https://advisories.gitlab.com/maven/org.elasticsearch/elasticsearch/CVE-2025-37731/
Elasticsearch PKI Realm Authentication Bypass Vulnerability Allows User Impersonation Through...
CVE-2025-37731 Elasticsearch PKI Realm Authentication Bypass Vulnerability Allows User Impersonation Through Crafted Client Certificates: Improper...
authentication bypassuser impersonationelasticsearchpkirealm
https://advisories.gitlab.com/npm/passport-wsfed-saml2/CVE-2022-23505/
Authentication Bypass for WSFed | GitLab Advisory Database (GLAD)
CVE-2022-23505 Authentication Bypass for WSFed: Passport-wsfed-saml2 is a ws-federation protocol and SAML2 tokens authentication provider for Passport. In...
authentication bypassgitlabadvisorydatabaseglad
https://advisories.gitlab.com/composer/typo3/cms/GHSA-mh3r-6cp5-hc2j/
Authentication Bypass in TYPO3 Frontend | GitLab Advisory Database (GLAD)
GHSA-mh3r-6cp5-hc2j Authentication Bypass in TYPO3 Frontend: Due to late TCA initialization the authentication service fails to restrict frontend user...
authentication bypassfrontendgitlabadvisorydatabase
https://advisories.gitlab.com/pypi/crate/CVE-2023-51982/
CrateDB authentication bypass vulnerability | GitLab Advisory Database (GLAD)
CVE-2023-51982 CrateDB authentication bypass vulnerability: CrateDB 5.5.1 is contains an authentication bypass vulnerability in the Admin UI component. After...
authentication bypasscratedbvulnerabilitygitlabadvisory
https://advisories.gitlab.com/composer/symfony/security-http/CVE-2024-36611/
Withdrawn Advisory: Symfony http-security has authentication bypass | GitLab Advisory Database...
CVE-2024-36611 Withdrawn Advisory: Symfony http-security has authentication bypass: Withdrawn Advisory This advisory has been withdrawn because the report is...
authentication bypasswithdrawnadvisorysymfonyhttp
https://advisories.gitlab.com/golang/github.com/komari-monitor/komari/GHSA-jhmr-57cj-q6g9/
Komari vulnerable to 2FA Authentication Bypass | GitLab Advisory Database (GLAD)
GHSA-jhmr-57cj-q6g9 Komari vulnerable to 2FA Authentication Bypass: Logic error in 2FA verification condition allows bypass of two-factor authentication
authentication bypasskomarivulnerablegitlabadvisory
https://advisories.gitlab.com/golang/github.com/robotsandpencils/go-saml/CVE-2023-48703/
RobotsAndPencils go-saml authentication bypass vulnerability | GitLab Advisory Database (GLAD)
CVE-2023-48703 RobotsAndPencils go-saml authentication bypass vulnerability: RobotsAndPencils go-saml, a SAML client library written in Go, contains an...
saml authenticationgobypassvulnerabilitygitlab
https://www.techradar.com/news/cisco-fixes-critical-authentication-bypass-bug-in-its-enterprise-software
Cisco fixes critical authentication bypass bug in its enterprise software | TechRadar
Sep 3, 2021 - Cisco urges users to upgrade their devices to the patched version
authentication bypassbug inenterprise softwareciscofixes
https://lists.archlinux.org/archives/list/arch-security@lists.archlinux.org/thread/VIT6FKYKNWJWM6AYXFQLHGRYD262UTS7/
[ASA-201902-1] dovecot: authentication bypass - Arch-security - lists.archlinux.org
authentication bypasssecurity listsasadovecot
https://advisories.gitlab.com/golang/github.com/patrickhener/goshs/GHSA-c29w-qq4m-2gcv/
Empty-username SFTP password authentication bypass in goshs | GitLab Advisory Database (GLAD)
GHSA-c29w-qq4m-2gcv Empty-username SFTP password authentication bypass in goshs: goshs contains an SFTP authentication bypass when the documented...
password authentication
https://support.lenovo.com/au/en/product_security/len-16095
Enterprise Networking Operating System (ENOS) Authentication Bypass in Lenovo and IBM RackSwitch...
