CWE-287
DiscouragedImproper Authentication
Abstraction: Class · Status: Draft
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
6773 vulnerabilities reference this CWE, most recent first.
CVE-2026-92914 (GCVE-0-2026-92914)
Vulnerability from cvelistv5 – Published: 2026-09-17 11:16 – Updated: 2026-09-17 19:22- CWE-287 - Improper Authentication
| URL | Tags |
|---|---|
| https://github.com/WWBN/AVideo/security/advisorie… | vendor-advisory |
| https://www.vulncheck.com/advisories/avideo-login… | third-party-advisory |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-92914",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-17T19:17:10.770540Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-17T19:22:52.032Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "AVideo",
"vendor": "WWBN",
"versions": [
{
"lessThanOrEqual": "29.0",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:wwbn:avideo:*:*:*:*:*:*:*:*",
"versionEndIncluding": "29.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "rajivraj"
}
],
"datePublic": "2026-09-02T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "AVideo LoginControl contains an authentication bypass vulnerability in the PGP second factor verification that compares challenge responses using loose equality against an uninitialized session variable. Attackers with a victim\u0027s password can bypass the second factor by sending a parameter-less GET request to verifyChallenge.json.php, which evaluates null == null and marks authentication complete."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 8.6,
"baseSeverity": "HIGH",
"privilegesRequired": "LOW",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 8.1,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-287",
"description": "Improper Authentication",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-17T11:16:43.116Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "GitHub Security Advisory (GHSA-mvmf-jqg6-qhjf)",
"tags": [
"vendor-advisory"
],
"url": "https://github.com/WWBN/AVideo/security/advisories/GHSA-mvmf-jqg6-qhjf"
},
{
"name": "VulnCheck Advisory: AVideo LoginControl PGP Second Factor Authentication Bypass",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/avideo-logincontrol-pgp-second-factor-authentication-bypass"
}
],
"title": "AVideo LoginControl PGP Second Factor Authentication Bypass",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-92914",
"datePublished": "2026-09-17T11:16:43.116Z",
"dateReserved": "2026-09-17T11:07:29.772Z",
"dateUpdated": "2026-09-17T19:22:52.032Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-92792 (GCVE-0-2026-92792)
Vulnerability from cvelistv5 – Published: 2026-09-16 20:32 – Updated: 2026-09-19 01:44- CWE-287 - Improper Authentication
| URL | Tags |
|---|---|
| https://github.com/OpenNHP/opennhp/issues/1732 | issue-tracking |
| https://github.com/OpenNHP/opennhp | product |
| https://github.com/OpenNHP/opennhp/blob/v1.0.2/nh… | technical-description |
| https://www.vulncheck.com/advisories/opennhp-thro… | third-party-advisory |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-92792",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-19T01:44:00.477221Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-19T01:44:37.436Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://github.com/OpenNHP/opennhp/issues/1732"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "opennhp",
"vendor": "OpenNHP",
"versions": [
{
"lessThanOrEqual": "1.0.2",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "George Chen"
}
],
"datePublic": "2026-09-14T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "OpenNHP through 1.0.2 selects its trusted-execution attestation verifier based on attacker-supplied evidence containing a test_purpose key, causing the FallbackVerifier to execute unconditionally. Attackers can bypass attestation verification by including the test_purpose key in evidence and providing enrolled measure and serial number pairs from the allowlist to gain unauthorized access."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 8.7,
"baseSeverity": "HIGH",
"privilegesRequired": "NONE",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "NONE"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 7.5,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-287",
"description": "Improper Authentication",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-16T20:32:47.538Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "GitHub Issue #1732",
"tags": [
"issue-tracking"
],
"url": "https://github.com/OpenNHP/opennhp/issues/1732"
},
{
"tags": [
"product"
],
"url": "https://github.com/OpenNHP/opennhp"
},
{
"name": "the fallback verifier always succeeds and is selected by an evidence key",
"tags": [
"technical-description"
],
"url": "https://github.com/OpenNHP/opennhp/blob/v1.0.2/nhp/core/verifier/verifier.go#L27-L92"
},
{
"name": "VulnCheck Advisory: OpenNHP through 1.0.2 Authentication Bypass via Fallback Verifier",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/opennhp-through-1.0.2-authentication-bypass-via-fallback-verifier"
}
],
"title": "OpenNHP through 1.0.2 Authentication Bypass via Fallback Verifier",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-92792",
"datePublished": "2026-09-16T20:32:47.538Z",
"dateReserved": "2026-09-16T19:40:19.806Z",
"dateUpdated": "2026-09-19T01:44:37.436Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-92578 (GCVE-0-2026-92578)
Vulnerability from cvelistv5 – Published: 2026-09-16 21:46 – Updated: 2026-09-17 14:52- CWE-287 - Improper Authentication
| URL | Tags |
|---|---|
| https://github.com/WWBN/AVideo/security/advisorie… | vendor-advisory |
| https://www.vulncheck.com/advisories/wwbn-avideo-… | third-party-advisory |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-92578",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-17T14:52:36.172760Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-17T14:52:56.526Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://github.com/WWBN/AVideo/security/advisories/GHSA-fq38-jp6c-q4cx"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "AVideo",
"vendor": "WWBN",
"versions": [
{
"lessThanOrEqual": "29.0",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:wwbn:avideo:*:*:*:*:*:*:*:*",
"versionEndIncluding": "29.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "rajivraj"
}
],
