CVE-2026-28185
Unauthenticated Broken Authentication in Log in with Google <= 1.4.2 versions.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.8
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS probability
- 0.20%
- CWE
- CWE-345
- Published
- 2026-08-13
- Last modified
- 2026-08-13
Affected products
- rtCamp Log in with Google
Weakness type
Related vulnerabilities
- CVE-2026-44523 — Note Mark: JWT Secret Weakness allows Full Account Takeover via token forgery
- CVE-2026-48781 — Postiz has cross-tenant SUPERADMIN takeover via Skool-provider JWT forgery
- CVE-2026-80172 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains
- CVE-2026-53513 — Better Auth: Server-side request forgery via unvalidated OIDC endpoints on @better-auth/sso provider registration
- CVE-2026-33471 — nimiq-block has skip block quorum bypass via out-of-range BitSet indices & u16 truncation
- CVE-2026-45058 — electerm: Import unsafe bookmark data could lead to unsafe operation when click local type bookmark
- CVE-2026-44592 — Gradient: Unauthenticated worker on /proto → arbitrary NAR write / cache poisoning
- CVE-2026-19410 — Google Cloud Build Comment Control Bypass via Webhook Suppression