CWE-807: Reliance on Untrusted Inputs in a Security Decision
The product uses a protection mechanism that relies on the existence or values of an input, but the input can be modified by an untrusted actor in a way that bypasses the protection mechanism.
92 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-66570 — cpp-httplib Untrusted HTTP Header Handling: Internal Header Shadowing (REMOTE*/LOCAL*)
- CVE-2025-12488 — oobabooga text-generation-webui trust_remote_code Reliance on Untrusted Inputs Remote Code Execution Vulnerability
- CVE-2025-12487 — oobabooga text-generation-webui trust_remote_code Reliance on Untrusted Inputs Remote Code Execution Vulnerability
- CVE-2026-87479 — Insufficient policy enforcement in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had
- CVE-2025-55736 — flaskBlog allows arbitrary privilege escalation
- CVE-2025-1126 — Lexmark has identified a vulnerability in our Lexmark Print Management Client (LPMC).
- CVE-2024-51561 — Authentication bypass Vulnerability in Aero
- CVE-2025-49827 — Conjur OSS and Secrets Manager, Self-Hosted (formerly Conjur Enterprise) Vulnerable to Bypass of IAM Authenticator
- CVE-2024-29039 — Missing check in tpm2_checkquote allows attackers to misrepresent the TPM state
- CVE-2024-28824 — Privilege escalation in mk_informix plugin
- CVE-2026-6213 — Remote Spark SparkView RCE
- CVE-2024-5754 — BT: Encryption procedure host vulnerability
- CVE-2026-44649 — SillyTavern: Authentication Bypass via SSO Header Injection
- CVE-2024-13974 — A business logic vulnerability in the Up2Date component of Sophos Firewall older than version 21.0 MR1 (20.0.1) can lead
- CVE-2026-82533 — DeepSeek Harness < 0.1.2-alpha.1 Authentication Bypass via Host Header Spoofing
- CVE-2026-25931 — vscode-spell-checker has a workspace-trust bypass Code Execution
- CVE-2026-64827 — Telenia TVox 26.5.3 Authentication Bypass via set_env.php
- CVE-2026-85602 — Grav Form Plugin before 9.1.20 reCAPTCHA v3 Authentication Bypass
- CVE-2025-13926 — Contemporary Controls BASC 20T Reliance on Untrusted Inputs in a Security Decision
- CVE-2026-33068 — Claude Code has a Workspace Trust Dialog Bypass via Repo-Controlled Settings File
Recently published
- CVE-2026-87479 — Insufficient policy enforcement in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had
- CVE-2026-82533 — DeepSeek Harness < 0.1.2-alpha.1 Authentication Bypass via Host Header Spoofing
- CVE-2026-66768 — Improper Access Control in SAP NetWeaver (SAP GUI for Java)
- CVE-2026-85602 — Grav Form Plugin before 9.1.20 reCAPTCHA v3 Authentication Bypass
- CVE-2026-63041 — Apache APISIX: attach-consumer-label does not strip client-supplied consumer-label headers
- CVE-2026-54730 — authentik: Authentication Flow Bypass via Unguarded challenge_valid() in AuthenticatorEndpointGDTCStage and GoogleChromeStageView
- CVE-2026-53789 — rsync < 3.5.0 Arbitrary File Deletion via Malicious File List
- CVE-2026-64934 — Mira Hormone Monitor, Mira Android App Reliance on untrusted inputs in a security decision
- CVE-2026-19579 — Snipe-IT Checkout Request Cancellation IDOR
- CVE-2026-18705 — Improper Authorization in MongoDB Atlas Vector Search Allows Unauthorized Access to Protected View Data
- CVE-2026-58239 — Multiple vulnerabilities in SAP Business AI Platform (Approuter)
- CVE-2026-9077 — Reliance on Untrusted Inputs in a Security Decision vulnerabilities in Model Context Protocol features
- CVE-2026-64827 — Telenia TVox 26.5.3 Authentication Bypass via set_env.php
- CVE-2026-13059 — Improper Validation of Client-Supplied Command Parameters Allowing Role-Based Access Control Bypass
- CVE-2026-16093 — Keycloak-services: keycloak-services: required signed-jwt assertion policy can be bypassed with unsigned assertion headers
- CVE-2026-9561 — Eclipse Kura versions prior to 5.6.2 trust the client-supplied X-Forwarded-For HTTP header as the authoritative source o
- CVE-2026-48980 — pam_usb: getenv() used in PAM context allows environment variable injection into local-check logic
- CVE-2026-53860 — OpenClaw < 2026.5.7 - Sender Policy Bypass via Mutable Conversation Identifiers in BlueBubbles
- CVE-2026-12058 — The connection confirmation pop-up of a specific feature in the PcSuite can be bypassed.
- CVE-2026-44649 — SillyTavern: Authentication Bypass via SSO Header Injection