"datePublic": "2026-09-01T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "WWBN AVideo through 29.0 contains an authentication bypass vulnerability where the stored password hash is accepted as a valid login credential through two independent code paths in loginFromRequest() and encryptPasswordVerify(). Attackers who obtain the stored users.password hash value can authenticate as any user by submitting the hash directly to login endpoints, completely bypassing password verification."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"attackVector": "NETWORK",
"baseScore": 9.2,
"baseSeverity": "CRITICAL",
"privilegesRequired": "NONE",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 8.1,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-287",
"description": "Improper Authentication",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-16T21:46:47.151Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "GitHub Security Advisory (GHSA-fq38-jp6c-q4cx)",
"tags": [
"vendor-advisory"
],
"url": "https://github.com/WWBN/AVideo/security/advisories/GHSA-fq38-jp6c-q4cx"
},
{
"name": "VulnCheck Advisory: WWBN AVideo through 29.0 Authentication Bypass via Stored Password Hash",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/wwbn-avideo-through-29.0-authentication-bypass-via-stored-password-hash"
}
],
"title": "WWBN AVideo through 29.0 Authentication Bypass via Stored Password Hash",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-92578",
"datePublished": "2026-09-16T21:46:47.151Z",
"dateReserved": "2026-09-16T13:47:20.117Z",
"dateUpdated": "2026-09-17T14:52:56.526Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-92401 (GCVE-0-2026-92401)
Vulnerability from cvelistv5 – Published: 2026-09-16 16:30 – Updated: 2026-09-16 17:33- CWE-287 - Improper Authentication
| URL | Tags |
|---|---|
| https://vuldb.com/vuln/405552 | vdb-entrytechnical-description |
| https://vuldb.com/vuln/405552/cti | signaturepermissions-required |
| https://vuldb.com/cve/CVE-2026-92401 | third-party-advisory |
| https://vuldb.com/submit/940347 | third-party-advisory |
| https://github.com/ChangeWeDer/crm/issues/2 | issue-tracking |
| https://github.com/ChangeWeDer/crm/ | product |
| Vendor | Product | Version | |
|---|---|---|---|
| ChangeWeDer | crm |
Affected:
c07bd4c97141521af6475034bc58523beed51bbd
cpe:2.3:a:changeweder:crm:*:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-92401",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-16T17:33:21.019648Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-16T17:33:29.701Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:changeweder:crm:*:*:*:*:*:*:*:*"
],
"product": "crm",
"vendor": "ChangeWeDer",
"versions": [
{
"status": "affected",
"version": "c07bd4c97141521af6475034bc58523beed51bbd"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "mjh_123 (VulDB User)"
},
{
"lang": "en",
"type": "coordinator",
"value": "VulDB CNA Team"
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability was identified in ChangeWeDer crm up to c07bd4c97141521af6475034bc58523beed51bbd. This vulnerability affects the function top.upstudy.crm.utils.LoginUserUtil.releaseUserIdFromCookie. The manipulation leads to improper authentication. The attack can be initiated remotely. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 6.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X",
"version": "4.0"
}
},
{
"cvssV3_1": {
"baseScore": 7.3,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 7.3,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 7.5,
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:ND/RL:ND/RC:UR",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-287",
"description": "Improper Authentication",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-16T16:30:07.965Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"name": "VDB-405552 | ChangeWeDer crm improper authentication",
"tags": [
"vdb-entry",
"technical-description"
],
"url": "https://vuldb.com/vuln/405552"
},
{
"name": "VDB-405552 | CTI Indicators (IOB, IOC, IOA)",
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/vuln/405552/cti"
},
{
"name": "CVE-2026-92401 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/cve/CVE-2026-92401"
},
{
"name": "Submit #940347 | ChangeWeDer crm \u2014 CRM Customer Management System 0.0.1-SNAPSHOT Authentication Bypass Issues",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/940347"
},
{
"tags": [
"issue-tracking"
],
"url": "https://github.com/ChangeWeDer/crm/issues/2"
},
{
"tags": [
"product"
],
"url": "https://github.com/ChangeWeDer/crm/"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-09-16T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2026-09-16T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2026-09-16T10:55:59.000Z",
"value": "VulDB entry last update"
}
],
"title": "ChangeWeDer crm improper authentication",
"x_generator": [
"VulDB PVTS v202609"
]
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2026-92401",
"datePublished": "2026-09-16T16:30:07.965Z",
"dateReserved": "2026-09-16T08:50:50.212Z",
"dateUpdated": "2026-09-16T17:33:29.701Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-92227 (GCVE-0-2026-92227)
Vulnerability from cvelistv5 – Published: 2026-09-29 16:36 – Updated: 2026-09-30 16:21- CWE-287 - Improper Authentication
| URL | Tags |
|---|---|
| https://www.joomla.org/ | product |
| https://developer.joomla.org/security-centre/1094… | vendor-advisory |
| Vendor | Product | Version | |
|---|---|---|---|
| Joomla! Project | Joomla! CMS |
Affected:
4.0.0-5.4.8
Affected: 6.0.0-6.1.3 |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-92227",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-30T15:11:21.654808Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T15:28:18.127Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Joomla! CMS",
"vendor": "Joomla! Project",
"versions": [
{
"status": "affected",
"version": "4.0.0-5.4.8"
},
{
"status": "affected",
"version": "6.0.0-6.1.3"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Google and Ada Logics"
},
{
"lang": "en",
"type": "finder",
"value": "Mukul Goyal, Parameter.ai"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "Joomla! Core - [20260914] - Core - MFA Authentication Bypass through rememberme cookies in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - The premature issuance of an rememberme cookie leads to a MFA bypass vulnerability."
}
],
"value": "Joomla! Core - [20260914] - Core - MFA Authentication Bypass through rememberme cookies in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - The premature issuance of an rememberme cookie leads to a MFA bypass vulnerability."