Enterprise Networking Operating System (ENOS) Authentication Bypass in Lenovo and IBM RackSwitch and BladeCenter Products
enterprise networkingoperating systemauthentication bypass
https://advisories.gitlab.com/maven/cn.dev33/sa-token-core/CVE-2023-43961/
SaToken authentication bypass vulnerability | GitLab Advisory Database (GLAD)
CVE-2023-43961 SaToken authentication bypass vulnerability: An issue in Dromara SaToken version 1.3.50RC and before when using Spring dynamic controllers, a...
authentication bypassvulnerabilitygitlabadvisorydatabase
https://advisories.gitlab.com/maven/org.apache.pinot/pinot-broker/CVE-2024-56325/
Apache Pinot Vulnerable to Authentication Bypass | GitLab Advisory Database (GLAD)
CVE-2024-56325 Apache Pinot Vulnerable to Authentication Bypass: Authentication Bypass Issue If the path does not contain / and contain., authentication is not...
apache pinotauthentication bypassvulnerablegitlabadvisory
https://advisories.gitlab.com/composer/thelia/thelia/GHSA-g8pg-33v4-9r96/
Thelia authentication bypass vulnerability | GitLab Advisory Database (GLAD)
GHSA-g8pg-33v4-9r96 Thelia authentication bypass vulnerability: An authentication bypass was identifed in thelia/thelia project for customer and admin. This...
authentication bypasstheliavulnerabilitygitlabadvisory
https://www.itsc.cuhk.edu.hk/tc/user-trainings/information-security-best-practices/pan-os-authentication-bypass-vulnerability-cve-2024-0012-privilege-escalation-vulnerability-cve-2024-9474/
PAN-OS Authentication Bypass Vulnerability (CVE-2024-0012) & Privilege Escalation Vulnerability...
authentication bypasspanosvulnerabilitycve
https://advisories.gitlab.com/pypi/mitmproxy/CVE-2025-23217/
Mitmweb API Authentication Bypass Using Proxy Server | GitLab Advisory Database (GLAD)
CVE-2025-23217 Mitmweb API Authentication Bypass Using Proxy Server: In mitmweb 11.1.0 and below, a malicious client can use mitmweb's proxy server (bound to...
api authenticationproxy serverbypassusing
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-wsa-auth-bypass-6YZkTQhd?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Secure%20Web%20Appliance%20Authentication%20Bypass%20Vulnerability%26vs_k=1
Cisco Secure Web Appliance Authentication Bypass Vulnerability
A vulnerability in the authentication service feature of Cisco AsyncOS Software for Cisco Secure Web Appliance could allow an unauthenticated, remote attacker...
cisco secure web applianceauthentication bypassvulnerability
https://thehackernews.com/2025/02/palo-alto-networks-patches.html?version=meter+at+null
Palo Alto Networks Patches Authentication Bypass Exploit in PAN-OS Software
Palo Alto Networks patches CVE-2025-0108, a PAN-OS flaw (CVSS 7.8) allowing authentication bypass. Update now.
palo alto networksauthentication bypasspatches
https://thehackernews.com/2022/04/atlassian-drops-patches-for-critical.html
Atlassian Drops Patches for Critical Jira Authentication Bypass Vulnerability
A critical authentication bypass vulnerability (CVE-2022-0540 and CVSS 9.9) has been discovered in Seraph affecting Atlassian Jira.
authentication bypassatlassiandropspatchescritical
https://advisories.gitlab.com/maven/io.crate/crate/CVE-2023-51982/
CrateDB authentication bypass vulnerability | GitLab Advisory Database (GLAD)
CVE-2023-51982 CrateDB authentication bypass vulnerability: CrateDB 5.5.1 is contains an authentication bypass vulnerability in the Admin UI component. After...
