CWE-347

Improper Verification of Cryptographic Signature

Parent: CWE-345 - Insufficient Verification of Data Authenticity

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

742 vulnerabilities with CWE-347
CVE-2026-56451 CRITICAL
Siemens Opcenter X < V2604 - Improper Verification of Cryptographic Signature
CVSS 10.0
CVE-2026-22097 CRITICAL
EVbee DC-80 - Missing Firmware Signature Validation Remote Code Execution
CVE-2026-54736 HIGH
Phalcon: Non-constant-time HMAC verification in `Encryption\Crypt::decrypt` (timing side-channel)
CVE-2026-9027 MEDIUM
CorvusPay WooCommerce Payment Gateway <= 2.7.4 - Payment Bypass
CVSS 5.3
CVE-2026-54783 HIGH
CoreWCF WS-Security - SOAP Message Replay
CVSS 7.4
CVE-2026-54782 CRITICAL
CoreWCF: Authentication bypass in CoreWCF SAML 1.1 / 2.0 token signature validation
CVSS 10.0
CVE-2026-54774 HIGH
CoreWCF: SamlSerializer skips SignatureValue verification when SAML signing token is not an X.509 certificate
CVSS 7.4
CVE-2026-54773 MEDIUM
CoreWCF: WS-Security signature substitution via document-wide Signature lookup
CVSS 5.9
CVE-2026-46354 CRITICAL
Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft
CVSS 9.1
CVE-2026-11348 HIGH
Authentication Bypass in HAVELSAN's Open Source Project Liman MYS
CVSS 8.1
CVE-2026-58426 CRITICAL
Gitea 1.22.0-1.26.1 Actions Artifacts - Cross-Repository Artifact Read and State Write
CVSS 9.6
CVE-2026-13722 HIGH
WatchGuard Firebox Firmware Image Validation Bypass in WatchGuard Fireware OS
CVE-2026-50722 HIGH
IKEv2 Denial of Service via RSA-SHA1 (PKCS#1 RSASSA-PKCS1-v1_5) authentication payload
CVSS 8.1
CVE-2026-50721 HIGH
IKEv1 Denial of Service via RSA-SHA1 (PKCS#1 Version 1.5 Encrypted) authentication payload
CVSS 8.1
CVE-2026-13743 LOW
Improper verification of cryptographic signature in CubeSpace CW0057 Reaction Wheel
CVE-2026-40941 MEDIUM
Cacti: Package Import Signature Validation Bypass Allows Self-Signed Packages
CVSS 6.5
CVE-2026-7511 HIGH
PKCS7_verify signer confusion allows forged signatures to be accepted
CVSS 7.5
CVE-2026-6331 HIGH
wolfSSL - HMAC Zero-Length Tag Forgery in EVP_DigestVerifyFinal
CVSS 7.5
CVE-2026-6329 MEDIUM
PKCS#12 MAC verification uses attacker-controlled comparison length
CVSS 6.5
CVE-2026-11800 HIGH
Org.keycloak:keycloak-services: keycloak: authentication bypass via jwt algorithm confusion
CVSS 8.1
CVE-2026-55961 HIGH
wolfSSL_PKCS7_verify() reports success for degenerate (certs-only) PKCS#7 with no signer
CVSS 7.5
CVE-2026-9779 HIGH
ATEN Unizon doCryptoHugeFileToFile Improper Verification of Cryptographic Signature Remote Code Execution Vulnerability
CVSS 7.2
CVE-2026-46423 CRITICAL
Rocket.Chat: SAML signature validation skipped when IdP certificate field is empty
CVE-2026-46349 MEDIUM
Mastodon: LD-Signature Bypass via JSON-LD Named-Graph Restructuring
CVSS 5.3
CVE-2026-49454 CRITICAL
Relyra SAML SignatureValue not cryptographically verified -> authentication bypass
CVSS 9.1
Details
Vulnerabilities 742