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"attackVector": "NETWORK",
"baseScore": 8.2,
"baseSeverity": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-287",
"description": "CWE-287 Improper Authentication",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T16:21:13.592Z",
"orgId": "6ff30186-7fb7-4ad9-be33-533e7b05e586",
"shortName": "Joomla"
},
"references": [
{
"tags": [
"product"
],
"url": "https://www.joomla.org/"
},
{
"tags": [
"vendor-advisory"
],
"url": "https://developer.joomla.org/security-centre/1094-20260914-core-mfa-authentication-bypass-through-rememberme-cookies.html"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "Joomla! Core - [20260914] - Core - MFA Authentication Bypass through rememberme cookies in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3",
"x_generator": {
"engine": "Vulnogram 0.1.0-dev"
}
}
},
"cveMetadata": {
"assignerOrgId": "6ff30186-7fb7-4ad9-be33-533e7b05e586",
"assignerShortName": "Joomla",
"cveId": "CVE-2026-92227",
"datePublished": "2026-09-29T16:36:45.747Z",
"dateReserved": "2026-09-15T18:55:02.652Z",
"dateUpdated": "2026-09-30T16:21:13.592Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-91002 (GCVE-0-2026-91002)
Vulnerability from cvelistv5 – Published: 2026-09-15 05:30 – Updated: 2026-09-15 13:53 X_Open Source| URL | Tags |
|---|---|
| https://vuldb.com/vuln/403583 | vdb-entrytechnical-description |
| https://vuldb.com/vuln/403583/cti | signaturepermissions-required |
| https://vuldb.com/cve/CVE-2026-91002 | third-party-advisory |
| https://vuldb.com/submit/931699 | third-party-advisory |
| https://gist.github.com/simyat/fd48e9c257ab95405c… | exploit |
| https://github.com/stamparm/maltrail/commit/d9586… | patch |
| https://github.com/stamparm/maltrail/releases/tag/3.1 | patch |
| https://github.com/stamparm/maltrail/ | product |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-91002",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-15T13:47:10.586693Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-15T13:53:57.405Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:stamparm:maltrail:*:*:*:*:*:*:*:*"
],
"modules": [
"Blacklist Endpoint"
],
"product": "maltrail",
"vendor": "stamparm",
"versions": [
{
"status": "affected",
"version": "3.0.0"
},
{
"status": "affected",
"version": "3.0.1"
},
{
"status": "unaffected",
"version": "3.1"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "inmoyang (VulDB User)"
},
{
"lang": "en",
"type": "coordinator",
"value": "VulDB CNA Team"
}
],
"descriptions": [
{
"lang": "en",
"value": "A weakness has been identified in stamparm maltrail up to 3.0.1. This vulnerability affects the function _blacklist of the file core/httpd.py of the component Blacklist Endpoint. Executing a manipulation can lead to missing authentication. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks. Upgrading to version 3.1 is able to resolve this issue. This patch is called d95868dff3da4d3bd4f942837a26cb7c73a797ae. It is suggested to upgrade the affected component. The vendor fixed the issue the same day it was reported, in version 3.1, by gating the endpoint on an authenticated session or the new Blacklist_ALLOWLIST option."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 6.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P",
"version": "4.0"
}
},
{
"cvssV3_1": {
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 5,
"vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N/E:POC/RL:OF/RC:C",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-306",
"description": "Missing Authentication",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-287",
"description": "Improper Authentication",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-15T05:30:16.803Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"name": "VDB-403583 | stamparm maltrail Blacklist Endpoint httpd.py _blacklist missing authentication",
"tags": [
"vdb-entry",
"technical-description"
],
"url": "https://vuldb.com/vuln/403583"
},
{
"name": "VDB-403583 | CTI Indicators (IOB, IOC, IOA)",
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/vuln/403583/cti"
},
{
"name": "CVE-2026-91002 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/cve/CVE-2026-91002"
},
{
"name": "Submit #931699 | Maltrail 3.0.1 Missing Authentication",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/931699"
},
{
"tags": [
"exploit"
],
"url": "https://gist.github.com/simyat/fd48e9c257ab95405c109aec575977f1"
},
{
"tags": [
"patch"
],
"url": "https://github.com/stamparm/maltrail/commit/d95868dff3da4d3bd4f942837a26cb7c73a797ae"
},
{
"tags": [
"patch"
],
"url": "https://github.com/stamparm/maltrail/releases/tag/3.1"
},
{
"tags": [
"product"
],
"url": "https://github.com/stamparm/maltrail/"
}
],
"tags": [
"x_open-source"
],
"timeline": [
{
"lang": "en",
"time": "2026-09-14T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2026-09-14T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2026-09-14T17:43:44.000Z",
"value": "VulDB entry last update"
}
],
"title": "stamparm maltrail Blacklist Endpoint httpd.py _blacklist missing authentication",
"x_generator": [
"VulDB PVTS v202609"
]
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2026-91002",
"datePublished": "2026-09-15T05:30:16.803Z",
"dateReserved": "2026-09-14T15:38:40.042Z",
"dateUpdated": "2026-09-15T13:53:57.405Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-90961 (GCVE-0-2026-90961)
Vulnerability from cvelistv5 – Published: 2026-09-14 13:22 – Updated: 2026-09-14 13:55| URL | Tags |
|---|---|
| https://github.com/MISP/MISP/commit/0ee058548 | patch |
qwen3.8:27b
advisory
bcp-05-x-01bcp-05-x-02
Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.
| Model | Source | Identifier |
|---|---|---|
| qwen3.8:27b | ollama | qwen3.8:27b |
- Generator
-
patch2vuln.pyon 2026-09-14 13:14 - Model
qwen3.8:27b- Input
-
https://github.com/MISP/MISP/commit/0ee058548.patch
01b60b396532… - Confidence
- high
| Commit | Subject | Patch SHA-256 |
|---|---|---|
0ee0585486cd
|
fix: [security] Reject empty and non-string credentials in | 01b60b396532… |
Fix summary
The fix adds explicit type and emptiness validation for the email and password fields in both LdapAuthenticate and LinOTPAuthenticate before any authentication logic is invoked. Non-string or empty credentials are rejected with a logged error and a false return. Additionally, the LDAP authenticator now assigns a cryptographically random password to auto-provisioned user accounts instead of an empty string, preventing the stored hash of '' from being verifiable in the mixed-authentication fallback path. The LinOTP authenticator also rejects an empty password specifically in the mixed-authentication branch where the password is checked against the local database.