authentication bypasscratedbvulnerabilitygitlabadvisory
https://security.paloaltonetworks.com/CVE-2020-2018
CVE-2020-2018 PAN-OS: Panorama authentication bypass vulnerability
May 13, 2020 - Palo Alto Networks Security Advisory: CVE-2020-2018 PAN-OS: Panorama authentication bypass vulnerability An authentication bypass vulnerability in the Panorama...
authentication bypasscvepanosvulnerability
https://advisories.gitlab.com/composer/joomla/joomla-cms/CVE-2025-25227/
Joomla CMS Multi-Factor Authentication Bypass | GitLab Advisory Database (GLAD)
CVE-2025-25227 Joomla CMS Multi-Factor Authentication Bypass: Insufficient state checks lead to a vector that allows to bypass 2FA checks.
multi factor authenticationjoomla cmsbypassgitlabadvisory
https://advisories.gitlab.com/maven/org.apache.tomcat/tomcat/CVE-2012-3546/
Authentication Bypass in Apache Tomcat | GitLab Advisory Database (GLAD)
CVE-2012-3546 Authentication Bypass in Apache Tomcat: org/apache/catalina/realm/RealmBase.java in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.30, when...
authentication bypassapache tomcatgitlabadvisorydatabase
https://advisories.gitlab.com/composer/symfony/security-http/CVE-2024-51996/
Symfony has an Authentication Bypass via RememberMe | GitLab Advisory Database (GLAD)
CVE-2024-51996 Symfony has an Authentication Bypass via RememberMe: When consuming a persisted remember-me cookie, Symfony does not check if the username...
authentication bypasssymfony
https://www.kaspersky.com/blog/cve-2024-10924-wordpress-authentication-bypass/52637/
CVE-2024-10924, authentication bypass vulnerability in WordPress
Vulnerability CVE-2024-10924 in the Really Simple Security plugin allows an attacker to log onto a WordPress site with administrator rights.
authentication bypasscvevulnerabilitywordpress
https://ccb.belgium.be/de/advisories/warning-critical-authentication-bypass-moveit-automation-cve-2026-4670-patch-immediately
Warning: Critical authentication bypass in MOVEit Automation (CVE-2026-4670), Patch Immediately! |...
authentication bypassmoveit automation
https://advisories.gitlab.com/pypi/mlflow/CVE-2025-11200/
MLflow Weak Password Requirements Authentication Bypass Vulnerability | GitLab Advisory Database...
CVE-2025-11200 MLflow Weak Password Requirements Authentication Bypass Vulnerability: MLflow Weak Password Requirements Authentication Bypass Vulnerability....
password requirementsauthentication bypassmlflowweakvulnerability
https://advisories.gitlab.com/pypi/paramiko/CVE-2018-1000805/
Paramiko Authentication Bypass vulnerability | GitLab Advisory Database (GLAD)
CVE-2018-1000805 Paramiko Authentication Bypass vulnerability: Paramiko version 2.4.1, 2.3.2, 2.2.3, 2.1.5, 2.0.8, 1.18.5, 1.17.6 contains a Incorrect Access...
authentication bypassparamikovulnerabilitygitlabadvisory
https://spring.io/security/cve-2026-22733/
CVE-2026-22733: Authentication Bypass under Actuator CloudFoundry endpoints
Level up your Java code and explore what Spring can do for you.
authentication bypasscveactuatorcloudfoundryendpoints
https://advisories.gitlab.com/maven/org.apache.tomcat/tomcat/CVE-2011-1184/
Authentication Bypass in Apache Tomcat | GitLab Advisory Database (GLAD)
CVE-2011-1184 Authentication Bypass in Apache Tomcat: The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before...
