CWE-290— Authentication Bypass by Spoofing
This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.— MITRE CWE catalog
620 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-290page 13 of 13
- CVE-2026-6090HIGHCVSS 7.0EG 7.02026-06-10
A potential authentication bypass was reported in Lenovo Smart Connect for Windows that could allow a local authenticated user to execute arbitrary code with elevated privileges.
- CVE-2026-61217MEDIUMCVSS 6.4EG 6.42026-07-21
Vulnerability in the Oracle Security Service product of Oracle Fusion Middleware (component: Oracle SSL API). The supported version that is affected is 12.2.1.4.0. Difficult to exploit vulnerability allows low privileged attacker with ne…
- CVE-2026-61428HIGHCVSS 7.3EG 7.32026-07-11
PraisonAI AgentMail versions before 4.6.78 lack signature verification in webhook mode, allowing unauthenticated attackers to inject messages with spoofed sender addresses. Attackers can POST crafted message.received events to the webhook …
- CVE-2026-6213CRITICALCVSS 10.0EG 10.02026-05-08
A vulnerability in Remote Spark SparkView before build 1122 allows an attacker to bypasses the local connection check and achieve arbitrary code execution as root on the server side. Depending on implementation the vulnerability can be…
- CVE-2026-62224MEDIUMCVSS 5.4EG 5.42026-07-17
OpenClaw MS Teams before 2026.5.12 contain an authorization bypass vulnerability where the allowFrom feature binds to mutable display names. Attackers with lower-trust access can perform actions requiring stronger authorization by exploiti…
- CVE-2026-62644CRITICALCVSS 9.8EG 9.82026-07-14
In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the password plugin of the Roundcube Webmail was subject to username spoofing via session data, which could lead to account takeover.
- CVE-2026-63683NONECVSS 0.0EG 0.02026-07-22
Joomla Extension - regularlabs.com - Client IP spoofing vulnerability in Regular Labs conditions manager - IP and GeoIP conditions trusted spoofable forwarded headers, allowing remote clients to bypass location-based rules.
- CVE-2026-64797NONECVSS 0.0EG 0.02026-07-22
Joomla Extension - regularlabs.com - IP spoofing vulnerability in IP login extension - IP Login trusted forwarded client-IP headers without requiring a configured trusted proxy. Attackers could spoof the IP used for automatic login and pot…
- CVE-2026-64875NONECVSS 0.0EG 0.02026-07-23
Joomla Extension - regularlabs.com - IP spoofing vulnerability in GeoIP extension - GeoIP lookups trusted spoofable forwarded client-IP headers, this could cause GeoIP-rule bypass.
- CVE-2026-6762MEDIUMCVSS 6.3EG 6.32026-04-21
Spoofing issue in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
- CVE-2026-7422MEDIUMCVSS 6.5EG 6.52026-04-29
Insufficient packet validation in FreeRTOS-Plus-TCP before V4.2.6 and V4.4.1 allows an adjacent network actor to bypass all checksum and minimum-size validation by spoofing the Ethernet source MAC address to match one of the device's own r…
- CVE-2026-7507HIGHCVSS 7.5EG 7.52026-05-19
A session fixation vulnerability was found in Keycloak's login-actions endpoints. An unauthenticated attacker could exploit this flaw by pre-creating an authentication session and tricking a victim into visiting a maliciously crafted link.…
- CVE-2026-7656MEDIUMCVSS 6.8EG 6.82026-06-29
The IPv6 Neighbor Discovery handlers in subsys/net/ip/ipv6_nbr.c (handle_ra_input, handle_ns_input, handle_na_input) used an incorrect boolean expression that combined the RFC 4861 validity checks with the ICMPv6 code check using the wrong…
- CVE-2026-8644CRITICALCVSS 9.1EG 9.12026-06-01
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to identity spoofing.
- CVE-2026-8651HIGHCVSS 7.5EG 7.52026-07-08
Limited authentication bypass by spoofing vulnerability in Progress MOVEit Transfer (HTTPS module). This issue affects MOVEit Transfer: before 2025.0.7, from 2025.1.0 before 2025.1.3.
- CVE-2026-8676HIGHCVSS 8.8EG 8.82026-05-26
An attacker is able to downgrade the security of a Bluetooth LE connection by deleting an existing bond, spoofing the bonded device and creating a new bond.
- CVE-2026-8951MEDIUMCVSS 6.5EG 6.52026-05-19
Spoofing issue in the Toolbar component in Firefox for Android. This vulnerability was fixed in Firefox 151.
- CVE-2026-8960HIGHCVSS 7.5EG 7.52026-05-19
Spoofing issue in WebExtensions. This vulnerability was fixed in Firefox 151 and Thunderbird 151.
- CVE-2026-8961MEDIUMCVSS 6.5EG 6.52026-05-19
Spoofing issue in the Form Autofill component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.
- CVE-2026-8963HIGHCVSS 7.5EG 7.52026-05-19
Spoofing issue in the Web Speech component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.
Map vulnerabilities like CWE-290 to your infrastructure
EchelonGraph correlates every CVE — across CWE-290 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →