CWE-603Base

Use of Client-Side Authentication

Draft in the CWE catalog · 23 CVEs mapped

23
CVEs mapped
8.4
Median CVSS
What it is

A client/server product performs authentication within client code but not in server code, allowing server-side authentication to be bypassed via a modified client that omits the authentication check.

Recent examples
7.5cvss
CVE-2026-76945

CVE-2026-76945 - HIGH Severity Vulnerability

The affected Ebyte device relies on client-managed authentication tokens without sufficient server-side validation. An attacker may replay or manipulate authentication tokens to gain unauthorized access to administrative functionality.

HIGHno explanation yet
0%
epss
9.8cvss
CVE-2026-71187

CVE-2026-71187 - CRITICAL Severity Vulnerability

The Ebyte device relies on client side authentication logic that can be reproduced by unauthenticated users. An attacker may generate valid authentication requests and bypass authentication to obtain administrative access to the device.

CRITICALno explanation yet
1%
epss
8.7cvss
CVE-2026-42098

Authorization Bypass in Sparx Enterprise Architect

Sparx Enterprise Architect software has a security feature that limits user's actions to those specified in the role. An authenticated attacker can modify the Enterprise Architect client behavior (e.g. using a debugger) and log in as any other user or administrator - then it is possible to do every possible change to the repository. The vendor was notified early about this vulnerability, but didn't respond with the details of vulnerability or vulnerable version range. Only version 17.1 and below were tested and confirmed as vulnerable, other versions were not tested and might also be vulnerable.

HIGHno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-603
Abstraction
Base
Structure
Simple
Status
Draft
References (1)