authentication bypassapache tomcatgitlabadvisorydatabase
https://advisories.gitlab.com/maven/org.apache.pinot/pinot-common/CVE-2024-56325/
Apache Pinot Vulnerable to Authentication Bypass | GitLab Advisory Database (GLAD)
CVE-2024-56325 Apache Pinot Vulnerable to Authentication Bypass: Authentication Bypass Issue If the path does not contain / and contain., authentication is not...
apache pinotauthentication bypassvulnerablegitlabadvisory
https://advisories.gitlab.com/npm/@sap/approuter/CVE-2025-24876/
Authentication bypass in @sap/approuter | GitLab Advisory Database (GLAD)
CVE-2025-24876 Authentication bypass in @sap/approuter: The SAP Approuter Node.js package version v16.7.1 and before is vulnerable to Authentication bypass....
authentication bypasssapgitlabadvisorydatabase
https://advisories.gitlab.com/golang/github.com/nanobox-io/golang-nanoauth/CVE-2020-36569/
golang-nanoauth authentication bypass vulnerability | GitLab Advisory Database (GLAD)
CVE-2020-36569 golang-nanoauth authentication bypass vulnerability: Authentication is globally bypassed in github.com/nanobox-io/golang-nanoauth between...
authentication bypassgolangvulnerabilitygitlabadvisory
https://www.huawei.com/en/psirt/security-advisories/2018/huawei-sa-20180307-01-smartphone-en
Security Advisory - Authentication Bypass Vulnerability in Some Huawei Smart Phones
security advisoryauthentication bypassvulnerabilityhuaweismart
https://advisories.gitlab.com/gem/ruby-saml/CVE-2025-25291/
Ruby SAML allows a SAML authentication bypass due to DOCTYPE handling (parser differential) |...
CVE-2025-25291 Ruby SAML allows a SAML authentication bypass due to DOCTYPE handling (parser differential): An authentication bypass vulnerability was found in...
authentication bypass
https://advisories.gitlab.com/pypi/dtale/CVE-2024-3408/
Authentication bypass in dtale | GitLab Advisory Database (GLAD)
CVE-2024-3408 Authentication bypass in dtale: man-group/dtale version 3.10.0 is vulnerable to an authentication bypass and remote code execution (RCE) due to...
authentication bypassgitlabadvisorydatabaseglad
https://advisories.gitlab.com/pypi/wiremock/CVE-2023-41329/
Authentication Bypass by Spoofing | GitLab Advisory Database (GLAD)
CVE-2023-41329 Authentication Bypass by Spoofing: WireMock is a tool for mocking HTTP services. The proxy mode of WireMock, can be protected by the network...
authentication bypassspoofinggitlabadvisorydatabase
https://advisories.gitlab.com/npm/node-saml/CVE-2025-54369/
Node-SAML SAML Authentication Bypass | GitLab Advisory Database (GLAD)
CVE-2025-54369 Node-SAML SAML Authentication Bypass: Node-SAML loads the assertion from the (unsigned) original response document. This is different than the...
saml authenticationnodebypassgitlabadvisory
https://grayhat.teachable.com/courses/web-application-penetration-tester-professional-waptp/lectures/3589797
Authentication bypass-hydra | grayhat | security
Attack web application like never before with latest tools, tricks and attacks at professional level
authentication bypasshydrasecurity
https://advisories.gitlab.com/golang/github.com/prometheus/prometheus/GMS-2022-7743/
Prometheus vulnerable to basic authentication bypass | GitLab Advisory Database (GLAD)
GMS-2022-7743 Prometheus vulnerable to basic authentication bypass: Prometheus can be secured by a web.yml file that specifies usernames and hashed passwords...
basic authenticationprometheusvulnerablebypassgitlab
https://advisories.gitlab.com/cargo/svix/CVE-2024-21491/
svix vulnerable to Authentication Bypass | GitLab Advisory Database (GLAD)
CVE-2024-21491 svix vulnerable to Authentication Bypass: Versions of the package svix before 1.17.0 are vulnerable to Authentication Bypass due to an issue in...