Patch summary
In LdapAuthenticate.php: (1) email and password are now extracted with isset() defaults to empty string; (2) a guard clause checks is_string() and non-emptiness for both fields, logging an error and returning false on failure; (3) the auto-provisioned user creation block now calls $userModel->generateRandomPassword() and stores that value in both 'password' and 'confirm_password' fields instead of empty strings. In LinOTPAuthenticate.php: (1) email, password, and otp are extracted with isset() defaults; (2) a guard clause checks is_string() and non-emptiness for email and is_string() for password, logging and returning false on failure; (3) in the mixed-authentication branch, an additional check rejects an empty password before calling _findUser().
CVSS rationale
AV:N: The vulnerability is exploitable over the network via the MISP web login endpoint. AC:L: Exploitation requires only sending a login request with an empty or non-string password field; no race conditions, specific directory configuration beyond accepting unauthenticated binds (which is common), or other special conditions are needed. AT:N: No attack target manipulation is required. PR:N: No prior authentication is needed; the attacker is attempting to authenticate. UI:N: No user interaction is required. VC:H: Successful exploitation grants the attacker the full data-access privileges of the impersonated user, potentially including all MISP threat intelligence data. VI:H: The attacker can create, modify, or delete MISP objects, tags, and configurations at the privilege level of the impersonated user. VA:N: No direct availability impact is demonstrated. SC/SI/SA:N: No separate subsequent system is identified; the impact is contained to the MISP instance itself.
Weakness rationale
- CWE-287 The primary impact is an authentication bypass: empty or non-string credentials allow an unauthenticated attacker to be authenticated as a known directory user. The root cause is the absence of the credential validation guard that FormAuthenticate normally provides.
- CWE-20 The underlying technical weakness is the failure to validate that user-supplied credential fields are non-empty strings before passing them to ldap_bind(), the LinOTP verifier, or _findUser(). Non-string types (null, false, arrays) and empty strings are all accepted and produce unintended authentication behavior.
Assumptions to verify
- The LDAP directory server is configured to accept unauthenticated (empty-password) binds, which is common but not universal; if the directory rejects empty-password binds, the LDAP-specific bypass is mitigated at the directory level, though the non-string credential and empty-password-hash issues remain.
- The attacker must know at least one valid email address that exists in the LDAP directory or MISP user store.
- The LdapAuth or LinOTPAuth plugin is enabled on the affected MISP instance.
- CVSS impact ratings assume the attacker can impersonate a user with high privileges (e.g., admin); actual impact scales with the privileges of the specific user impersonated.
- The exact fixed version is not specified in the patch metadata; the fix commit is 238 commits after tag v2.5.46, suggesting the fix landed in a release after 2.5.46, but the precise version boundary is unconfirmed.
- The LinOTP empty-password bypass in the mixed-auth branch requires the mixedauth setting to be enabled.
Model comparison
Selected qwen3.8:27b
by deterministic-consensus-v1
The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required.
| Model | Score | Agreement | Confidence | Assumptions |
|---|---|---|---|---|
qwen3.8:27b |
5 | 9 | high | 6 |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-90961",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-14T13:55:28.674675Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-14T13:55:49.225Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"modules": [
"LdapAuth plugin (app/Plugin/LdapAuth/Controller/Component/Auth/LdapAuthenticate.php)",
"LinOTPAuth plugin (app/Plugin/LinOTPAuth/Controller/Component/Auth/LinOTPAuthenticate.php)"
],
"product": "MISP",
"programFiles": [
"app/Plugin/LdapAuth/Controller/Component/Auth/LdapAuthenticate.php",
"app/Plugin/LinOTPAuth/Controller/Component/Auth/LinOTPAuthenticate.php"
],
"repo": "https://github.com/MISP/MISP",
"vendor": "MISP",
"versions": [
{
"lessThan": "2.5.46",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "elhoim (David Andr\u00e9)"
},
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Claude Opus 5 (1M context)"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eThe LdapAuth and LinOTPAuth authentication plugins in MISP contain an authentication bypass vulnerability. Both LdapAuthenticate and LinOTPAuthenticate replace CakePHP\u0027s FormAuthenticate class but fail to replicate its _checkFields() input validation guard. As a result, the email and password fields extracted from the login request are passed to downstream authentication logic without verifying that they are non-empty strings.\u003c/p\u003e\u003cp\u003eIn the LDAP authenticator, an empty or null password is forwarded to ldap_bind(). Per RFC 4513 section 5.1.2, a bind request with a valid DN and an empty password constitutes an unauthenticated bind, which many LDAP directory servers accept as successful. An attacker who knows any valid user email address in the directory can therefore authenticate as that user without possessing a password. Additionally, non-string values (null, false, arrays) are either coerced to empty strings by ldap_bind(), raise TypeErrors, or are misinterpreted as find conditions in _findUser(), all of which can lead to unintended authentication outcomes.\u003c/p\u003e\u003cp\u003eIn the LinOTP authenticator, the same missing guard allows non-string credentials to be concatenated into the LinOTP verification request, and in the mixed-authentication branch an empty password is accepted against a stored hash of the empty string.\u003c/p\u003e\u003cp\u003eA secondary issue in the LDAP authenticator is that newly created user accounts (auto-provisioned on first LDAP login) were assigned an empty password. Because the save path skips validation, the empty string is hashed and stored. If the user later ceases to be found in LDAP and the mixed-authentication fallback is used, the stored hash of the empty string verifies against an empty password, again permitting unauthenticated access.\u003c/p\u003e\u003cp\u003eThe vulnerability requires that the affected plugin (LdapAuth or LinOTPAuth) is enabled on the MISP instance and that the attacker knows at least one valid email address registered in the directory or MISP user store. No prior authentication is required. Successful exploitation grants the attacker the full privileges of the impersonated user, which may include administrative access to threat intelligence data.\u003cbr\u003e\u003c/p\u003e\u003cp\u003eVersion affected: \u22642.5.45\u003cbr\u003e\u003c/p\u003e"
