Threats Tagged 'cwe-305'
View all threats tagged with 'cwe-305'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-305'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2024-1202: CWE-305 Authentication Bypass by Primary Weakness in XPodas OctopodCVE-2024-1202 0 Authentication Bypass by Primary Weakness vulnerability in XPodas Octopod allows Authentication Bypass. This issue affects Octopod: before v1. NOTE: The vendor was contacted and it was learned that the product is not supported. Join the discussion | CVE Database V5 | 03/05/2024, 14:41:40 UTC Added: 06/03/2026, 15:48:58 UTC |
CVE-2026-9047: CWE-305 Authentication bypass by primary weakness in Devolutions ServerCVE-2026-9047 0 Improper handling of factor key state in the multi-factor authentication management feature in Devolutions Server allows an attacker with knowledge of a user's password to bypass the user's multi-factor authentication after the user reconfigures their factors. This issue affects : * Devolutions Server 2026.1.6.0 through 2026.1.16.0 Join the discussion | CVE Database V5 | 05/22/2026, 15:18:39 UTC Added: 05/22/2026, 15:44:48 UTC |
CVE-2024-12802: CWE-305 Authentication Bypass by Primary Weakness in SonicWall SonicOSCVE-2024-12802 0 SSL-VPN MFA Bypass in SonicWALL SSL-VPN can arise in specific cases due to the separate handling of UPN (User Principal Name) and SAM (Security Account Manager) account names when integrated with Microsoft Active Directory, allowing MFA to be configured independently for each login method and potentially enabling attackers to bypass MFA by exploiting the alternative account name. Join the discussion | CVE Database V5 | 01/09/2025, 09:08:26 UTC Added: 05/22/2026, 04:59:51 UTC |
CVE-2026-41054: CWE-305: Authentication Bypass by Primary Weakness in SUSE Container suse/sle-micro-rancher/5.3:latestCVE-2026-41054 0 In `src/havegecmd.c`, the `socket_handler` function performs a credential check on the abstract UNIX socket (`\0/sys/entropy/haveged`). However, while it detects if the connecting user is not root (`cred.uid != 0`) and prepares a negative acknowledgement (`ASCII_NAK`), it **fails to stop execution**. The code proceeds to the `switch` statement, allowing any local unprivileged user to execute privileged commands such as `MAGIC_CHROOT`. Join the discussion | CVE Database V5 | 05/20/2026, 08:56:14 UTC Added: 05/20/2026, 10:03:41 UTC |
CVE-2026-2652: CWE-305 Authentication Bypass by Primary Weakness in mlflow mlflow/mlflowCVE-2026-2652 0 A vulnerability in mlflow/mlflow versions 3.9.0 and earlier allows unauthenticated access to certain FastAPI routes when the server is started with authentication enabled (`--app-name basic-auth`) and served via uvicorn (ASGI). The FastAPI permission middleware only enforces authentication on `/gateway/` routes, leaving other routes such as the Job API (`/ajax-api/3.0/jobs/*`) and the OpenTelemetry trace ingestion API (`/v1/traces`) unprotected. This allows unauthenticated remote attackers to submit jobs, read job results, cancel running jobs, and inject arbitrary trace data into experiments. The issue arises from an architectural mismatch between Flask and FastAPI authentication mechanisms, where the `_find_fastapi_validator()` function fails to handle non-`/gateway/` paths, resulting in a complete authentication bypass. This vulnerability is fixed in version 3.10.0. Join the discussion | CVE Database V5 | 05/15/2026, 02:13:19 UTC Added: 05/15/2026, 03:06:41 UTC |
CVE-2026-4670: CWE-305 Authentication bypass by primary weakness in Progress Software MOVEit AutomationCVE-2026-4670 0 CVE-2026-4670 is a critical authentication bypass vulnerability in Progress Software MOVEit Automation affecting versions from 2024. 0. 0 before 2024. 1. 8 and from 2025. 0. 0 before 2025. 0. 9. This vulnerability allows an attacker to bypass authentication controls, potentially leading to full compromise of confidentiality, integrity, and availability of the affected system. Join the discussion | CVE Database V5 | 04/30/2026, 15:06:11 UTC Added: 04/30/2026, 15:36:27 UTC |
CVE-2024-50478: CWE-305: Authentication Bypass by Primary Weakness in Swoop 1-Click Login: Passwordless AuthenticationCVE-2024-50478 0 Authentication Bypass by Primary Weakness vulnerability in Swoop 1-Click Login: Passwordless Authentication allows Authentication Bypass.This issue affects 1-Click Login: Passwordless Authentication: 1.4.5. Join the discussion | CVE Database V5 | 10/28/2024, 12:32:27 UTC Added: 04/23/2026, 22:34:41 UTC |
CVE-2026-40582: CWE-288: Authentication Bypass Using an Alternate Path or Channel in ChurchCRM CRMCVE-2026-40582 0 ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the /api/public/user/login endpoint validates only the username and password before returning the user's API key, bypassing the normal authentication flow that enforces account lockout and two-factor authentication checks. An attacker with knowledge of a user's password can obtain API access even when the account is locked or has 2FA enabled, granting direct access to all protected API endpoints with that user's privileges. This issue has been fixed in version 7.2.0. Note: this issue had a duplicate, GHSA-472m-p3gf-46xp, which has been closed. Join the discussion | CVE Database V5 | 04/17/2026, 23:16:13 UTC Added: 04/17/2026, 23:23:06 UTC |
CVE-2026-33892: CWE-305: Authentication Bypass by Primary Weakness in Siemens Industrial Edge Management Pro V1CVE-2026-33892 0 A vulnerability has been identified in Industrial Edge Management Pro V1 (All versions >= V1.7.6 < V1.15.17), Industrial Edge Management Pro V2 (All versions >= V2.0.0 < V2.1.1), Industrial Edge Management Virtual (All versions >= V2.2.0 < V2.8.0). Affected management systems do not properly enforce user authentication on remote connections to devices. This could facilitate an unauthenticated remote attacker to circumvent authentication and impersonate a legitimate user. Successful exploitation requires that the attacker has identified the header and port used for remote connections to devices and that the remote connection feature is enabled for the device. Exploitation allows the attacker to tunnel to the device. Security features on this device itself (e.g. app specific authentication) are not affected. Join the discussion | CVE Database V5 | 04/14/2026, 08:40:46 UTC Added: 04/14/2026, 09:01:58 UTC |
CVE-2026-33496: CWE-1289: Improper Validation of Unsafe Equivalence in Input in ory oathkeeperCVE-2026-33496 0 ORY Oathkeeper is an Identity & Access Proxy (IAP) and Access Control Decision API that authorizes HTTP requests based on sets of Access Rules. Versions prior to 26.2.0 are vulnerable to authentication bypass due to cache key confusion. The `oauth2_introspection` authenticator cache does not distinguish tokens that were validated with different introspection URLs. An attacker can therefore legitimately use a token to prime the cache, and subsequently use the same token for rules that use a different introspection server. Ory Oathkeeper has to be configured with multiple `oauth2_introspection` authenticator servers, each accepting different tokens. The authenticators also must be configured to use caching. An attacker has to have a way to gain a valid token for one of the configured introspection servers. Starting in version 26.2.0, Ory Oathkeeper includes the introspection server URL in the cache key, preventing confusion of tokens. Update to the patched version of Ory Oathkeeper. If that is not immediately possible, disable caching for `oauth2_introspection` authenticators. Join the discussion | CVE Database V5 | 03/26/2026, 17:29:41 UTC Added: 03/26/2026, 17:46:00 UTC |
Showing 1 to 10 of 35 results