Threats Tagged 'cwe-347'
View all threats tagged with 'cwe-347'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-347'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-58262: CWE-345: Insufficient Verification of Data Authenticity in klever-io klever-goCVE-2026-58262 0 Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, header signature verification counts the unused padding bits of the PubKeysBitmap toward the two-thirds validator quorum. These padding bits do not correspond to any validator and are ignored by the actual BLS aggregate-signature check, so a malicious or compromised block producer can set them to reach the required quorum while gathering fewer genuine validator signatures than the protocol demands. As a result, nodes that import or intercept the header accept it as correctly signed without a real two-thirds quorum, weakening consensus safety and undermining finality. This issue is fixed in version 1.7.20. Join the discussion | CVE Database V5 | 08/07/2026, 22:00:57 UTC Added: 08/07/2026, 22:12:01 UTC |
CVE-2026-62873: CWE-347: Improper Verification of Cryptographic Signature in Microsoft Microsoft 365 Admin CenterCVE-2026-62873 0 Improper verification of cryptographic signature in Microsoft 365 Admin Center allows an unauthorized attacker to elevate privileges over a network. Join the discussion | GCVE Database | 08/06/2026, 22:37:47 UTC Added: 08/07/2026, 05:56:42 UTC |
CVE-2026-62918: CWE-347: Improper Verification of Cryptographic Signature in Microsoft Microsoft TeamsCVE-2026-62918 0 Improper verification of cryptographic signature in Microsoft Teams allows an unauthorized attacker to perform spoofing over a network. Join the discussion | GCVE Database | 08/06/2026, 22:37:40 UTC Added: 08/07/2026, 05:56:42 UTC |
CVE-2026-62918: CWE-347: Improper Verification of Cryptographic Signature in Microsoft Microsoft TeamsCVE-2026-62918 0 Improper verification of cryptographic signature in Microsoft Teams allows an unauthorized attacker to perform spoofing over a network. Join the discussion | CVE Database V5 | 08/06/2026, 22:37:40 UTC Added: 08/07/2026, 00:27:03 UTC |
CVE-2026-62873: CWE-347: Improper Verification of Cryptographic Signature in Microsoft Microsoft 365 Admin CenterCVE-2026-62873 0 Improper verification of cryptographic signature in Microsoft 365 Admin Center allows an unauthorized attacker to elevate privileges over a network. Join the discussion | CVE Database V5 | 08/06/2026, 22:37:47 UTC Added: 08/07/2026, 00:27:03 UTC |
CVE-2026-5430: CWE-347: Improper Validation of Certificate With Host Mismatch in WSO2 WSO2 Universal GatewayCVE-2026-5430 0 The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows an attacker to craft a JWT with an unsupported algorithm, which is then incorrectly validated, leading to unauthorized access. Successful exploitation of this vulnerability may result in unauthorized access to the system, including the potential compromise of administrative accounts and full account takeover. The CVSS score is adjusted to 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) in single-tenant deployments, reflecting that the impact is contained within a single security authority boundary. Join the discussion | CVE Database V5 | 08/06/2026, 07:33:28 UTC Added: 08/06/2026, 08:11:48 UTC |
CVE-2026-7557: CWE-347: Improper Verification of Cryptographic Signature in Progress Software Corporation MarkLogic ServerCVE-2026-7557 0 An improper verification of cryptographic signature vulnerability in the SAML authentication module of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass authentication and impersonate any user, including administrators. This vulnerability affects deployments with SAML single sign-on enabled. Join the discussion | CVE Database V5 | 08/05/2026, 15:33:05 UTC Added: 08/05/2026, 16:11:52 UTC |
CVE-2026-46713: CWE-347: Improper Verification of Cryptographic Signature in misskey-dev misskeyCVE-2026-46713 0 Misskey is an open source, federated social media platform. Versions 12.37.0 and later, but prior to 2026.5.4, contain a vulnerability in the JSON-LD signature validation and compaction process that allows spoofed activities to be accepted as valid. This issue has been fixed in version 2026.5.4. Join the discussion | CVE Database V5 | 08/03/2026, 21:37:45 UTC Added: 08/03/2026, 22:03:40 UTC |
In Bouncy Castle for Java before 1.85, RSA PKCS#1 verification skips last two hash bytes in NULL-omitted path. (CVE-2026-12860)CVE-2026-12860 0 Bouncy Castle for Java versions before 1.85 and LTS versions before 2.73.12 contain a vulnerability in RSA PKCS#1 signature verification. The verification process incorrectly skips the last two hash bytes when the NULL byte is omitted in the signature. This flaw can lead to incorrect signature validation. Join the discussion | GCVE Database | 08/03/2026, 06:31:44 UTC Added: 08/03/2026, 21:22:08 UTC |
CVE-2026-18568: CWE-347 Improper Verification of Cryptographic Signature in TIMLEGGE XML::SigCVE-2026-18568 0 XML::Sig versions from 0.29 before 0.72 for Perl allow signature verification bypass because verify returns true when every signature was skipped before any cryptographic check. verify in lib/XML/Sig.pm counts the `//dsig:Signature` elements into `$numsigs` and iterates over them, but two paths reach `next` before any digest or key check runs: a `SignedInfo/Reference/@URI` that resolves to no element while `$numsigs` is greater than 1, and, when `id_attr` is set, a reference that does not match the requested ID. The loop records nothing about what it checked, so when every signature takes one of those paths control reaches the unconditional `return 1` that ends verify. Two `Signature` elements whose Reference URI names an ID that no element carries is enough, as is one such element combined with `id_attr`. Any caller that passes untrusted XML to verify can receive a true return for a document in which no digest and no signature value was checked; a `cert` or `cert_text` trust anchor does not change this, because no key check runs. Versions up to 0.28 use an XML::XPath based verify that has no such skip and are not affected. Join the discussion | CVE Database V5 | 08/03/2026, 14:38:52 UTC Added: 08/03/2026, 15:33:56 UTC |
Showing 1 to 10 of 36 results