Threats Tagged 'cwe-288'
View all threats tagged with 'cwe-288'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-288'
Click on any threat for detailed analysis and mitigation recommendations
Authentication Bypass Using an Alternate Path or Channel vulnerability in Magepeople inc. Taxi Booking Manager for WooCommerce allows Authentication Bypass. This issue affects Taxi Booking Manager for WooCommerce: from n/a before 2.0.8. Join the discussion | CVE Database V5 | 09/22/2026, 08:42:37 UTC Added: 09/22/2026, 08:48:27 UTC |
0 Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing. Prior to version 2.4.0, `POST /api/auth/token` authenticates with username and password only, then calls `getTokens()`, which returns full access and refresh JWTs without checking whether the account has TOTP 2FA enabled. An attacker with stolen or phished credentials can bypass 2FA in a single request. The parallel login endpoint (`POST /api/auth/login`) correctly enforces 2FA by calling `setCookies(user, res, true)`, which gates on `user.twoFaEnabled`. Version 2.4.0 patches the issue. Join the discussion | CVE Database V5 | 09/21/2026, 20:01:56 UTC Added: 09/21/2026, 20:17:15 UTC |
0 Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. Prior to 4.3.0, Steeltoe.Security.Authorization.Certificate deployments using AddOrgAndSpacePolicies() and UseCertificateAuthorization() trust the public certificate supplied in the X-Client-Cert request header without proving possession of the corresponding private key. Common Cloud Foundry routers do not remove this header from inbound requests. When inbound requests are not restricted to a known trusted proxy source IP, an attacker who obtains the public certificate of an application instance in the target organization or space and can reach the application can spoof X-Client-Cert to bypass the SameOrg and SameSpace policies for the certificate validity period. This issue is fixed in version 4.3.0. Join the discussion | CVE Database V5 | 09/17/2026, 15:36:23 UTC Added: 09/17/2026, 15:47:13 UTC |
CVE Database V5 | 09/17/2026, 13:24:36 UTC Added: 09/17/2026, 13:32:20 UTC | |
0 A SAML authentication bypass vulnerability affects the Kong SAML plugin when the validate_assertion_signature option is explicitly set to false. This option is enabled by default. When disabled, the plugin may extract the SAML identity from an unsigned assertion and authenticate the user without verifying a valid cryptographic signature. As a result, an unauthenticated remote attacker may be able to submit a crafted SAML response and impersonate arbitrary users, including administrators Join the discussion | CVE Database V5 | 09/16/2026, 10:06:07 UTC Added: 09/16/2026, 10:17:48 UTC |
0 An unauthenticated remote attacker can exploit an authentication bypass in the _account_log function to log in as an admin, even when accounts are properly configured. Join the discussion | CVE Database V5 | 09/16/2026, 07:48:15 UTC Added: 09/16/2026, 08:02:20 UTC |
PraisonAI is a multi-agent teams system. From 1.5.1 until 1.7.2, MCPSecurity.evaluatePolicy() in src/praisonai-ts/src/mcp/security.ts invokes the configured credential validator only when AuthMethod is api-key or bearer. Basic and OAuth policies accept any non-empty Authorization header without calling auth.validate(), then return an authenticated result, allowing callers with invalid credentials to access MCP tools and resources protected by those policies. This issue is fixed in version 1.7.2. Join the discussion | CVE Database V5 | 09/15/2026, 10:23:11 UTC Added: 09/15/2026, 10:47:05 UTC |
0 Authentication bypass using an alternate path or channel and Improper validation of syntactic correctness of input vulnerability in Brainzcompany Zenius EMS 8.0 allows Remote Code Inclusion. This issue affects Zenius EMS 8.0: through OAM (Build 109). Join the discussion | CVE Database V5 | 09/11/2026, 02:29:52 UTC Added: 09/11/2026, 02:32:47 UTC |
0 Unauthenticated Broken Authentication in IMPress for IDX Broker <= 3.3.0 versions. Join the discussion | CVE Database V5 | 09/10/2026, 14:23:42 UTC Added: 09/10/2026, 14:38:04 UTC |
0 Subscriber Broken Authentication in MailMunch – Grow your Email List <= 3.2.5 versions. Join the discussion | CVE Database V5 | 09/10/2026, 14:23:39 UTC Added: 09/10/2026, 14:38:04 UTC |
Showing 1 to 10 of 294 results