}
],
"value": "The LdapAuth and LinOTPAuth authentication plugins in MISP contain an authentication bypass vulnerability. Both LdapAuthenticate and LinOTPAuthenticate replace CakePHP\u0027s FormAuthenticate class but fail to replicate its _checkFields() input validation guard. As a result, the email and password fields extracted from the login request are passed to downstream authentication logic without verifying that they are non-empty strings.\n\nIn the LDAP authenticator, an empty or null password is forwarded to ldap_bind(). Per RFC 4513 section 5.1.2, a bind request with a valid DN and an empty password constitutes an unauthenticated bind, which many LDAP directory servers accept as successful. An attacker who knows any valid user email address in the directory can therefore authenticate as that user without possessing a password. Additionally, non-string values (null, false, arrays) are either coerced to empty strings by ldap_bind(), raise TypeErrors, or are misinterpreted as find conditions in _findUser(), all of which can lead to unintended authentication outcomes.\n\nIn the LinOTP authenticator, the same missing guard allows non-string credentials to be concatenated into the LinOTP verification request, and in the mixed-authentication branch an empty password is accepted against a stored hash of the empty string.\n\nA secondary issue in the LDAP authenticator is that newly created user accounts (auto-provisioned on first LDAP login) were assigned an empty password. Because the save path skips validation, the empty string is hashed and stored. If the user later ceases to be found in LDAP and the mixed-authentication fallback is used, the stored hash of the empty string verifies against an empty password, again permitting unauthenticated access.\n\nThe vulnerability requires that the affected plugin (LdapAuth or LinOTPAuth) is enabled on the MISP instance and that the attacker knows at least one valid email address registered in the directory or MISP user store. No prior authentication is required. Successful exploitation grants the attacker the full privileges of the impersonated user, which may include administrative access to threat intelligence data.\n\n\nVersion affected: \u22642.5.45"
}
],
"impacts": [
{
"capecId": "CAPEC-115",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-115 Authentication Bypass"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 9.3,
"baseSeverity": "CRITICAL",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "LOW",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-287",
"description": "CWE-287 Improper Authentication",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-20",
"description": "CWE-20 Improper Input Validation",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-14T13:22:07.185Z",
"orgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"shortName": "CIRCL"
},
"references": [
{
"name": "Security patch",
"tags": [
"patch"
],
"url": "https://github.com/MISP/MISP/commit/0ee058548"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eThe fix adds explicit type and emptiness validation for the email and password fields in both LdapAuthenticate and LinOTPAuthenticate before any authentication logic is invoked. Non-string or empty credentials are rejected with a logged error and a false return. Additionally, the LDAP authenticator now assigns a cryptographically random password to auto-provisioned user accounts instead of an empty string, preventing the stored hash of \u0027\u0027 from being verifiable in the mixed-authentication fallback path. The LinOTP authenticator also rejects an empty password specifically in the mixed-authentication branch where the password is checked against the local database.\u003c/p\u003e"
}
],
"value": "The fix adds explicit type and emptiness validation for the email and password fields in both LdapAuthenticate and LinOTPAuthenticate before any authentication logic is invoked. Non-string or empty credentials are rejected with a logged error and a false return. Additionally, the LDAP authenticator now assigns a cryptographically random password to auto-provisioned user accounts instead of an empty string, preventing the stored hash of \u0027\u0027 from being verifiable in the mixed-authentication fallback path. The LinOTP authenticator also rejects an empty password specifically in the mixed-authentication branch where the password is checked against the local database."
}
],
"title": "MISP LdapAuth and LinOTPAuth Authentication Bypass via Empty or Non-String Credentials",
"x_gcve": [
{
"extensions": {
"bcp-05-x-01": {
"ai_annotations": [
{
"ai_level": "generated",
"description": "Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.",
"gna_source": 1,
"models": [
{
"gna_source": 1,
"identifier": "qwen3.8:27b",
"name": "qwen3.8:27b",
"source": "ollama"
}
],
"review_status": "review",
"scope": "record",
"tags": [
"ai-computer-assisted:llm-generated",
"ai-computer-assisted:classification"
]
}
]
},
"bcp-05-x-02": {
"x_patch2vuln": {
"assumptions": [
"The LDAP directory server is configured to accept unauthenticated (empty-password) binds, which is common but not universal; if the directory rejects empty-password binds, the LDAP-specific bypass is mitigated at the directory level, though the non-string credential and empty-password-hash issues remain.",
"The attacker must know at least one valid email address that exists in the LDAP directory or MISP user store.",
"The LdapAuth or LinOTPAuth plugin is enabled on the affected MISP instance.",
"CVSS impact ratings assume the attacker can impersonate a user with high privileges (e.g., admin); actual impact scales with the privileges of the specific user impersonated.",
"The exact fixed version is not specified in the patch metadata; the fix commit is 238 commits after tag v2.5.46, suggesting the fix landed in a release after 2.5.46, but the precise version boundary is unconfirmed.",
"The LinOTP empty-password bypass in the mixed-auth branch requires the mixedauth setting to be enabled."