authentication bypasssvixvulnerablegitlabadvisory
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-wsa-auth-bypass-6YZkTQhd?vs_f=Cisco%20Security%20Advisory%26vs_cat%3DSecurity%20Intelligence%26vs_type%3DRSS%26vs_p%3DCisco%20Secure%20Web%20Appliance%20Authentication%20Bypass%20Vulnerability%26vs_k%3D1
Cisco Secure Web Appliance Authentication Bypass Vulnerability
A vulnerability in the authentication service feature of Cisco AsyncOS Software for Cisco Secure Web Appliance could allow an unauthenticated, remote attacker...
cisco secure web applianceauthentication bypassvulnerability
https://advisories.gitlab.com/golang/github.com/answerdev/answer/CVE-2023-1537/
Authentication Bypass by Capture-replay | GitLab Advisory Database (GLAD)
CVE-2023-1537 Authentication Bypass by Capture-replay: Authentication Bypass by Capture-replay in GitHub repository answerdev/answer prior to 1.0.6.
authentication bypasscapturereplaygitlabadvisory
https://blog.zimbra.com/2022/08/authentication-bypass-in-mailboximportservlet-vulnerability/
Authentication Bypass in MailboxImportServlet vulnerability - Zimbra : Blog
Aug 10, 2022 - Zimbra 8.8.15 patch 33 and Zimbra 9.0.0 patch 26 contain an important security update that fixes an authentication bypass in MailboxImportServlet...
authentication bypassvulnerabilityzimbrablog
https://advisories.gitlab.com/maven/org.apache.kylin/kylin/CVE-2025-61733/
Apache Kylin Authentication Bypass Vulnerability | GitLab Advisory Database (GLAD)
CVE-2025-61733 Apache Kylin Authentication Bypass Vulnerability: Authentication Bypass Using an Alternate Path or Channel vulnerability in Apache Kylin. This...
apache kylinauthentication bypassvulnerabilitygitlabadvisory
https://advisories.gitlab.com/maven/org.keycloak/keycloak-core/CVE-2024-10039/
Keycloak mTLS Authentication Bypass via Reverse Proxy TLS Termination | GitLab Advisory Database...
CVE-2024-10039 Keycloak mTLS Authentication Bypass via Reverse Proxy TLS Termination : A vulnerability was found in Keycloak. Deployments of Keycloak with a...
authentication bypassreverse proxy
https://advisories.gitlab.com/npm/@fastify/middie/CVE-2026-6270/
@fastify/middie vulnerable to middleware authentication bypass in child plugin scopes | GitLab...
CVE-2026-6270 @fastify/middie vulnerable to middleware authentication bypass in child plugin scopes: @fastify/middie v9.3.1 and earlier incorrectly re-prefixes...
authentication bypass
https://advisories.gitlab.com/pypi/octoprint/CVE-2025-32788/
OctoPrint Authenticated Reverse Proxy Page Authentication Bypass | GitLab Advisory Database (GLAD)
CVE-2025-32788 OctoPrint Authenticated Reverse Proxy Page Authentication Bypass: OctoPrint versions up until and including 1.10.3 contain a vulnerability that...
reverse proxyauthentication bypassoctoprintauthenticated
https://advisories.gitlab.com/npm/@fastify/express/CVE-2026-33808/
@fastify/express has a middleware authentication bypass via URL normalization gaps (duplicate...
CVE-2026-33808 @fastify/express has a middleware authentication bypass via URL normalization gaps (duplicate slashes and semicolons): @fastify/express v4.0.4...
authentication bypass
https://advisories.gitlab.com/pypi/rdiffweb/CVE-2022-4722/
rdiffweb vulnerable to Authentication Bypass by Primary Weakness | GitLab Advisory Database (GLAD)
CVE-2022-4722 rdiffweb vulnerable to Authentication Bypass by Primary Weakness: In rdiffweb prior to 2.5.5, the username field is not unique to users. This...
authentication bypass
https://cert.europa.eu/publications/security-advisories/2023-043/
CERT-EU - Grafana Authentication Bypass Using Azure AD OAuth
CERT-EU - Grafana Authentication Bypass Using Azure AD OAuth
authentication bypassazure adcerteugrafana
https://advisories.gitlab.com/npm/passport-wsfed-saml2/CVE-2025-46572/
Passport-wsfed-saml2 allows SAML Authentication Bypass via Signature Wrapping | GitLab Advisory...
CVE-2025-46572 Passport-wsfed-saml2 allows SAML Authentication Bypass via Signature Wrapping: Overview This vulnerability allows an attacker to impersonate any...
saml authentication
https://helpcenter.trendmicro.com/en-us/article/tmka-20493
Authentication Bypass DNS Change notification | Trend Micro Help Center
Learn more about the Authentication Bypass DNS Change notification Trend Micro Home Network Security detected on your network.
authentication bypasschange notificationtrend microdnshelp
https://advisories.gitlab.com/maven/com.vaadin/vaadin/CVE-2026-2742/
Vaadin Vulnerable to Authentication Bypass When Accessing the /VAADIN Endpoint Without a Trailing...
CVE-2026-2742 Vaadin Vulnerable to Authentication Bypass When Accessing the /VAADIN Endpoint Without a Trailing Slash: An authentication bypass vulnerability...
authentication bypass
https://advisories.gitlab.com/golang/github.com/openshift/apiserver-library-go/CVE-2023-1260/
kube-apiserver authentication bypass vulnerability | GitLab Advisory Database (GLAD)
CVE-2023-1260 kube-apiserver authentication bypass vulnerability: An authentication bypass vulnerability was discovered in kube-apiserver. This issue could...
authentication bypasskubevulnerabilitygitlabadvisory
https://advisories.gitlab.com/npm/dagu/CVE-2026-31882/
Dagu: SSE Authentication Bypass in Basic Auth Mode | GitLab Advisory Database (GLAD)
CVE-2026-31882 Dagu: SSE Authentication Bypass in Basic Auth Mode: When Dagu is configured with HTTP Basic authentication (DAGU_AUTH_MODE=basic), all...
authentication bypass
https://advisories.gitlab.com/golang/github.com/grafana/grafana/CVE-2023-3128/
Grafana vulnerable to Authentication Bypass by Spoofing | GitLab Advisory Database (GLAD)
CVE-2023-3128 Grafana vulnerable to Authentication Bypass by Spoofing: Grafana is validating Azure AD accounts based on the email claim. On Azure AD, the...
authentication bypassgrafanavulnerable
https://pastebin.com/JuHZX7zJ
MySQL Remote Root Authentication Bypass - Pastebin.com
Pastebin.com is the number one paste tool since 2002. Pastebin is a website where you can store text online for a set period of time.
authentication bypassmysqlremoterootpastebin
https://ccb.belgium.be/advisories/warning-critical-authentication-bypass-moveit-automation-cve-2026-4670-patch-immediately
Warning: Critical authentication bypass in MOVEit Automation (CVE-2026-4670), Patch Immediately! |...
authentication bypassmoveit automation
https://advisories.gitlab.com/pypi/strawberry-graphql/CVE-2026-35523/
strawberry-graphql: Authentication bypass via legacy graphql-ws WebSocket subprotocol | GitLab...
CVE-2026-35523 strawberry-graphql: Authentication bypass via legacy graphql-ws WebSocket subprotocol: Strawberry up until version 0.312.3 is vulnerable to an...
authentication bypassstrawberrygraphqlvialegacy
https://advisories.gitlab.com/maven/org.wiremock/wiremock-standalone/CVE-2023-41329/
Authentication Bypass by Spoofing | GitLab Advisory Database (GLAD)
CVE-2023-41329 Authentication Bypass by Spoofing: WireMock is a tool for mocking HTTP services. The proxy mode of WireMock, can be protected by the network...
authentication bypassspoofinggitlabadvisorydatabase
https://cwe.mitre.org/data/definitions/294.html
CWE - CWE-294: Authentication Bypass by Capture-replay (4.20)
Common Weakness Enumeration (CWE) is a list of software weaknesses.
authentication bypasscwecapturereplay
https://advisories.gitlab.com/npm/parse-server/CVE-2024-39309/
ZDI-CAN-23894: Parse Server literalizeRegexPart SQL Injection Authentication Bypass Vulnerability |...
CVE-2024-39309 ZDI-CAN-23894: Parse Server literalizeRegexPart SQL Injection Authentication Bypass Vulnerability: This vulnerability allows SQL injection when...
parse serversql injectionauthentication bypasszdi
https://advisories.gitlab.com/pypi/flower/CVE-2022-30034/
Flower OAuth authentication bypass | GitLab Advisory Database (GLAD)
CVE-2022-30034 Flower OAuth authentication bypass: All versions of Flower, a web UI for the Celery Python RPC framework, as of 05-02-2022 are vulnerable to an...
oauth authenticationflowerbypassgitlabadvisory
https://advisories.gitlab.com/golang/github.com/argoproj/argo-cd/v2/CVE-2022-29165/
Authentication Bypass by Spoofing | GitLab Advisory Database (GLAD)
CVE-2022-29165 Authentication Bypass by Spoofing: Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. A critical vulnerability has been...
authentication bypassspoofinggitlabadvisorydatabase
https://advisories.gitlab.com/golang/github.com/foxcpp/maddy/CVE-2023-27582/
Authentication Bypass by Primary Weakness | GitLab Advisory Database (GLAD)
CVE-2023-27582 Authentication Bypass by Primary Weakness: maddy is a composable, all-in-one mail server. Starting with version 0.2.0 and prior to version...
authentication bypassprimaryweaknessgitlabadvisory
https://ccb.belgium.be/nl/advisories/warning-critical-authentication-bypass-moveit-automation-cve-2026-4670-patch-immediately
Warning: Critical authentication bypass in MOVEit Automation (CVE-2026-4670), Patch Immediately! |...
authentication bypassmoveit automation
https://advisories.gitlab.com/pypi/oauthenticator/CVE-2026-33175/
Auth0OAuthenticator has an Authentication Bypass via Unverified Email Claims | GitLab Advisory...
CVE-2026-33175 Auth0OAuthenticator has an Authentication Bypass via Unverified Email Claims: An authentication bypass vulnerability in oauthenticator allows an...
authentication bypass
https://advisories.gitlab.com/golang/github.com/iofinnet/tss-lib/CVE-2022-47930/
Authentication Bypass by Capture-replay | GitLab Advisory Database (GLAD)
CVE-2022-47930 Authentication Bypass by Capture-replay: An issue was discovered in IO FinNet tss-lib before 2.0.0. The parameter ssid for defining a session id...
authentication bypasscapturereplaygitlabadvisory
https://advisories.gitlab.com/npm/parse-server/CVE-2023-22474/
Authentication Bypass by Spoofing | GitLab Advisory Database (GLAD)
CVE-2023-22474 Authentication Bypass by Spoofing: Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Parse...
authentication bypassspoofinggitlabadvisorydatabase
https://advisories.gitlab.com/maven/org.keycloak/keycloak-services/GHSA-fx44-2wx5-5fvp/
Duplicate Advisory: Keycloak vulnerable to two factor authentication bypass | GitLab Advisory...
GHSA-fx44-2wx5-5fvp Duplicate Advisory: Keycloak vulnerable to two factor authentication bypass: Duplicate Advisory This advisory has been withdrawn because it...
two factor authenticationduplicateadvisorykeycloakvulnerable
https://advisories.gitlab.com/golang/github.com/hashicorp/vault/CVE-2020-16251/
HashiCorp Vault Authentication bypass | GitLab Advisory Database (GLAD)
CVE-2020-16251 HashiCorp Vault Authentication bypass: HashiCorp Vault and Vault Enterprise versions 0.8.3 and newer, when configured with the GCP GCE auth...
hashicorp vaultauthentication bypassgitlabadvisorydatabase
https://advisories.gitlab.com/golang/github.com/milvus-io/milvus/CVE-2025-64513/
Milvus Proxy has a Critical Authentication Bypass Vulnerability | GitLab Advisory Database (GLAD)
CVE-2025-64513 Milvus Proxy has a Critical Authentication Bypass Vulnerability: What kind of vulnerability is it? Who is impacted? An unauthenticated attacker...
authentication bypass
https://www.semperis.com/blog/golden-dmsa-what-is-dmsa-authentication-bypass/
Golden dMSA: What Is dMSA Authentication Bypass? | Semperis Research
Jan 8, 2026 - The Golden dMSA attack enables attackers to bypass authentication and generate passwords for managed service accounts in AD. Understand the risks.
what isauthentication bypassgoldendmsasemperis
https://advisories.gitlab.com/npm/@lobehub/lobehub/CVE-2026-39411/
LobeHub: Unauthenticated authentication bypass on `webapi` routes via forgeable `X-lobe-chat-auth`...
CVE-2026-39411 LobeHub: Unauthenticated authentication bypass on `webapi` routes via forgeable `X-lobe-chat-auth` header: The webapi authentication layer...
https://lists.archlinux.org/archives/list/arch-security@lists.archlinux.org/thread/5TBZP6YM2BUBMANQURHSXOPI4WXAF6BN/?sort=thread
[ASA-201902-21] python-mysql-connector: authentication bypass - Arch-security - lists.archlinux.org
https://apereo.github.io/cas/7.3.x/mfa/Configuring-Multifactor-Authentication-Bypass.html
CAS - Multifactor Authentication Bypass
CAS - Enterprise Single Sign-On for the Web
multifactor authenticationcasbypass
https://advisories.gitlab.com/composer/scheb/two-factor-bundle/GHSA-9phw-7h96-q3rv/
scheb/two-factor-bundle bypass two-factor authentication with remember-me option | GitLab Advisory...
GHSA-9phw-7h96-q3rv scheb/two-factor-bundle bypass two-factor authentication with remember-me option: In versions prior to 3.26.0 and prior to 4.11.0 of the...
two factor
https://advisories.gitlab.com/golang/github.com/dgraph-io/dgraph/v25/CVE-2026-41492/
Dgraph: Unauthenticated Admin Token Disclosure Leading to Authentication Bypass via /debug/vars |...
CVE-2026-41492 Dgraph: Unauthenticated Admin Token Disclosure Leading to Authentication Bypass via /debug/vars: Dgraph v25.3.2 still exposes the process...
https://thehackernews.com/2026/05/progress-patches-critical-moveit.html
Progress Patches Critical MOVEit Automation Bug Enabling Authentication Bypass
MOVEit Automation flaws (CVE-2026-4670, CVE-2026-5174) enable bypass and escalation, risking enterprise data exposure.
moveit automationprogresspatchescriticalbug
https://vuxml.freebsd.org/freebsd/2bc376c0-977e-11ee-b4bc-b42e991fc52e.html
VuXML: apache -- Apache ZooKeeper: Authorization bypass in SASL Quorum Peer Authentication
apache zookeepervuxmlauthorizationbypasssasl
https://advisories.gitlab.com/golang/github.com/traefik/traefik/v2/CVE-2026-39858/
Traefik: Pre-authentication decision bypass due to forwarded alias spoofing | GitLab Advisory...
CVE-2026-39858 Traefik: Pre-authentication decision bypass due to forwarded alias spoofing: There is a high severity authentication bypass vulnerability in...
due to
https://developer.joomla.org/security-centre/713-20171102-core-2-factor-authentication-bypass
[20171102] - Core - 2-factor-authentication bypass
corefactorauthenticationbypass