Authentication Bypass Vulnerabilities

13 advisories classified as Authentication Bypass

13

Total CVEs

9

Critical

4

High

CVE-2026-18577

Aug 2, 2026

High 8.2

An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1...

Read Advisory

CVE-2026-18556

Aug 1, 2026

High 8.2

Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass. This issue affects N-central: through 2026.1....

Read Advisory

CVE-2026-16232

Jul 22, 2026

Critical 9.1

An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full...

Read Advisory

CVE-2026-48558

Jun 12, 2026

Critical 10.0

SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity token...

Read Advisory

CVE-2026-0257

May 13, 2026

Critical 9.1

Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized V...

Read Advisory

CVE-2026-41940

Apr 29, 2026

Critical 9.8

cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel....

Read Advisory

CVE-2018-25236

Apr 3, 2026

Critical 9.8

Hirschmann HiOS and HiSecOS products RSP, RSPE, RSPS, RSPL, MSP, EES, EESX, GRS, OS, RED, EAGLE contain an authentication bypass vulnerability in the HTTP(S) management module that allows unauthentica...

Read Advisory

CVE-2026-32974

Mar 29, 2026

High 8.6

OpenClaw before 2026.3.12 contains an authentication bypass vulnerability in Feishu webhook mode when only verificationToken is configured without encryptKey, allowing acceptance of forged events. Una...

Read Advisory

CVE-2019-25510

Mar 12, 2026

High 8.2

Jettweb PHP Hazir Haber Sitesi Scripti V2 contains an authentication bypass vulnerability in the administration panel that allows unauthenticated attackers to gain administrative access by exploiting ...

Read Advisory

CVE-2026-21718

Feb 27, 2026

Critical 10.0

An authentication bypass vulnerability exists in Copeland XWEB Pro version 1.12.1 and prior, enabling any attackers to bypass the authentication requirement and achieve pre-authenticated code execut...

Read Advisory

CVE-2026-2624

Feb 25, 2026

Critical 9.8

Missing Authentication for Critical Function vulnerability in ePati Cyber ​​Security Technologies Inc. Antikor Next Generation Firewall (NGFW) allows Authentication Bypass.This issue affects Antikor N...

Read Advisory

CVE-2026-2635

Feb 20, 2026

Critical 9.8

MLflow Use of Default Password Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of MLflow. Authentication is not requi...

Read Advisory

CVE-2025-32975

Jun 24, 2025

Critical 10.0

Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.0.x before 14.0.341 (Patch 5), and 14.1.x before 14.1.101 (Patch 4) contains an ...

Read Advisory

Never Miss a Critical Alert

CVE advisories, breach reports, and threat intel — delivered daily to your inbox.