Skip to main content

Threats Tagged 'cwe-294'

View all threats tagged with 'cwe-294'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-294

Threats Tagged 'cwe-294'

Click on any threat for detailed analysis and mitigation recommendations

Authentication Bypass by Capture-replay in ZenHive mpp allows an attacker holding a captured subscription activation credential to charge the payer repeatedly. The payer signs a Tempo KeyAuthorization over the chain id, key type, key id, expiry, limits and scopes only, with nothing tying it to the challenge that prompted it. MPP.Methods.Tempo.KeyAuthorization.verify/3 in lib/mpp/methods/tempo/key_authorization.ex pins each of those signed fields against the subscription request, and the access key it pins is a static per-endpoint server key, so one signed authorization verifies against every challenge the server issues for the same subscription terms. MPP.Methods.Tempo.Subscription.activate/4 deduplicates activations by challenge id, so presenting the captured credential under a fresh challenge produces a different dedup key, claim_activation succeeds, and the subscription transaction is built and broadcast again. Each replay charges the payer's wallet a new first-period settlement and re-authorizes the server key, bounded only by the subscription expiry and the chain's own semantics for re-installing an existing key. This issue affects mpp: from 0.14.0 before 0.16.2.

Join the discussion

Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. Prior to 1.6.6 and from 1.7.0 until 1.7.3, SAML.getSession in internal/pkg/auth/interceptor/saml.go checks SAMLAssertion.Used and marks it used in separate state operations. Concurrent requests carrying the same captured saml-session token can each observe the assertion as unused and obtain authentication as the victim before either update is visible. The attacker can invoke SAML-protected gRPC endpoints, use ConfirmPublicKey to create multiple persistent credentials tied to the victim, and generate audit entries attributed to the victim, with the resulting access potentially affecting confidentiality, integrity, and availability according to the victim's privileges. This issue is fixed in versions 1.6.6 and 1.7.3.

Join the discussion

CVE-2026-73443 is an authentication bypass vulnerability in Arista Networks EOS affecting VRRPv2 IP-AH authentication. An unauthenticated attacker on the same layer 2 network segment can capture and replay legitimate VRRP advertisements indefinitely. This replay can cause stale VRRP state to be advertised, preventing backup routers from taking over the virtual gateway after the master router fails, resulting in denial of service for hosts relying on the virtual gateway.

Join the discussion

GeoVision GV-LPC2211 V1.13 fails to enforce WS-Security UsernameToken freshness or nonce reuse protection, allowing a captured PasswordDigest token to be replayed for subsequent ONVIF operations.

Join the discussion

CVE-2026-86219 is a critical authentication bypass vulnerability in Authen::SASL::Perl::DIGEST_MD5 versions before 2.2100. The flaw allows an attacker to replay a captured authentication response due to the server not verifying the nonce returned by the client against the originally issued nonce. This enables authentication as a legitimate user without knowing their password.

Join the discussion

Maravel Framework versions prior to 10.74.0 have a high-severity token replay vulnerability due to a lifecycle mismatch between stateless token validation and relational caching layers. This flaw causes blacklisted JWT tokens to be prematurely evicted from cache, allowing them to be reused for up to 14 days. The issue arises from the tymon/jwt-auth package's use of cache tags with a forced 2-hour eviction ceiling, which truncates the intended 14-day blacklist lifespan. Cache flushes or natural evictions invalidate blacklist records, enabling token replay attacks. The vulnerability is architectural and not fixed by a simple framework upgrade; version 10.74.0 introduces a workaround to decouple token identifiers from tagged caches. Users must apply configuration changes to avoid early cache evictions and ensure token blacklists persist for their full lifespan.

Join the discussion

Authentication bypass by capture-replay in Microsoft Authentication Library (MSAL) for Node.js allows an unauthorized attacker to perform spoofing over a network.

Join the discussion

CVE-2026-69676 is an authentication bypass vulnerability in the Windows Kerberos implementation affecting multiple versions of Microsoft Windows 10, including Version 1607. The flaw allows an authorized attacker to execute code remotely over a network by leveraging a capture-replay technique. This vulnerability has a high severity score and has been officially fixed by Microsoft.

Join the discussion
0

When SAML IdP-initiated login is enabled in Grafana Enterprise, the SAML library skips validation of the InResponseTo field on all SAML responses, including SP-initiated logins. This removes anti-replay protection, allowing an attacker who obtains a valid signed SAML assertion to replay it and gain a session as the victim user. Only instances with the allow_idp_initiated SAML setting enabled are affected; this setting is off by default and Grafana OSS is not affected.

Join the discussion

A flaw was found in Rancher Manager. The SAML assertion replay protection introduced by the fix for CVE-2026-44946 recorded consumed assertion IDs in a per-process cache, so each replica only detected replays that reached the same pod. In a high-availability deployment, an attacker holding a captured assertion could replay it once against every other replica to obtain additional authenticated sessions as the victim. This issue affects Rancher: before 2.15.1.

Join the discussion

Showing 1 to 10 of 67 results

Filters:Tag: cwe-294
Page 1 of 7
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses