CWE-347
Improper Verification of Cryptographic Signature
The product does not verify, or incorrectly verifies, the cryptographic signature for data.
742 vulnerabilities with CWE-347
CVE-2026-56451
CRITICAL
Siemens Opcenter X < V2604 - Improper Verification of Cryptographic Signature
CVSS 10.0
CVE-2026-22097
CRITICAL
EVbee DC-80 - Missing Firmware Signature Validation Remote Code Execution
CVE-2026-54736
HIGH
Phalcon: Non-constant-time HMAC verification in `Encryption\Crypt::decrypt` (timing side-channel)
CVE-2026-9027
MEDIUM
CorvusPay WooCommerce Payment Gateway <= 2.7.4 - Payment Bypass
CVSS 5.3
CVE-2026-54783
HIGH
CoreWCF WS-Security - SOAP Message Replay
CVSS 7.4
CVE-2026-54782
CRITICAL
CoreWCF: Authentication bypass in CoreWCF SAML 1.1 / 2.0 token signature validation
CVSS 10.0
CVE-2026-54774
HIGH
CoreWCF: SamlSerializer skips SignatureValue verification when SAML signing token is not an X.509 certificate
CVSS 7.4
CVE-2026-54773
MEDIUM
CoreWCF: WS-Security signature substitution via document-wide Signature lookup
CVSS 5.9
CVE-2026-46354
CRITICAL
Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft
CVSS 9.1
CVE-2026-11348
HIGH
Authentication Bypass in HAVELSAN's Open Source Project Liman MYS
CVSS 8.1
CVE-2026-58426
CRITICAL
Gitea 1.22.0-1.26.1 Actions Artifacts - Cross-Repository Artifact Read and State Write
CVSS 9.6
CVE-2026-13722
HIGH
WatchGuard Firebox Firmware Image Validation Bypass in WatchGuard Fireware OS
CVE-2026-50722
HIGH
IKEv2 Denial of Service via RSA-SHA1 (PKCS#1 RSASSA-PKCS1-v1_5) authentication payload
CVSS 8.1
CVE-2026-50721
HIGH
IKEv1 Denial of Service via RSA-SHA1 (PKCS#1 Version 1.5 Encrypted) authentication payload
CVSS 8.1
CVE-2026-13743
LOW
Improper verification of cryptographic signature in CubeSpace CW0057 Reaction Wheel
CVE-2026-40941
MEDIUM
Cacti: Package Import Signature Validation Bypass Allows Self-Signed Packages
CVSS 6.5
CVE-2026-7511
HIGH
PKCS7_verify signer confusion allows forged signatures to be accepted
CVSS 7.5
CVE-2026-6331
HIGH
wolfSSL - HMAC Zero-Length Tag Forgery in EVP_DigestVerifyFinal
CVSS 7.5
CVE-2026-6329
MEDIUM
PKCS#12 MAC verification uses attacker-controlled comparison length
CVSS 6.5
CVE-2026-11800
HIGH
Org.keycloak:keycloak-services: keycloak: authentication bypass via jwt algorithm confusion
CVSS 8.1
CVE-2026-55961
HIGH
wolfSSL_PKCS7_verify() reports success for degenerate (certs-only) PKCS#7 with no signer
CVSS 7.5
CVE-2026-9779
HIGH
ATEN Unizon doCryptoHugeFileToFile Improper Verification of Cryptographic Signature Remote Code Execution Vulnerability
CVSS 7.2
CVE-2026-46423
CRITICAL
Rocket.Chat: SAML signature validation skipped when IdP certificate field is empty
CVE-2026-46349
MEDIUM
Mastodon: LD-Signature Bypass via JSON-LD Named-Graph Restructuring
CVSS 5.3
CVE-2026-49454
CRITICAL
Relyra SAML SignatureValue not cryptographically verified -> authentication bypass
CVSS 9.1
Details
Vulnerabilities
742