CWE-1270: Generation of Incorrect Security Tokens
The product implements a Security Token mechanism to differentiate what actions are allowed or disallowed when a transaction originates from an entity. However, the Security Tokens generated in the system are incorrect.
8 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-49499 — Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) a Generation of Incorrect Security Tokens vulnera
- CVE-2026-54593 — Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions
- CVE-2026-19636 — Insuffucient Protections Lead to Brute Force
- CVE-2026-15831 — Generation of Incorrect Security Tokens in GitLab
Recently published
- CVE-2026-19636 — Insuffucient Protections Lead to Brute Force
- CVE-2026-15831 — Generation of Incorrect Security Tokens in GitLab
- CVE-2026-54593 — Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions
- CVE-2026-49499 — Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) a Generation of Incorrect Security Tokens vulnera