CWE-347

Improper Verification of Cryptographic Signature

Parent: CWE-345 - Insufficient Verification of Data Authenticity

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

686 vulnerabilities with CWE-347
CVE-2026-33117 CRITICAL
Azure SDK for Java Security Feature Bypass Vulnerability
CVSS 9.1
CVE-2026-41431 HIGH
Zen Browser MAR updater ships with signature verification removed — unsigned updates accepted
CVSS 8.0
CVE-2026-42193 CRITICAL
Plunk: SNS webhook forgery
CVSS 9.1
CVE-2026-44497 CRITICAL
ZEBRA: Consensus Divergence in Transparent Sighash Hash-Type Handling due to Stale Buffer
CVSS 9.1
CVE-2026-42501 HIGH
Malicious module proxy can bypass checksum database in cmd/go
CVSS 7.5
CVE-2026-41669 HIGH
Admidio: SAML Signature Validation Result Ignored — Forged AuthnRequests and LogoutRequests Processed
CVSS 8.2
CVE-2026-7689 LOW
Dolibarr ERP CRM Online Signature security.lib.php dol_verifyHash signature verification
CVSS 3.7
CVE-2026-33467 MEDIUM
Improper Verification of Cryptographic Signature in Elastic Package Registry Leading to Package Integrity Bypass
CVSS 5.9
CVE-2026-38651 HIGH
Netmaker < 1.5.0 - Authentication Bypass via JWT Signature Verification Failure
CVSS 8.2
CVE-2026-6986 LOW
Cesanta Mongoose GCM Authentication Tag tls_aes128.c mg_aes_gcm_decrypt signature verification
CVSS 3.7
CVE-2026-6966 MEDIUM
Signature Threshold Bypass in awslabs/tough Delegated Roles
CVSS 5.3
CVE-2026-6911 CRITICAL
Authentication Bypass via Missing JWT Signature Verification in AWS Ops Wheel
CVSS 9.8
CVE-2026-34068 MEDIUM
nimiq-transaction: UpdateValidator transactions allows voting key change without proof-of-knowledge
CVSS 6.8
CVE-2026-40372 CRITICAL
ASP.NET Core Elevation of Privilege Vulnerability
CVSS 9.1
CVE-2026-41301 MEDIUM
OpenClaw 2026.3.22 < 2026.3.31 - Forged Nostr DM Pairing State Creation via Signature Verification Bypass
CVSS 5.3
CVE-2026-5050 HIGH
Payment Gateway for Redsys & WooCommerce Lite <= 7.0.0 - Improper Verification of Cryptographic Signature to Unauthenticated Payment Status Manipulation
CVSS 7.5
CVE-2026-6328 HIGH
XQUIC Improper STREAM Frame Validation in Initial/Handshake Packets
CVE-2026-24032 HIGH
Siemens SINEC NMS <V4.0 SP3 - Auth Bypass
CVSS 7.3
CVE-2026-0234 HIGH
Cortex XSOAR: Improper Verification of Cryptographic Signature in Microsoft Teams integration
CVE-2026-5466 HIGH
wc_VerifyEccsiHash missing sanity check
CVSS 8.1
CVE-2026-40070 HIGH
bsv-sdk and bsv-wallet persist unverified certifier signatures in acquire_certificate (direct and issuance paths)
CVSS 8.1
CVE-2026-39413 MEDIUM
LightRAG <1.4.14 API - JWT Algorithm Confusion
CVSS 4.2
CVE-2026-2625 MEDIUM
Rust-rpm-sequoia: rust-rpm-sequoia: denial of service via crafted rpm file during signature verification
CVSS 4.0
CVE-2026-34840 HIGH
OneUptime SSO: Multi-Assertion Identity Injection via Decoupled Signature Verification
CVSS 8.1
CVE-2026-33746 CRITICAL
Convoy: JWT Signature Verification Bypass Allows Authentication as Arbitrary Users
CVSS 9.8
Details
Vulnerabilities 686