo - LMS plugin <= 2.1.8 - Broken Authentication vulnerability
CVSS 6.5
CVE-2026-48558
CRITICAL
SimpleHelp Authentication Bypass via Missing OIDC JWT Signature Verification
CVSS 10.0
CVE-2026-50010
HIGH
Netty's wrapping plain trust manager silently disables hostname verification
CVSS 7.5
CVE-2026-50634
MEDIUM
Apache CXF: WS JSON request filter trusts metadata from an unvalidated first signature entry
CVSS 6.5
CVE-2026-41005
CRITICAL
Cloud Foundry - UAA Accepts SAML Encrypted Assertions Authentication Bypass
CVSS 9.0
CVE-2026-10795
HIGH
UpdraftPlus: WP Backup & Migration Plugin <= 1.26.4 - Unauthenticated Authentication Bypass via UpdraftCentral udrpc
CVSS 8.1
CVE-2026-42462
HIGH
Fedify has an LD-Signature Bypass via JSON-LD Named-Graph Restructuring
CVSS 7.0
CVE-2026-52754
HIGH
Ghidra < 12.1 - Authentication Bypass via Null Signature in PKIAuthenticationModule
CVSS 8.8
CVE-2026-41694
LOW
Spring Security - SAML Payloads Decrypted Without Valid Signature
CVSS 3.7
CVE-2026-36721
CRITICAL
bookcars 8.3 - Authentication Bypass via Forged JWT Token
CVSS 9.8
CVE-2026-44748
CRITICAL
XML Signature Wrapping in SAML Authentication in SAP NetWeaver AS ABAP and ABAP Platform
CVSS 9.9
CVE-2026-45614
MEDIUM
OP-TEE optee_os - OP-TEE Vulnerable to ECDH Private Key Recovery
CVSS 4.7
CVE-2026-6873
LOW
Signed cookie salt namespace collision in django.http.HttpRequest.get_signed_cookie
CVSS 3.1
CVE-2026-47201
HIGH
authentik: XML Signature Wrapping in SAML Source ACS allows authentication as arbitrary federated user
CVSS 8.5
CVE-2026-48526
HIGH
PyJWT: Public-key JWK accepted as HMAC secret enables forged HS256 tokens when mixed families are allowed
CVSS 7.4
CVE-2026-48523
MEDIUM
PyJWT: Algorithm allow-list bypass when decoding with `PyJWK` / `PyJWKClient` keys
CVSS 5.4
CVE-2026-9793
MEDIUM
Keycloak: keycloak: security policy bypass in jwe-encrypted request object processing
CVSS 5.9
CVE-2026-44720
MEDIUM
OpenLearnX: Critical Authentication Bypass via JWT Signature Verification Disabled Leading to Account Takeover
CVE-2026-45575
HIGH
epa4all-client: Improper Verification of Cryptographic Signature
CVSS 7.4
CVE-2026-39829
HIGH
Invoking pathological RSA/DSA parameters may cause DoS in golang.org/x/crypto/ssh
CVSS 7.5
CVE-2026-44714
HIGH
bitcoinj: ScriptExecution P2PKH/P2WPKH Verification Bypass
CVSS 7.5
CVE-2026-44699
CRITICAL
LibJWT: Algorithm confusion allows JWT forgery with RSA JWK as empty-key HMAC
CVE-2026-44309
MEDIUM
gitsign verify accepts signatures over go-git-normalized bytes, enabling trust confusion on malformed commits
CVSS 5.3
CVE-2026-42602
HIGH
azureauthextension Authenticate method does not validate bearer tokens, allowing auth bypass via replay
CVSS 8.1
CVE-2026-0265
HIGH
Palo Alto Networks PAN-OS Unauthenticated Authentication Bypass via Cloud Authentication Service
Details
Vulnerabilities
686