CWE-807
High likelihoodReliance on Untrusted Inputs in a Security Decision
The product uses a protection mechanism that relies on the existence or values of an input, but the input can be modified by an untrusted actor in a way that bypasses the protection mechanism.
76 vulnerabilities with CWE-807
CVE-2026-12058
MEDIUM
Vivo PcSuite - Reliance on Untrusted Inputs in a Security Decision
CVE-2026-44649
CRITICAL
SillyTavern: Authentication Bypass via SSO Header Injection
CVSS 9.8
CVE-2026-43935
HIGH
e107: Host Header Injection in e107 password reset enables phishing
CVSS 8.1
CVE-2026-6213
CRITICAL
Remote Spark SparkView RCE
CVE-2026-39807
MEDIUM
Client-supplied URI scheme trusted without transport verification in bandit
CVE-2026-41403
LOW
OpenClaw < 2026.3.31 - Access Control Bypass via Proxied Remote Request Misclassification
CVSS 2.9
CVE-2026-41390
HIGH
OpenClaw < 2026.3.28 - Exec Allowlist Bypass via Unregistered /usr/bin/script Wrapper
CVSS 7.3
CVE-2026-41380
HIGH
OpenClaw < 2026.3.28 - Arbitrary Execution Allowlist via Wrapper Carrier Executables
CVSS 7.3
CVE-2026-1789
MEDIUM
Canon imagePRESS Series - Info Disclosure
CVSS 4.9
CVE-2026-41299
HIGH
OpenClaw < 2026.3.28 - Client Identity Spoofing in chat.send Gateway Provenance Guard
CVSS 7.1
CVE-2026-0390
MEDIUM
UEFI Secure Boot Security Feature Bypass Vulnerability
CVSS 6.7
CVE-2026-35670
MEDIUM
OpenClaw < 2026.3.22 - Webhook Reply Rebinding via Username Resolution in Synology Chat
CVSS 5.9
CVE-2026-35655
MEDIUM
OpenClaw < 2026.3.22 - Identity Spoofing via rawInput Tool in ACP Permission Resolution
CVSS 5.7
CVE-2026-35624
MEDIUM
OpenClaw < 2026.3.22 - Policy Confusion via Room Name Collision in Nextcloud Talk
CVSS 4.2
CVE-2026-35617
MEDIUM
OpenClaw < 2026.3.25 - Authorization Bypass via Group Policy Rebinding with Mutable Space displayName
CVSS 4.2
CVE-2026-29134
HIGH
SEPPmail Secure Email Gateway - GINA Domain Switch
CVSS 7.5
CVE-2026-32975
CRITICAL
OpenClaw < 2026.3.12 - Weak Authorization via Mutable Group Names in Zalouser Allowlist
CVSS 9.8
CVE-2026-32898
MEDIUM
OpenClaw < 2026.2.23 - ACP Permission Auto-Approval Bypass via Untrusted Tool Metadata
CVSS 5.4
CVE-2026-32057
HIGH
OpenClaw < 2026.2.25 - Authentication Bypass via Control UI client.id Parameter
CVSS 7.1
CVE-2026-29794
MEDIUM
Vikunja has Rate-Limit Bypass for Unauthenticated Users via Spoofed Headers
CVSS 5.3
CVE-2026-33068
HIGH
Claude Code <2.1.53 Repo Settings - Workspace Trust Bypass
CVSS 8.8
CVE-2026-27707
HIGH
Seerr 2.0.0-3.0.9 - Unauthenticated Account Registration via Jellyfin Authentication Bypass
CVSS 7.3
CVE-2026-21514
HIGH
KEV
Microsoft Office Word - Info Disclosure
CVSS 7.8
CVE-2026-25958
HIGH
Cube.js server-core 0.27.19-1.0.14 - Privilege Escalation via API Token
CVSS 7.7
CVE-2026-25931
HIGH
vscode-spell-checker <4.5.4 - Info Disclosure
CVSS 7.8
Details
Vulnerabilities
76
Exploit Likelihood
High