CWE-807

High likelihood

Reliance on Untrusted Inputs in a Security Decision

Parent: CWE-693 - Protection Mechanism Failure

The product uses a protection mechanism that relies on the existence or values of an input, but the input can be modified by an untrusted actor in a way that bypasses the protection mechanism.

85 vulnerabilities with CWE-807
CVE-2026-13059 HIGH
Improper Validation of Client-Supplied Command Parameters Allowing Role-Based Access Control Bypass
CVSS 8.1
CVE-2026-16093 MEDIUM
Red Hat Keycloak Client Policies - Signed JWT Assertion Bypass
CVSS 5.4
CVE-2026-9561 HIGH
Eclipse Kura < 5.6.1 - Insufficient Verification of Data Authenticity
CVE-2026-48491 CRITICAL
Traefik: SNICheck ignores wildcard TLSOptions mappings, allowing domain-fronted mTLS bypass
CVSS 10.0
CVE-2026-48980 MEDIUM
pam_usb: getenv() used in PAM context allows environment variable injection into local-check logic
CVSS 6.3
CVE-2026-53860 MEDIUM
OpenClaw < 2026.5.7 - Sender Policy Bypass via Mutable Conversation Identifiers in BlueBubbles
CVSS 4.2
CVE-2026-12058 MEDIUM
Vivo PcSuite - Reliance on Untrusted Inputs in a Security Decision
CVE-2026-44649 CRITICAL
SillyTavern: Authentication Bypass via SSO Header Injection
CVSS 9.8
CVE-2026-43935 HIGH
e107: Host Header Injection in e107 password reset enables phishing
CVSS 8.1
CVE-2026-6213 CRITICAL
Remote Spark SparkView RCE
CVE-2026-24120 CRITICAL
vm2: Sandbox Breakout Through Promise Species
CVSS 9.8
CVE-2026-39807 MEDIUM
Client-supplied URI scheme trusted without transport verification in bandit
CVE-2026-41403 LOW
OpenClaw < 2026.3.31 - Access Control Bypass via Proxied Remote Request Misclassification
CVSS 2.9
CVE-2026-41390 HIGH
OpenClaw < 2026.3.28 - Exec Allowlist Bypass via Unregistered /usr/bin/script Wrapper
CVSS 7.3
CVE-2026-41380 HIGH
OpenClaw < 2026.3.28 - Arbitrary Execution Allowlist via Wrapper Carrier Executables
CVSS 7.3
CVE-2026-1789 MEDIUM
Canon imagePRESS Series - Info Disclosure
CVSS 4.9
CVE-2026-41299 HIGH
OpenClaw < 2026.3.28 - Client Identity Spoofing in chat.send Gateway Provenance Guard
CVSS 7.1
CVE-2026-0390 MEDIUM
UEFI Secure Boot Security Feature Bypass Vulnerability
CVSS 6.7
CVE-2026-35670 MEDIUM
OpenClaw < 2026.3.22 - Webhook Reply Rebinding via Username Resolution in Synology Chat
CVSS 5.9
CVE-2026-35655 MEDIUM
OpenClaw < 2026.3.22 - Identity Spoofing via rawInput Tool in ACP Permission Resolution
CVSS 5.7
CVE-2026-35624 MEDIUM
OpenClaw < 2026.3.22 - Policy Confusion via Room Name Collision in Nextcloud Talk
CVSS 4.2
CVE-2026-35617 MEDIUM
OpenClaw < 2026.3.25 - Authorization Bypass via Group Policy Rebinding with Mutable Space displayName
CVSS 4.2
CVE-2026-34486 HIGH
Apache Tomcat: Fix for CVE-2026-29146 allowed bypass of EncryptInterceptor
CVSS 7.5
CVE-2026-29134 HIGH
SEPPmail Secure Email Gateway - GINA Domain Switch
CVSS 7.5
CVE-2026-32975 CRITICAL
OpenClaw < 2026.3.12 - Weak Authorization via Mutable Group Names in Zalouser Allowlist
CVSS 9.8
Details
Vulnerabilities 85
Exploit Likelihood High