CWE-302: Authentication Bypass by Assumed-Immutable Data
The authentication scheme or implementation uses key data elements that are assumed to be immutable, but can be controlled or modified by the attacker.
42 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2024-56404 — In One Identity Identity Manager 9.x before 9.3, an insecure direct object reference (IDOR) vulnerability allows privile
- CVE-2024-12838 — Changing Information Technology CGFIDO - Authentication Bypass
- CVE-2024-47086 — OTP Bypass Vulnerability
- CVE-2024-22179 — Electrolink FM/DAB/TV Transmitter Authentication Bypass by Assumed-Immutable Data
- CVE-2026-48781 — Postiz has cross-tenant SUPERADMIN takeover via Skool-provider JWT forgery
- CVE-2025-24876 — Authentication bypass via authorization code injection in SAP Approuter
- CVE-2024-4024 — Authentication Bypass by Assumed-Immutable Data in GitLab
- CVE-2025-26522 — Authentication Bypass Vulnerability in RupeeWeb trading platform
- CVE-2026-40285 — WeGIA has SQL Injection via Session Variable Override in DespachoControle.php
- CVE-2026-5423 — Subscription Authentication Bypass via Unverified connectionParams.jwt
- CVE-2026-39429 — kcp's cache server is accessible without authentication or authorization checks
- CVE-2026-13267 — Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access
- CVE-2025-8855 — 2FA Expiry Bypass in Optimus Software's Brokerage Automation
- CVE-2026-48117 — DroneAware's Improper Account Activation in Registration and SSO Flows Leads to Account Takeover
- CVE-2026-28510 — elabftw allows MFA bypass during login
- CVE-2025-43992 — Dell ECS versions 3.8.1.0 through 3.8.1.7 and Dell ObjectScale versions prior to 4.3.0.0, contains an authentication byp
- CVE-2026-34460 — NamelessMC: OAuth callback `state` is not validated, allowing login CSRF / session swapping
- CVE-2025-20285 — Cisco Identity Services Engine IP Filter Access Restriction for Admin Access Configuration Bypass Vulnerability
- CVE-2026-77508 — Weblate: Unverified REST API email changes
- CVE-2025-46647 — Apache APISIX: improper validation of issuer from introspection discovery url in plugin openid-connect
Recently published
- CVE-2026-77508 — Weblate: Unverified REST API email changes
- CVE-2026-13267 — Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access
- CVE-2026-5423 — Subscription Authentication Bypass via Unverified connectionParams.jwt
- CVE-2026-48117 — DroneAware's Improper Account Activation in Registration and SSO Flows Leads to Account Takeover
- CVE-2026-48781 — Postiz has cross-tenant SUPERADMIN takeover via Skool-provider JWT forgery
- CVE-2026-34460 — NamelessMC: OAuth callback `state` is not validated, allowing login CSRF / session swapping
- CVE-2025-43992 — Dell ECS versions 3.8.1.0 through 3.8.1.7 and Dell ObjectScale versions prior to 4.3.0.0, contains an authentication byp
- CVE-2026-28510 — elabftw allows MFA bypass during login
- CVE-2026-40285 — WeGIA has SQL Injection via Session Variable Override in DespachoControle.php
- CVE-2026-39429 — kcp's cache server is accessible without authentication or authorization checks
- CVE-2025-8855 — 2FA Expiry Bypass in Optimus Software's Brokerage Automation
- CVE-2025-20285 — Cisco Identity Services Engine IP Filter Access Restriction for Admin Access Configuration Bypass Vulnerability
- CVE-2025-46647 — Apache APISIX: improper validation of issuer from introspection discovery url in plugin openid-connect
- CVE-2025-26522 — Authentication Bypass Vulnerability in RupeeWeb trading platform
- CVE-2025-24876 — Authentication bypass via authorization code injection in SAP Approuter
- CVE-2024-56404 — In One Identity Identity Manager 9.x before 9.3, an insecure direct object reference (IDOR) vulnerability allows privile
- CVE-2024-12838 — Changing Information Technology CGFIDO - Authentication Bypass
- CVE-2024-43441 — Apache HugeGraph-Server: Fixed JWT Token(Secret)
- CVE-2024-47086 — OTP Bypass Vulnerability
- CVE-2024-4024 — Authentication Bypass by Assumed-Immutable Data in GitLab