CWE-290: Authentication Bypass by Spoofing
This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.
393 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2024-4358 — Registration Authentication Bypass Vulnerability
- CVE-2024-12108 — WhatsUp Gold - Public API signing key rotation issue
- CVE-2025-9265 — API Authentication Bypass via Header Spoofing vulnerability in Kiloview NDI N30 Products
- CVE-2025-66570 — cpp-httplib Untrusted HTTP Header Handling: Internal Header Shadowing (REMOTE*/LOCAL*)
- CVE-2025-34063 — OneLogin AD Connector JWT Authentication Bypass via Exposed Signing Key
- CVE-2025-8853 — 2100 Technology|Official Document Management System - Authentication Bypass
- CVE-2025-69258 — A LoadLibraryEX vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to load an atta
- CVE-2025-36594 — Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3.
- CVE-2024-13061 — 2100 Technology Electronic Official Document Management System - Authentication Bypass
- CVE-2026-25938 — FUXA Unauthenticated Remote Code Execution in Node-RED Integration
- CVE-2025-25182 — Stroom Authentication/Authorization Bypass when using AWS ALB
- CVE-2024-23832 — Mastodon Remote user impersonation and takeover
- CVE-2025-61778 — Akka.Remote TLS did not properly implement certificate-based authentication
- CVE-2025-36754 — Authentication bypass on web interface
- CVE-2025-13953 — Bypass in the authentication method of the GTT Sistema de Información Tributario application
- CVE-2025-12414 — Looker account compromise via punycode homograph attack
- CVE-2026-27478 — Unity Catalog has a JWT Issuer Validation Bypass Allows Complete User Impersonation
- CVE-2025-54576 — OAuth2-Proxy has authentication bypass in oauth2-proxy skip_auth_routes due to Query Parameter inclusion
- CVE-2025-11250 — Authentication Bypass
- CVE-2024-37082 — When deploying Cloud Foundry together with the haproxy-boshrelease and using a non default configuration, it might be po
Recently published
- CVE-2026-82563 — Softish C6 Ear Camera and EarVision Android Application Authentication bypass by spoofing
- CVE-2026-82530 — IP2Location Country Blocker < 2.45.0 Access Control Bypass via X-Real-IP Header
- CVE-2026-86478 — In JetBrains YouTrack before 2025.3.161254, 2026.1.14042 improper authentication in YouTrack Helpdesk allowed unauthent
- CVE-2026-84186 — Incorrect access control in PrestaShop
- CVE-2026-86196 — Grav API Plugin before 1.0.20 Authentication Bypass via Host Header
- CVE-2026-85432 — MOOS core-moos through 10.4.0 MOOSDB Message Source Spoofing via Wire Identity
- CVE-2026-84766 — WordPress FluentBooking Pro plugin <= 2.2.1 - Bypass Vulnerability vulnerability
- CVE-2026-84849 — WordPress Pre-Orders for WooCommerce plugin <= 2.3 - Bypass Vulnerability vulnerability
- CVE-2026-82180 — In Eclipse Arrowhead versions from 5.0.0 to 5.2.1 when the MQTT API is enabled with the certificate authentication polic
- CVE-2026-19117 — Delinea Secret Server FIDO2 credential registration authentication bypass vulnerability
- CVE-2026-14199 — Session takeover via Auth Proxy cache key collision
- CVE-2026-84479 — WWBN AVideo Authentication Bypass via User-Agent Header
- CVE-2026-84476 — WWBN AVideo Authentication Bypass via X-Real-IP Header
- CVE-2026-58575 — Dell PowerStore contains an Authentication Bypass by Spoofing vulnerability. An authenticated attacker could potentially
- CVE-2026-82228 — WordPress SiteGround Security plugin <= 1.6.6 - 2FA Bypass vulnerability
- CVE-2026-13735 — WireGuard keepalive transport-data messages accepted without Poly1305 authentication
- CVE-2026-55584 — phpSysInfo: IP allowlist (PSI_ALLOWED) bypass via spoofed X-Forwarded-For / Client-IP headers
- CVE-2026-81777 — WordPress Essential Addons for Elementor plugin <= 6.8.0 - Bypass vulnerability vulnerability
- CVE-2026-80349 — TarsWeb through 3.0.14 Authentication Bypass via Spoofed X-Forwarded-For and uid Parameter
- CVE-2026-19538 — Bypass of BLOCKED ACL items on proxy protocol port over TCP or TLS