CWE-290Base5 in KEV

Authentication Bypass by Spoofing

Incomplete in the CWE catalog · 402 CVEs mapped

402
CVEs mapped
5
In KEV
7.5
Median CVSS
What it is

This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.

Recent examples
none
CVE-2026-86196

CVE-2026-86196 - UNKNOWN Severity Vulnerability

Grav API plugin versions before 1.0.20 build password reset links from the untrusted Host header in the forgot-password endpoint, allowing unauthenticated attackers to redirect reset tokens to attacker-controlled domains. Attackers can send password reset requests for any account with a malicious Host header, intercept the reset token from victim emails, and complete account takeover including super-admin accounts.

no explanation yet
epss
8.2cvss
CVE-2026-85432

CVE-2026-85432 - HIGH Severity Vulnerability

MOOS core-moos through 10.4.0 fails to validate client identity in MOOSDB message processing, allowing authenticated attackers to attribute writes to other clients by supplying arbitrary source identifiers in serialized messages. Attackers can forge message origins and cancel third-party subscriptions by exploiting the disconnect between authenticated connection identity and wire-supplied source attribution.

HIGHno explanation yet
0%
epss
6.5cvss
CVE-2026-84849

CVE-2026-84849 - MEDIUM Severity Vulnerability

Unauthenticated Bypass Vulnerability in Pre-Orders for WooCommerce <= 2.3 versions.

MEDIUMno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-290
Abstraction
Base
Structure
Simple
Status
Incomplete