CWE-294: Authentication Bypass by Capture-replay
A capture-replay flaw exists when the design of the product makes it possible for a malicious user to sniff network traffic and bypass authentication by replaying it to the server in question to the same effect as the original message (or with minor changes).
150 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-65905 — Apache Tomcat: Limited replay attack possible with DIGEST authentication
- CVE-2024-38438 — D-Link - CWE-294: Authentication Bypass by Capture-replay
- CVE-2025-6030 — Autoeastern Smart Keyless Entry System Replay Attack
- CVE-2025-6029 — KIA-branded Aftermarket Generic Smart Keyless Entry System Replay Attack
- CVE-2025-36593 — Dell OpenManage Network Integration, versions prior to 3.8, contains an Authentication Bypass by Capture-replay vulnerab
- CVE-2024-43099 — AutomationDirect DirectLogic H2-DM1E Authentication Bypass by Capture-replay
- CVE-2024-12839 — Changing Information Technology CGFIDO - Authentication Bypass
- CVE-2024-38284 — Authentication Bypass by Capture-replay in Motorola Solutions Vigilant Fixed LPR Coms Box (BCAV1F2-C600)
- CVE-2025-54810 — Cognex In-Sight Explorer and In-Sight Camera Firmware Authentication Bypass by Capture-replay
- CVE-2026-2540 — Micca KE700 Acceptance of previously used rolling codes
- CVE-2025-13777 — Authentication Bypass due to Improper Session Validation
- CVE-2026-28787 — OneUptime has WebAuthn 2FA bypass: server accepts client-supplied challenge instead of server-stored value, allowing credential replay
- CVE-2025-35061 — Newforma Info Exchange (NIX) forced NTLMv2 authentication via /NPCSRemoteWeb/LegacyIntegrationServices.asmx
- CVE-2025-35058 — Newforma Info Exchange (NIX) forced NTLMv2 authentication via /UserWeb/Common/MarkupServices.ashx
- CVE-2026-86219 — Authen::SASL::Perl::DIGEST_MD5 versions before 2.2100 for Perl accept replayed authentication responses via unverified nonce in server_step
- CVE-2026-68079 — Apache CXF: DefaultEncryptingCodeDataProvider allows unlimited authorization code replay
- CVE-2026-28564 — Apache IoTDB: REST Basic Authentication Accepts Stale Cached Credentials
- CVE-2025-46815 — ZITADEL Allows IdP Intent Token Reuse
- CVE-2026-44946 — SAML Authentication Replay in Rancher
- CVE-2026-32987 — OpenClaw < 2026.3.13 - Bootstrap Setup Code Replay via Device Pairing
Recently published
- CVE-2026-55250 — Maravel-Framework Token Replay Vulnerability via Premature JWT Blacklist Eviction in Tagged Caches
- CVE-2026-73312 — XenForo < 2.3.13 Refresh Token Replay via Expired Access Token
- CVE-2026-73311 — XenForo < 2.3.13 OAuth2 Authorization Code Reuse
- CVE-2022-51016 — PocketMine-MP 3.x before 3.27.0 Authentication Bypass via Login Replay
- CVE-2026-86219 — Authen::SASL::Perl::DIGEST_MD5 versions before 2.2100 for Perl accept replayed authentication responses via unverified nonce in server_step
- CVE-2026-75034 — Rancher: SAML Assertion Replay
- CVE-2026-53636 — Open edX LTI OAuth Replay Attack
- CVE-2026-12704 — SAML assertion replay via skipped InResponseTo validation
- CVE-2026-84306 — Filament: Multi-factor authentication (app) codes can still be used after a newer code has been used
- CVE-2026-82470 — Rodauth before 2.47.0 TOTP Code Reuse via Drift Window
- CVE-2026-13734 — Zephyr WireGuard mutates peer state before anti-replay check, enabling capture-replay endpoint hijack
- CVE-2026-82220 — WordPress Forminator plugin <= 1.57.1 - Other vulnerability Type vulnerability
- CVE-2026-46369 — Nimiq: Validity store off by one error
- CVE-2026-41707 — Spring Security DPoPProofJwtDecoderFactory vulnerable to DPoP Proof Replay
- CVE-2026-65905 — Apache Tomcat: Limited replay attack possible with DIGEST authentication
- CVE-2026-53424 — Missing one-time-use enforcement in Samly allows replay of SAML bearer assertions
- CVE-2026-55088 — Etherpad: Device-to-device author-token transfer endpoint is replayable, never expires, and exposes the cleartext author token
- CVE-2026-67581 — On-chain transfer proof is not single-use in mpp EVM payment method, enabling cross-challenge replay
- CVE-2026-73136 — Static memo configuration in mpp Tempo disables per-challenge attribution binding, enabling third-party replay
- CVE-2026-76214 — phpMyFAQ before 4.1.7 WebAuthn Replay Attack via Challenge