Vulnerabilities (CVE)

Filtered by CWE-1390
Total 95 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-77483 1 Microsoft 4 Sql Server 2017, Sql Server 2019, Sql Server 2022 and 1 more 2026-09-15 N/A 8.8 HIGH
Weak authentication in SQL Server allows an authorized attacker to elevate privileges over a network.
CVE-2026-80219 2026-09-11 N/A 8.7 HIGH
A flaw was found in hawtio-operator. When deploying Hawtio in cluster mode, the operator creates a cluster-scoped OAuthClient with automatic grant approval (GrantMethod: auto) and no client secret (public client). The redirect URIs are derived from the operator-created Route, whose hostname is tenant-controlled via the Hawtio CR spec.routeHostName field. A malicious tenant can register an arbitrary hostname as a valid OAuth redirect target and, because grants are auto-approved, obtain OpenShift access tokens of any cluster user who visits the crafted authorization URL without any consent prompt.
CVE-2026-62895 2026-09-10 N/A 8.8 HIGH
Permissive cross-domain policy with untrusted domains in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-44476 2026-09-09 N/A N/A
Doorkeeper is an OAuth 2 provider for Ruby on Rails. In version 1.9.0, an attacker who knows only a dynamically registered client's client_id, which is public information, can authenticate as that client at the token endpoint and obtain an access token without providing its client_secret. This occurs because the Dynamic Client Registration feature creates applications with confidential: false hard-coded, even though the registration response returns a client_secret and advertises support for the client_secret_basic and client_secret_post authentication methods; since Doorkeeper treats a blank or missing secret as valid for non-confidential (public) clients, the secret is never verified. Only projects that have explicitly enabled Dynamic Client Registration, which is disabled by default, are affected. This issue is fixed in version 1.10.0.
CVE-2026-73025 2026-09-09 N/A 9.8 CRITICAL
Weak authentication in Windows iSCSI allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-68067 2026-09-01 N/A 9.8 CRITICAL
The login endpoint on the Mira cloud API accepts any format-valid string in the password field and returns a live active session token for the account matching the supplied email address. An attacker could use an email address to control cloud accounts and access hormone record information and account settings.
CVE-2026-65098 2 Linux, Nvidia 2 Linux Kernel, Nemoclaw 2026-09-01 N/A 8.1 HIGH
NVIDIA NemoClaw for Linux contains a vulnerability in its remote-access helper workflow, where an attacker could cause weak authentication. A successful exploit of this vulnerability might lead to code execution, information disclosure, and data tampering.
CVE-2026-73819 2026-09-01 N/A 9.8 CRITICAL
The affected Ebyte product's vendor configuration utility permits access to administrative functions without verifying the operator's identity under certain credential conditions. An unauthenticated attacker on the adjacent network could modify critical settings or change access credentials, potentially preventing legitimate administrators from managing the device.
CVE-2026-55040 1 Microsoft 1 Sharepoint Server 2026-08-19 N/A 9.1 CRITICAL
Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-59135 1 Microsoft 13 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 10 more 2026-08-16 N/A 5.5 MEDIUM
Weak authentication in Microsoft Windows Search Component allows an authorized attacker to disclose information locally.
CVE-2026-40417 1 Microsoft 1 Dynamics 365 Business Central 2026-08-10 N/A 7.8 HIGH
Weak authentication in Dynamics Business Central allows an authorized attacker to elevate privileges locally.
CVE-2024-38239 1 Microsoft 15 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 12 more 2026-08-10 N/A 7.2 HIGH
Windows Kerberos Elevation of Privilege Vulnerability
CVE-2026-59554 2026-07-23 N/A 7.5 HIGH
Unauthenticated Broken Authentication in Ziina <= 1.2.21 versions.
CVE-2026-0274 1 Paloaltonetworks 2 Cortex Xsiam Commvaultsecurityiq Marketplace, Cortex Xsoar Commvaultsecurityiq Marketplace 2026-07-23 N/A 9.1 CRITICAL
An improper validation of credentials vulnerability in the CommvaultSecurityIQ integration for Cortex XSOAR and Cortex XSIAM allows an unauthenticated attacker to access and modify protected resources.
CVE-2026-6274 2026-07-23 N/A 9.8 CRITICAL
Improper Authentication, Missing authentication for critical function, Weak Authentication vulnerability in DTS Electronics Industry and Trade Ltd. Co. Redline WR3200 allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Redline WR3200: from 7.1.3 before 7.1.8.
CVE-2026-50756 2026-07-22 N/A 7.5 HIGH
An issue in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to obtain sensitive information via the x-ai-provider component
CVE-2024-35248 1 Microsoft 1 Dynamics 365 Business Central 2026-07-21 N/A 7.3 HIGH
Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability
CVE-2026-44237 1 Sangoma 1 Freepbx 2026-07-21 N/A 8.1 HIGH
FreePBX is an open source IP PBX. Prior to 17.0.8, the FreePBX api module's OAuth2 implementation does not sufficiently validate client credentials during token issuance. Knowledge of a valid client_id is required. The validateClient() method in ClientRepository.php unconditionally returns true, allowing any party with knowledge of a valid client_id to obtain OAuth2 access tokens without providing the correct client_secret. This vulnerability is fixed in 17.0.8.
CVE-2026-49323 2026-07-21 N/A 4.3 MEDIUM
Weak authentication between the Wireless Control Module (WCM) and the Engine Control Module (ECM) of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-network attacker with read access to the in-vehicle network to recover the per-vehicle ECM immobilizer secret by passively observing a single seed/key exchange. The WCM derives its response using a reversible, non-cryptographic operation rather than a cryptographic challenge-response, so the persistent immobilizer secret can be reconstructed from one captured exchange. With this secret the attacker can authenticate to the ECM independently of the WCM and start the engine, defeating the immobilizer. Specific protocol details have been withheld pending vendor remediation.
CVE-2026-49322 2026-07-21 N/A 4.3 MEDIUM
Weak authentication in the Wireless Control Module (WCM) of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-network attacker with read access to the in-vehicle network to recover the user-set unlock PIN by passively observing a single PIN authentication exchange. The Infotainment Digital Round display computes its response using a non-cryptographic operation rather than a cryptographic challenge-response, so the PIN is mathematically derivable from one captured exchange, defeating the motorcycle's primary user-authentication control. Specific protocol details have been withheld pending vendor remediation.