Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

type:auth-bypass — CVE vulnerabilities tagged 2281

2281 CVE security advisories tagged "type:auth-bypass" with AI Chinese analysis, CVSS, references and POCs.

The tag "type:auth-bypass" identifies vulnerabilities where attackers circumvent authentication mechanisms to gain unauthorized access to protected resources. This class of flaws is critical because it undermines the fundamental integrity of access controls, allowing malicious actors to assume legitimate user identities or access administrative functions without valid credentials. Typical scenarios include improper validation of session tokens, logic errors in multi-factor authentication workflows, or the exploitation of weak cryptographic implementations that allow password guessing or token forgery. With 1739 associated CVEs, this widespread issue highlights persistent challenges in secure coding practices. Successful exploitation often leads to data breaches, privilege escalation, and complete system compromise, making the remediation of authentication bypasses a priority for security teams aiming to maintain robust perimeter defenses and protect sensitive organizational data from external threats.

CVE ID Title CVSS Severity Published
CVE-2026-53761 Frappe CRM: Authentication Bypass via Logged Invitation Keys in crm/api — crm CWE-287 8.2 High 2026-09-04
CVE-2026-85152 undici vulnerable to cross-origin cache poisoning via missing origin isolation in interceptors — undici CWE-346 7.4 High 2026-09-04
CVE-2026-85695 FastChat Unauthenticated Worker Registration SSRF and Model Spoofing — FastChat CWE-306 9.4 Critical 2026-09-04
CVE-2026-85671 QAnything 2.0.0 Unauthenticated Cross-User File Disclosure — QAnything CWE-306 7.5 High 2026-09-04
CVE-2026-85597 Traefik before v2.11.55 mTLS Bypass via TLS Option Conflict — traefik CWE-863 8.2 High 2026-09-04
CVE-2026-85596 Traefik v3.7 Authentication Bypass via TLS Option Conflict — traefik CWE-287 8.2 High 2026-09-04
CVE-2026-85595 Traefik before v2.11.55 Authentication Bypass via digestAuth — traefik CWE-287 9.3 Critical 2026-09-04
CVE-2026-85591 phpMyFAQ before 4.1.8 Authentication Bypass via Unverified Password Change — phpMyFAQ CWE-620 7.1 High 2026-09-04
CVE-2026-85590 phpMyFAQ before 4.1.8 Authentication Bypass via Two-Factor Disable — phpMyFAQ CWE-308 7.1 High 2026-09-04
CVE-2026-84428 fastify vulnerable to header validation bypass via incomplete schema case normalization — fastify CWE-178 7.5 High 2026-09-04
CVE-2026-15937 Agent receiver certificate confusion allows authentication with a certificate issued for another endpoint — Checkmk CWE-295 5.3 Medium 2026-09-04
CVE-2026-85147 Lightstar|SmartIT Desktop Manager - Use of Hard-coded Credentials — SmartIT Desktop Manager CWE-284 7.5 High 2026-09-04
CVE-2026-62916 Microsoft Entra ID Elevation of Privilege Vulnerability — Microsoft Entra CWE-288 9.1 Critical 2026-09-03
CVE-2026-85430 MOOS essential-moos through 10.0.1 pShare Unauthenticated UDP Datagram Republishing — essential-moos CWE-345 9.1 Critical 2026-09-03
CVE-2026-85428 MOOS core-moos through 10.4.0 MOOSDB HTTP Server Unauthenticated Variable Write — core-moos CWE-306 9.8 Critical 2026-09-03
CVE-2026-85393 node-forge through 1.4.0 RSA PKCS#1 v1.5 Signature Forgery via Nested DigestAlgorithm Padding — forge CWE-347 7.5 High 2026-09-03
CVE-2026-85237 Missing Rate Limiting in Email OTP Verification Allows Brute-Force Authentication Bypass — misp CWE-307 8.6 High 2026-09-03
CVE-2026-85212 CRMEB through 6.0.0 Missing Authorization via Inert verifyAuth Role Check — CRMEB CWE-862 8.3 High 2026-09-03
CVE-2026-85216 MISP LDAP and LinOTP Authentication Bypass via Empty or Invalid Credentials — misp CWE-521 9.5 Critical 2026-09-03
CVE-2026-84831 Mandatory MFA bypass before enrollment — SEPPmail Secure Email Gateway (SEG) CWE-287 7.7 High 2026-09-03
CVE-2026-14199 Session takeover via Auth Proxy cache key collision — Grafana Enterprise CWE-290 7.1 High 2026-09-02
CVE-2026-84668 Jenkins SAML Plugin 权限许可和访问控制问题漏洞 — Jenkins SAML Plugin - - 2026-09-02
CVE-2026-2688 CM HIPAA Forms < 3.2.0 - Unauthenticated Authorization Bypass — HIPAA FORMS 6.5 Medium 2026-09-02
CVE-2026-17563 WP User Frontend < 4.3.11 - Unauthenticated Post Creation via Subscription-Gated Form — User Frontend 5.3 Medium 2026-09-02
CVE-2026-16647 Disable Login Page - Moderately critical - Access bypass - SA-CONTRIB-2026-111 — Disable Login Page CWE-288 - - 2026-09-02
CVE-2026-81168 CAPTCHA Protected Page - Moderately critical - Cookie Forgery - SA-CONTRIB-2026-105 — CAPTCHA Protected Page CWE-288 - - 2026-09-02
CVE-2026-81205 LDAP / Active Directory Integration - Moderately critical - Information Disclosure - SA-CONTRIB-2026-115 — LDAP / Active Directory Integration CWE-90 - - 2026-09-02
CVE-2026-84483 WWBN AVideo Unauthenticated Password Hash Oracle via encryptPass.json.php — AVideo CWE-321 5.3 Medium 2026-09-01
CVE-2023-54391 Proxmox VE 7.0-8.0 Authentication Bypass via tfa-challenge Parameter — Proxmox Virtual Environment (VE) CWE-304 9.8 Critical 2026-09-01
CVE-2026-73771 Improper Authentication Handling in AOS-CX Management Interface and API — AOS-CX 7.5 High 2026-09-01

Vulnerabilities classified as type:auth-bypass represent 2281 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.