Threats Tagged 'cwe-305'
View all threats tagged with 'cwe-305'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-305'
Click on any threat for detailed analysis and mitigation recommendations
0 Authentication Bypass by Primary Weakness vulnerability in team-alembic AshAuthentication allows an unconfirmed user to obtain a session, defeating a mandatory email confirmation requirement. AshAuthentication.Strategy.Password.Actions.check_user/2 decides whether the attribute named by require_confirmed_with is set using a bare is_nil(Map.get(user, value)). When that attribute is not selected on the loaded record Map.get/2 returns %Ash.NotLoaded{}, and when a field policy denies it for the current actor it returns %Ash.ForbiddenField{}. Neither is nil, so the rejection branch is skipped and sign-i require_confirmed_with is enforced in two places, and neither holds in every configuration. sign_in_with_token and register are checked only inside AshAuthentication.Strategy.Password.Actions, not on the action itself, so any caller that invokes the action directly skips the check. An API layer such as AshGraphql or AshJsonApi invokes the action directly, so this applies to the default configuration. Where a check does run it compares the confirmation attribute against nil. That attribute holds %Ash.NotLoaded{} or %Ash.ForbiddenField{} when it sets select_by_default?: false, when an API layer narrows the read's select, or when a field policy hides it from the sign-in actor. Neither struct is nil, so those configurations read every user as confirmed. This issue affects ash_authentication: from 4.3.8 before 4.15.0 and from 5.0.0-rc.0 before 5.0.0-rc.14. Join the discussion | CVE Database V5 | 09/17/2026, 13:09:43 UTC Added: 09/17/2026, 13:17:28 UTC |
0 In late August 2026, a sophisticated device code phishing campaign was identified, distributed through web contact forms. Threat actors impersonated procurement officers from legitimate businesses, specifically BJ's Wholesale Club, using lookalike domains registered with Zoho Mail. The campaign, tracked as GhostCode, abused Microsoft's OAuth 2.0 device authorization grant flow to obtain authentication tokens. Victims received WeTransfer links to password-protected HTML files containing three layers of obfuscation: junk padding, character-level HTML comment injection, and AES-256-GCM encrypted redirect URLs. After passing multiple security checks including Cloudflare Turnstile, victims were directed to legitimate Microsoft sign-in pages where they unwittingly authorized attacker-controlled devices. Within 78 seconds of successful authentication, threat actors registered three devices, obtained Primary Refresh Tokens, and harvested emails using residential proxy rotation to evade detection. Join the discussion | CVE Database V5 | 09/16/2026, 12:51:13 UTC Added: 08/28/2026, 15:38:05 UTC |
0 An authentication bypass in N-central < 2026.3 HF 3 leads to authentication bypass in internal only APIs Join the discussion | GCVE Database | 09/05/2026, 19:12:06 UTC Added: 09/06/2026, 14:18:32 UTC |
0 CVE-2026-86207 is a high-severity authentication bypass vulnerability in N-able N-central versions prior to 2026.3.1.13. The flaw allows bypassing authentication in internal-only APIs due to a primary weakness classified as CWE-305. This vulnerability could enable unauthorized access to internal API functions. Join the discussion | CVE Database V5 | 09/05/2026, 19:12:06 UTC Added: 09/05/2026, 19:22:43 UTC |
0 An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions prior to the completion of access validation checks. This allows an unauthenticated remote attacker to modify certain system configurations. Join the discussion | GCVE Database | 08/28/2026, 11:39:45 UTC Added: 08/31/2026, 17:51:03 UTC |
0 CVE-2026-16895 is a logic vulnerability in the Rapid7 Metasploit Framework's JSON-RPC web service interface. It arises when an exception during the database health check causes the internal authentication state to reset improperly if a specific environment variable is not set. This leads to an authentication bypass, granting unauthenticated local access to the JSON-RPC request dispatcher. Join the discussion | GCVE Database | 08/27/2026, 03:14:21 UTC Added: 08/27/2026, 15:12:57 UTC |
0 CVE-2026-16895 is a logic vulnerability in the Rapid7 Metasploit Framework's JSON-RPC web service interface. The flaw arises when an exception during a database health check causes the internal authentication state to reset improperly, allowing unauthenticated local access. This occurs if the environment variable MSF_WS_JSON_RPC_API_TOKEN is not set, leading the authentication mechanism to mistakenly allow access without credentials. The vulnerability affects versions prior to 6.5.2 and has a medium severity rating. Join the discussion | CVE Database V5 | 08/27/2026, 03:14:21 UTC Added: 08/27/2026, 04:07:53 UTC |
Punk::Plugin::TOTP versions before 0.05 for Perl contain an authentication bypass vulnerability in the two-factor authentication process. The vulnerability arises because the recovery code verification compares user identifiers numerically, causing identifiers without leading digits to coerce to zero and bypass ownership checks. This allows an attacker who knows a victim's password and has their own recovery code to bypass the victim's second factor and authenticate as the victim. Join the discussion | CVE Database V5 | 08/25/2026, 21:21:08 UTC Added: 08/25/2026, 21:37:38 UTC |
0 An improper authentication vulnerability exists in Apache Hive versions 4.0.0 through 4.2.0 when using HiveServer2 with SAML authentication over HTTP transport. This flaw allows an unauthenticated attacker with network access to the HiveServer2 HTTP port to impersonate any Hive user by sending a forged Authorization: Bearer token to the /cliservice endpoint. No Hive credentials, SAML IdP login, or server signing secret knowledge is required. The vulnerability does not affect deployments where Apache Knox handles SSO and HiveServer2 uses LDAP or Kerberos authentication. Join the discussion | CVE Database V5 | 08/25/2026, 10:12:53 UTC Added: 08/25/2026, 10:22:41 UTC |
CVE-2026-19349 is a critical authentication bypass vulnerability in Lemonldap::NG::Portal affecting certain versions that use the GitHub and LinkedIn OAuth2 backends. The flaw allows an unauthenticated visitor to replay a session identifier used as an OAuth2 state parameter to gain a valid SSO session without proper authentication. This occurs because the state parameter is stored as a regular SSO session lacking user and authentication level attributes, which some default configurations accept. Only deployments with the GitHub or LinkedIn authentication modules enabled are affected. Join the discussion | CVE Database V5 | 08/16/2026, 13:22:34 UTC Added: 08/16/2026, 13:41:46 UTC |
Showing 1 to 10 of 58 results