],
"commit": "0ee0585486cd2c9df49e4f14d48a32a953666e3a",
"confidence": "high",
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "elhoim (David Andr\u00e9)"
},
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Claude Opus 5 (1M context)"
}
],
"cvssRationale": "AV:N: The vulnerability is exploitable over the network via the MISP web login endpoint. AC:L: Exploitation requires only sending a login request with an empty or non-string password field; no race conditions, specific directory configuration beyond accepting unauthenticated binds (which is common), or other special conditions are needed. AT:N: No attack target manipulation is required. PR:N: No prior authentication is needed; the attacker is attempting to authenticate. UI:N: No user interaction is required. VC:H: Successful exploitation grants the attacker the full data-access privileges of the impersonated user, potentially including all MISP threat intelligence data. VI:H: The attacker can create, modify, or delete MISP objects, tags, and configurations at the privilege level of the impersonated user. VA:N: No direct availability impact is demonstrated. SC/SI/SA:N: No separate subsequent system is identified; the impact is contained to the MISP instance itself.",
"draft": false,
"fixSummary": "The fix adds explicit type and emptiness validation for the email and password fields in both LdapAuthenticate and LinOTPAuthenticate before any authentication logic is invoked. Non-string or empty credentials are rejected with a logged error and a false return. Additionally, the LDAP authenticator now assigns a cryptographically random password to auto-provisioned user accounts instead of an empty string, preventing the stored hash of \u0027\u0027 from being verifiable in the mixed-authentication fallback path. The LinOTP authenticator also rejects an empty password specifically in the mixed-authentication branch where the password is checked against the local database.",
"generatedAt": "2026-09-14T13:14:35.161935Z",
"generator": "patch2vuln.py",
"model": "qwen3.8:27b",
"modelComparison": {
"rankings": [
{
"agreementScore": 9,
"assumptionCount": 6,
"confidence": "high",
"model": "qwen3.8:27b",
"score": 5
}
],
"selectedModel": "qwen3.8:27b",
"selectionMethod": "deterministic-consensus-v1",
"selectionNotice": "The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required."
},
"patchSha256": "01b60b396532e5f6ff5efca8c41961e701b7b6c539edcf49ad29aba06a906149",
"patchSummary": "In LdapAuthenticate.php: (1) email and password are now extracted with isset() defaults to empty string; (2) a guard clause checks is_string() and non-emptiness for both fields, logging an error and returning false on failure; (3) the auto-provisioned user creation block now calls $userModel-\u003egenerateRandomPassword() and stores that value in both \u0027password\u0027 and \u0027confirm_password\u0027 fields instead of empty strings. In LinOTPAuthenticate.php: (1) email, password, and otp are extracted with isset() defaults; (2) a guard clause checks is_string() and non-emptiness for email and is_string() for password, logging and returning false on failure; (3) in the mixed-authentication branch, an additional check rejects an empty password before calling _findUser().",
"patchTruncated": false,
"patches": [
{
"commit": "0ee0585486cd2c9df49e4f14d48a32a953666e3a",
"patchSha256": "01b60b396532e5f6ff5efca8c41961e701b7b6c539edcf49ad29aba06a906149",
"source": "https://github.com/MISP/MISP/commit/0ee058548.patch",
"sourceUrl": "https://github.com/MISP/MISP/commit/0ee058548.patch",
"subject": "fix: [security] Reject empty and non-string credentials in"
}
],
"source": "https://github.com/MISP/MISP/commit/0ee058548.patch",
"subject": "fix: [security] Reject empty and non-string credentials in",
"tagVersionBoundary": {
"commits_after_fix": 238,
"repository": "https://github.com/MISP/MISP",
"tag": "v2.5.46",
"version": "2.5.46",
"version_type": "semver"
},
"weaknessRationale": [
{
"cweId": "CWE-287",
"rationale": "The primary impact is an authentication bypass: empty or non-string credentials allow an unauthenticated attacker to be authenticated as a known directory user. The root cause is the absence of the credential validation guard that FormAuthenticate normally provides."
},
{
"cweId": "CWE-20",
"rationale": "The underlying technical weakness is the failure to validate that user-supplied credential fields are non-empty strings before passing them to ldap_bind(), the LinOTP verifier, or _findUser(). Non-string types (null, false, arrays) and empty strings are all accepted and produce unintended authentication behavior."
}
]
}
}
},
"recordType": "advisory",
"vulnId": "GCVE-1-2026-20246"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"assignerShortName": "CIRCL",
"cveId": "CVE-2026-90961",
"datePublished": "2026-09-14T13:22:07.185Z",
"dateReserved": "2026-09-14T13:22:04.165Z",
"dateUpdated": "2026-09-14T13:55:49.225Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-90840 (GCVE-0-2026-90840)
Vulnerability from cvelistv5 – Published: 2026-09-14 23:15 – Updated: 2026-09-15 13:54 X_Freeware- CWE-287 - Improper Authentication
| URL | Tags |
|---|---|
| https://vuldb.com/vuln/403392 | vdb-entrytechnical-description |
| https://vuldb.com/vuln/403392/cti | signaturepermissions-required |
| https://vuldb.com/cve/CVE-2026-90840 | third-party-advisory |
| https://vuldb.com/submit/925615 | third-party-advisory |
| https://github.com/usernamevnq/CVEs/issues/1 | exploitissue-tracking |
| https://phpgurukul.com/ | product |
| Vendor | Product | Version | |
|---|---|---|---|
| PHPGurukul | Blood Donor Management System |
Affected:
1.0
cpe:2.3:a:phpgurukul:blood_donor_management_system:*:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-90840",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-15T13:47:16.490017Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-15T13:54:52.393Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:phpgurukul:blood_donor_management_system:*:*:*:*:*:*:*:*"
],
"modules": [
"Admin Controllers"
],
"product": "Blood Donor Management System",
"vendor": "PHPGurukul",
"versions": [
{
"status": "affected",
"version": "1.0"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "n4k3r0 (VulDB User)"
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability was identified in PHPGurukul Blood Donor Management System 1.0. Affected is the function __construct of the file /application/controllers/admin/Dashboard.php of the component Admin Controllers. The manipulation leads to improper authentication. The attack can be initiated remotely. The exploit is publicly available and might be used."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 6.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P",
"version": "4.0"
}
},
{
"cvssV3_1": {
"baseScore": 7.3,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 7.3,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 7.5,
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-287",
"description": "Improper Authentication",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-14T23:15:08.456Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"name": "VDB-403392 | PHPGurukul Blood Donor Management System Admin Controllers Dashboard.php __construct improper authentication",
"tags": [
"vdb-entry",
"technical-description"
],
"url": "https://vuldb.com/vuln/403392"
},
{
"name": "VDB-403392 | CTI Indicators (IOB, IOC, IOA)",
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/vuln/403392/cti"
},
{
"name": "CVE-2026-90840 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/cve/CVE-2026-90840"
},
{
"name": "Submit #925615 | PHPGurukul Blood Donor Management System Using CodeIgniter 1.0 Improper Authentication",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/925615"
},
{
"tags": [
"exploit",
"issue-tracking"
],
"url": "https://github.com/usernamevnq/CVEs/issues/1"
},
{
"tags": [
"product"
],
"url": "https://phpgurukul.com/"
}
],
"tags": [
"x_freeware"
],
"timeline": [
{
"lang": "en",
"time": "2026-09-14T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2026-09-14T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2026-09-14T07:08:50.000Z",
"value": "VulDB entry last update"
}
],
"title": "PHPGurukul Blood Donor Management System Admin Controllers Dashboard.php __construct improper authentication",
"x_generator": [
"VulDB PVTS v202609"
]
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2026-90840",
"datePublished": "2026-09-14T23:15:08.456Z",
"dateReserved": "2026-09-14T05:03:31.492Z",
"dateUpdated": "2026-09-15T13:54:52.393Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-90623 (GCVE-0-2026-90623)
Vulnerability from cvelistv5 – Published: 2026-09-14 03:45 – Updated: 2026-09-14 15:48| URL | Tags |
|---|---|
| https://vuldb.com/vuln/403205 | vdb-entrytechnical-description |
| https://vuldb.com/vuln/403205/cti | signaturepermissions-required |
| https://vuldb.com/cve/CVE-2026-90623 | third-party-advisory |
| https://vuldb.com/submit/914815 | third-party-advisory |
| https://github.com/andreashappe/cochise/issues/13 | exploitissue-tracking |
| https://github.com/andreashappe/cochise/ | product |
| Vendor | Product | Version | |
|---|---|---|---|
| andreashappe | cochise |
Affected:
0.4.0
Affected: 0.4.1 cpe:2.3:a:andreashappe:cochise:*:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-90623",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-14T15:48:25.626549Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-14T15:48:49.067Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:andreashappe:cochise:*:*:*:*:*:*:*:*"
],
"modules": [
"SSH Host Key Handler"
],
"product": "cochise",
"vendor": "andreashappe",
"versions": [
{
"status": "affected",
"version": "0.4.0"
},
{
"status": "affected",
"version": "0.4.1"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "ez-lbz (VulDB User)"
},
{
"lang": "en",
"type": "coordinator",
"value": "VulDB CNA Team"
}
],
"descriptions": [
{
"lang": "en",
"value": "A weakness has been identified in andreashappe cochise up to 0.4.1. Affected is the function asyncssh.connect of the file src/cochise/ssh_connection.py of the component SSH Host Key Handler. Executing a manipulation can lead to improper certificate validation. The attack may be launched remotely. The attack requires a high level of complexity. The exploitability is told to be difficult. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 6.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P",
"version": "4.0"
}
},
{
"cvssV3_1": {
"baseScore": 3.7,
"baseSeverity": "LOW",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 3.7,
"baseSeverity": "LOW",
"vectorString": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 2.6,
"vectorString": "AV:N/AC:H/Au:N/C:N/I:P/A:N/E:POC/RL:ND/RC:UR",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-295",
"description": "Improper Certificate Validation",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-287",
"description": "Improper Authentication",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-14T03:45:13.120Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"name": "VDB-403205 | andreashappe cochise SSH Host Key ssh_connection.py asyncssh.connect certificate validation",
"tags": [
"vdb-entry",
"technical-description"
],
"url": "https://vuldb.com/vuln/403205"
},
{
"name": "VDB-403205 | CTI Indicators (IOB, IOC, TTP, IOA)",
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/vuln/403205/cti"
},
{
"name": "CVE-2026-90623 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/cve/CVE-2026-90623"
},
{
"name": "Submit #914815 | andreashappe cochise v0.4.1 RCE",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/914815"
},
{
"tags": [
"exploit",
"issue-tracking"
],
"url": "https://github.com/andreashappe/cochise/issues/13"
},
{
"tags": [
"product"
],
"url": "https://github.com/andreashappe/cochise/"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-09-12T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2026-09-12T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2026-09-12T22:35:26.000Z",
"value": "VulDB entry last update"
}
],
"title": "andreashappe cochise SSH Host Key ssh_connection.py asyncssh.connect certificate validation",
"x_generator": [
"VulDB PVTS v202609"
]
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2026-90623",
"datePublished": "2026-09-14T03:45:13.120Z",
