Skip to main content

Threats Tagged 'cwe-289'

View all threats tagged with 'cwe-289'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-289

Threats Tagged 'cwe-289'

Click on any threat for detailed analysis and mitigation recommendations

Authentication Bypass by Alternate Name vulnerability in Apache Tomcat allowed the security constraints for any WebSocket endpoint to be bypassed. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.25, from 10.1.0-M1 through 10.1.59, from 9.0.0.M1 through 9.0.121. The following versions were EOS at the time the CVE was created but are known to be affected: from 8.5.0 through 8.5.100, from 7.0.43 through 7.0.109. Other unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.26, 10.1.60 or 9.0.122, which fix the issue.

Join the discussion

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy normally matches the raw request path, while servlet backends such as Apache Tomcat strip semicolon matrix parameters from each path segment before resolving the resource. Envoy's ignore_path_parameters_in_path_matching option instead truncates at the first semicolon and still does not match per-segment backend behavior. A remote client can use a parameterized protected segment, or a parameter on an earlier segment, to make Envoy select an unprotected fallback while the backend resolves the protected resource. The relevant scope boundary is that the bypass requires both a path-based Envoy decision and a backend that strips semicolon parameters per segment. This issue is fixed in versions 1.36.10, 1.37.6, 1.38.4, and 1.39.1.

Join the discussion

IBM Verify Identity Access could allow an administrator to execute additional commands they are not entitled to due to improper validation of user supplied requests.

Join the discussion

The MyHome Core WordPress plugin up to version 4.4.5 contains an authentication bypass vulnerability due to missing authorization checks and improper token validation. This flaw allows unauthenticated attackers to generate activation tokens and obtain valid authentication cookies for unconfirmed user accounts, including administrators. Exploitation requires specific configuration settings in the MyHome theme and that the target account lacks a particular user meta flag.

Join the discussion

Winter CMS versions up to 1.2.12 contain an authentication bypass vulnerability in the CMS Theme Editor AJAX handlers. These handlers do not enforce per-template-type permission checks, allowing authenticated backend users with any single CMS permission to perform unauthorized actions on other template types. Additionally, the AssetList widget permits unauthorized file uploads due to missing theme validation. This issue is fixed in version 1.2.13.

Join the discussion

The Classified Listing - Mobile Number Verification plugin for WordPress contains an authentication bypass vulnerability in all versions up to and including 1.6.0. This flaw arises from missing server-side Firebase OTP validation in the process_otp_login() function, allowing unauthenticated attackers to log in as any user by submitting arbitrary OTP codes and user IDs. Exploitation requires OTP login enabled with Firebase as the verification gateway and knowledge or guessing of the target's registered phone number. Administrator accounts with registered phone numbers are also vulnerable to takeover.

Join the discussion

The WooCommerce - Social Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to and including 2.8.7. This is due to the plugin's Apple login handler accepting the Apple id_token and decoding only its base64 payload without verifying the JWT signature against Apple's public keys or validating the issuer, audience, or expiry claims, combined with the security nonce required to invoke the login flow being publicly exposed to unauthenticated users via a localized JavaScript object on the login page. This makes it possible for unauthenticated attackers to log in as any existing WordPress user — including administrators — by supplying a forged id_token whose payload contains the target user's email address, as that email is used without any role exclusion to resolve a WordPress account and immediately issue an authenticated session for it.

Join the discussion

IBM WebSphere Application Server versions 8.5, 9.0, and Liberty versions 17.0.0.3 through 26.0.0.7 have a vulnerability that could allow a remote attacker to bypass security constraints. This issue affects both Traditional and Liberty editions. The vulnerability is classified under CWE-289, indicating improper authentication. No specific patch or remediation information is provided in the available data.

Join the discussion

The Eventer plugin for WordPress is vulnerable to an insecure password reset mechanism in all versions up to, and including, 4.4.2. The plugin stores a plaintext copy of the password reset key in the `eventer_verification_code` user meta field when a user requests a password reset. The plaintext key stored in `wp_usermeta` can be used with the plugin's custom reset action to set a new password for any user. Combined with another vulnerability such as SQL Injection (CVE-2026-9700), this makes it possible for unauthenticated attackers to extract the plaintext reset key and take over any user account, including administrators. Note: The password reset function only works up to PHP version 7.4.

Join the discussion

A flaw in Node.js TLS hostname handling can cause Node.js unicode dot separator handling can lead to tls wildcard-depth authentication bypass due to resolver and verifier hostname normalization mismat. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

Join the discussion

Showing 1 to 10 of 21 results

Filters:Tag: cwe-289
Page 1 of 3
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses