CWE-347

Improper Verification of Cryptographic Signature

Parent: CWE-345 - Insufficient Verification of Data Authenticity

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

686 vulnerabilities with CWE-347
CVE-2026-42743 MEDIUM
WordPress Masteriyo - LMS plugin <= 2.1.8 - Broken Authentication vulnerability
CVSS 6.5
CVE-2026-48558 CRITICAL
SimpleHelp Authentication Bypass via Missing OIDC JWT Signature Verification
CVSS 10.0
CVE-2026-50010 HIGH
Netty's wrapping plain trust manager silently disables hostname verification
CVSS 7.5
CVE-2026-50634 MEDIUM
Apache CXF: WS JSON request filter trusts metadata from an unvalidated first signature entry
CVSS 6.5
CVE-2026-41005 CRITICAL
Cloud Foundry - UAA Accepts SAML Encrypted Assertions Authentication Bypass
CVSS 9.0
CVE-2026-10795 HIGH
UpdraftPlus: WP Backup & Migration Plugin <= 1.26.4 - Unauthenticated Authentication Bypass via UpdraftCentral udrpc
CVSS 8.1
CVE-2026-42462 HIGH
Fedify has an LD-Signature Bypass via JSON-LD Named-Graph Restructuring
CVSS 7.0
CVE-2026-52754 HIGH
Ghidra < 12.1 - Authentication Bypass via Null Signature in PKIAuthenticationModule
CVSS 8.8
CVE-2026-41694 LOW
Spring Security - SAML Payloads Decrypted Without Valid Signature
CVSS 3.7
CVE-2026-36721 CRITICAL
bookcars 8.3 - Authentication Bypass via Forged JWT Token
CVSS 9.8
CVE-2026-44748 CRITICAL
XML Signature Wrapping in SAML Authentication in SAP NetWeaver AS ABAP and ABAP Platform
CVSS 9.9
CVE-2026-45614 MEDIUM
OP-TEE optee_os - OP-TEE Vulnerable to ECDH Private Key Recovery
CVSS 4.7
CVE-2026-6873 LOW
Signed cookie salt namespace collision in django.http.HttpRequest.get_signed_cookie
CVSS 3.1
CVE-2026-47201 HIGH
authentik: XML Signature Wrapping in SAML Source ACS allows authentication as arbitrary federated user
CVSS 8.5
CVE-2026-48526 HIGH
PyJWT: Public-key JWK accepted as HMAC secret enables forged HS256 tokens when mixed families are allowed
CVSS 7.4
CVE-2026-48523 MEDIUM
PyJWT: Algorithm allow-list bypass when decoding with `PyJWK` / `PyJWKClient` keys
CVSS 5.4
CVE-2026-9793 MEDIUM
Keycloak: keycloak: security policy bypass in jwe-encrypted request object processing
CVSS 5.9
CVE-2026-44720 MEDIUM
OpenLearnX: Critical Authentication Bypass via JWT Signature Verification Disabled Leading to Account Takeover
CVE-2026-45575 HIGH
epa4all-client: Improper Verification of Cryptographic Signature
CVSS 7.4
CVE-2026-39829 HIGH
Invoking pathological RSA/DSA parameters may cause DoS in golang.org/x/crypto/ssh
CVSS 7.5
CVE-2026-44714 HIGH
bitcoinj: ScriptExecution P2PKH/P2WPKH Verification Bypass
CVSS 7.5
CVE-2026-44699 CRITICAL
LibJWT: Algorithm confusion allows JWT forgery with RSA JWK as empty-key HMAC
CVE-2026-44309 MEDIUM
gitsign verify accepts signatures over go-git-normalized bytes, enabling trust confusion on malformed commits
CVSS 5.3
CVE-2026-42602 HIGH
azureauthextension Authenticate method does not validate bearer tokens, allowing auth bypass via replay
CVSS 8.1
CVE-2026-0265 HIGH
Palo Alto Networks PAN-OS Unauthenticated Authentication Bypass via Cloud Authentication Service
Details
Vulnerabilities 686