"dateReserved": "2026-09-12T20:30:21.642Z",
"dateUpdated": "2026-09-14T15:48:49.067Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-90620 (GCVE-0-2026-90620)
Vulnerability from cvelistv5 – Published: 2026-09-14 03:00 – Updated: 2026-09-14 14:59| URL | Tags |
|---|---|
| https://vuldb.com/vuln/403202 | vdb-entry |
| https://vuldb.com/vuln/403202/cti | signaturepermissions-required |
| https://vuldb.com/cve/CVE-2026-90620 | third-party-advisory |
| https://vuldb.com/submit/914813 | third-party-advisory |
| https://github.com/0x4m4/hexstrike-ai/issues/223 | exploitissue-tracking |
| Vendor | Product | Version | |
|---|---|---|---|
| 0x4m4 | HexStrike AI |
Affected:
d689933ff579d839c676c82b231f8e98326c5f04
cpe:2.3:a:0x4m4:hexstrike_ai:*:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-90620",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-14T14:59:27.417179Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-14T14:59:40.285Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:0x4m4:hexstrike_ai:*:*:*:*:*:*:*:*"
],
"modules": [
"API Command Endpoint"
],
"product": "HexStrike AI",
"vendor": "0x4m4",
"versions": [
{
"status": "affected",
"version": "d689933ff579d839c676c82b231f8e98326c5f04"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "ez-lbz (VulDB User)"
},
{
"lang": "en",
"type": "coordinator",
"value": "VulDB CNA Team"
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability was determined in 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04. The impacted element is an unknown function of the file hexstrike_server.py of the component API Command Endpoint. This manipulation causes missing authentication. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 6.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P",
"version": "4.0"
}
},
{
"cvssV3_1": {
"baseScore": 7.3,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 7.3,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 7.5,
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-306",
"description": "Missing Authentication",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-287",
"description": "Improper Authentication",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-14T03:00:11.752Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"name": "VDB-403202 | 0x4m4 HexStrike AI API Command Endpoint hexstrike_server.py missing authentication",
"tags": [
"vdb-entry"
],
"url": "https://vuldb.com/vuln/403202"
},
{
"name": "VDB-403202 | CTI Indicators (IOB, IOC, IOA)",
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/vuln/403202/cti"
},
{
"name": "CVE-2026-90620 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/cve/CVE-2026-90620"
},
{
"name": "Submit #914813 | 0x4m4 hexstrike-ai v1.0 rce",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/914813"
},
{
"tags": [
"exploit",
"issue-tracking"
],
"url": "https://github.com/0x4m4/hexstrike-ai/issues/223"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-09-12T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2026-09-12T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2026-09-12T22:24:35.000Z",
"value": "VulDB entry last update"
}
],
"title": "0x4m4 HexStrike AI API Command Endpoint hexstrike_server.py missing authentication",
"x_generator": [
"VulDB PVTS v202609"
]
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2026-90620",
"datePublished": "2026-09-14T03:00:11.752Z",
"dateReserved": "2026-09-12T20:17:19.176Z",
"dateUpdated": "2026-09-14T14:59:40.285Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
Mitigation
Strategy: Libraries or Frameworks
Use an authentication framework or library such as the OWASP ESAPI Authentication feature.
CAPEC-114: Authentication Abuse
An attacker obtains unauthorized access to an application, service or device either through knowledge of the inherent weaknesses of an authentication mechanism, or by exploiting a flaw in the authentication scheme's implementation. In such an attack an authentication mechanism is functioning but a carefully controlled sequence of events causes the mechanism to grant access to the attacker.
CAPEC-115: Authentication Bypass
An attacker gains access to application, service, or device with the privileges of an authorized or privileged user by evading or circumventing an authentication mechanism. The attacker is therefore able to access protected data without authentication ever having taken place.
CAPEC-151: Identity Spoofing
Identity Spoofing refers to the action of assuming (i.e., taking on) the identity of some other entity (human or non-human) and then using that identity to accomplish a goal. An adversary may craft messages that appear to come from a different principle or use stolen / spoofed authentication credentials.
CAPEC-194: Fake the Source of Data
An adversary takes advantage of improper authentication to provide data or services under a falsified identity. The purpose of using the falsified identity may be to prevent traceability of the provided data or to assume the rights granted to another individual. One of the simplest forms of this attack would be the creation of an email message with a modified "From" field in order to appear that the message was sent from someone other than the actual sender. The root of the attack (in this case the email system) fails to properly authenticate the source and this results in the reader incorrectly performing the instructed action. Results of the attack vary depending on the details of the attack, but common results include privilege escalation, obfuscation of other attacks, and data corruption/manipulation.
CAPEC-22: Exploiting Trust in Client
An attack of this type exploits vulnerabilities in client/server communication channel authentication and data integrity. It leverages the implicit trust a server places in the client, or more importantly, that which the server believes is the client. An attacker executes this type of attack by communicating directly with the server where the server believes it is communicating only with a valid client. There are numerous variations of this type of attack.
CAPEC-57: Utilizing REST's Trust in the System Resource to Obtain Sensitive Data
This attack utilizes a REST(REpresentational State Transfer)-style applications' trust in the system resources and environment to obtain sensitive data once SSL is terminated.
CAPEC-593: Session Hijacking
This type of attack involves an adversary that exploits weaknesses in an application's use of sessions in performing authentication. The adversary is able to steal or manipulate an active session and use it to gain unathorized access to the application.
CAPEC-633: Token Impersonation
An adversary exploits a weakness in authentication to create an access token (or equivalent) that impersonates a different entity, and then associates a process/thread to that that impersonated token. This action causes a downstream user to make a decision or take action that is based on the assumed identity, and not the response that blocks the adversary.
CAPEC-650: Upload a Web Shell to a Web Server
By exploiting insufficient permissions, it is possible to upload a web shell to a web server in such a way that it can be executed remotely. This shell can have various capabilities, thereby acting as a "gateway" to the underlying web server. The shell might execute at the higher permission level of the web server, providing the ability the execute malicious code at elevated levels.
CAPEC-94: Adversary in the Middle (AiTM)
An adversary targets the communication between two components (typically client and server), in order to alter or obtain data from transactions. A general approach entails the adversary placing themself within the communication channel between the two components.