CWE-303
AllowedIncorrect Implementation of Authentication Algorithm
Abstraction: Base · Status: Draft
The requirements for the product dictate the use of an established authentication algorithm, but the implementation of the algorithm is incorrect.
186 vulnerabilities reference this CWE, most recent first.
CVE-2026-101878 (GCVE-0-2026-101878)
Vulnerability from cvelistv5 – Published: 2026-09-29 01:58 – Updated: 2026-10-01 19:19 X_Open Source- CWE-303 - Incorrect Implementation of Authentication Algorithm
| URL | Tags |
|---|---|
| https://sanjokkarki.com.np/blog/bitwarden-sso-ext… | technical-descriptionexploit |
| https://github.com/bitwarden/server/releases/tag/… | release-notes |
| https://github.com/bitwarden/server/pull/7501 | issue-tracking |
| https://github.com/bitwarden/server/commit/27ae3d… | patch |
| https://www.vulncheck.com/advisories/bitwarden-se… | third-party-advisory |
| Vendor | Product | Version | |
|---|---|---|---|
| bitwarden | bitwarden server |
Affected:
2025.6.0 , < 2026.5.0
(custom)
cpe:2.3:a:bitwarden:server:*:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-101878",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-29T17:21:45.867113Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-29T17:22:11.133Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:github/bitwarden/server",
"product": "bitwarden server",
"repo": "https://github.com/bitwarden/server",
"vendor": "bitwarden",
"versions": [
{
"lessThan": "2026.5.0",
"status": "affected",
"version": "2025.6.0",
"versionType": "custom"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:bitwarden:server:*:*:*:*:*:*:*:*",
"versionEndExcluding": "2026.5.0",
"versionStartIncluding": "2025.6.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Sanjok Karki"
}
],
"datePublic": "2026-04-29T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Bitwarden Server 2025.6.0 before 2026.5.0 declares the @ExternalId parameter of the User_ReadBySsoUserOrganizationIdExternalId stored procedure as NVARCHAR(50) while the column it queries stores NVARCHAR(300), silently truncating the SSO login identifier on SQL Server deployments and allowing a user whose identity-provider identifier begins with another organization member\u0027s full 50-character identifier to authenticate as that member and obtain a victim-scoped access token."
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "HIGH",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 7.7,
"baseSeverity": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "LOW",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
},
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 7.5,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-303",
"description": "Incorrect Implementation of Authentication Algorithm",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T19:19:18.222Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "Researcher Blog",
"tags": [
"technical-description",
"exploit"
],
"url": "https://sanjokkarki.com.np/blog/bitwarden-sso-externalid-truncation"
},
{
"name": "Release Notes",
"tags": [
"release-notes"
],
"url": "https://github.com/bitwarden/server/releases/tag/v2026.5.0"
},
{
"name": "Pull Request",
"tags": [
"issue-tracking"
],
"url": "https://github.com/bitwarden/server/pull/7501"
},
{
"name": "Patch Commit",
"tags": [
"patch"
],
"url": "https://github.com/bitwarden/server/commit/27ae3d5455f723975fac03819eaeba8710666bc4"
},
{
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/bitwarden-server-authentication-bypass-via-sso-identifier-truncation"
}
],
"source": {
"discovery": "UNKNOWN"
},
"tags": [
"x_open-source"
],
"title": "Bitwarden Server 2025.6.0 \u003c 2025.6.0 Authentication Bypass via SSO Identifier Truncation",
"x_generator": {
"engine": "vulncheck"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-101878",
"datePublished": "2026-09-29T01:58:32.484Z",
"dateReserved": "2026-09-28T15:44:45.389Z",
"dateUpdated": "2026-10-01T19:19:18.222Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-93394 (GCVE-0-2026-93394)
Vulnerability from cvelistv5 – Published: 2026-09-17 20:31 – Updated: 2026-09-18 14:31- CWE-303 - Incorrect Implementation of Authentication Algorithm
| Vendor | Product | Version | |
|---|---|---|---|
| MongoDB Inc. | C Driver |
Affected:
2.0.0 , < 2.3.2
(semver)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-93394",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-18T14:27:52.100964Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-18T14:31:41.209Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "C Driver",
"vendor": "MongoDB Inc.",
"versions": [
{
"lessThan": "2.3.2",
"status": "affected",
"version": "2.0.0",
"versionType": "semver"
}
]
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "A flaw in libmongoc\u0027s SCRAM authentication implementation caused the client to continue the authentication handshake and transmit the client proof even when a nonce mismatch was detected in the server\u0027s first message. An unauthorized party with a man-in-the-middle position could exploit this by injecting a crafted server-first-message containing a controlled salt and low iteration count, then capturing the resulting client proof to perform offline password cracking. This vulnerability is mitigated by TLS, which is standard in production deployments."
}
],
"value": "A flaw in libmongoc\u0027s SCRAM authentication implementation caused the client to continue the authentication handshake and transmit the client proof even when a nonce mismatch was detected in the server\u0027s first message. An unauthorized party with a man-in-the-middle position could exploit this by injecting a crafted server-first-message containing a controlled salt and low iteration count, then capturing the resulting client proof to perform offline password cracking. This vulnerability is mitigated by TLS, which is standard in production deployments."
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"attackVector": "NETWORK",
"baseScore": 6.3,
"baseSeverity": "MEDIUM",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "LOW",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
},
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 3.7,
"baseSeverity": "LOW",
"confidentialityImpact": "LOW",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-303",
"description": "CWE-303: Incorrect Implementation of Authentication Algorithm",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-17T20:31:27.875Z",
"orgId": "a39b4221-9bd0-4244-95fc-f3e2e07f1deb",
"shortName": "mongodb"
},
"references": [
{
"url": "https://jira.mongodb.org/browse/CDRIVER-6315"
}
],
"source": {
"discovery": "INTERNAL"
},
"title": "libmongoc SCRAM client nonce-validation bypass",
"x_generator": {
"engine": "Vulnogram 1.0.5"
}
}
},
"cveMetadata": {
"assignerOrgId": "a39b4221-9bd0-4244-95fc-f3e2e07f1deb",
"assignerShortName": "mongodb",
"cveId": "CVE-2026-93394",
"datePublished": "2026-09-17T20:31:27.875Z",
"dateReserved": "2026-09-17T20:11:00.595Z",
"dateUpdated": "2026-09-18T14:31:41.209Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-92873 (GCVE-0-2026-92873)
Vulnerability from cvelistv5 – Published: 2026-09-30 07:51 – Updated: 2026-09-30 16:58- CWE-303 - Incorrect Implementation of Authentication Algorithm
| Vendor | Product | Version | |
|---|---|---|---|
| Pgpool Global Development Group | Pgpool-II |
Affected:
4.7.0 , ≤ 4.7.2
(semver)
Affected: 4.6.0 , ≤ 4.6.7 (semver) Affected: 4.5.0 , ≤ 4.5.12 (semver) Affected: 4.4.0 , ≤ 4.4.17 (semver) Affected: 4.3.0 , ≤ 4.3.20 (semver) Affected: 3.5.x , ≤ 4.2.x (semver) |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-92873",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-30T16:58:11.622461Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T16:58:20.542Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Pgpool-II",
"vendor": "Pgpool Global Development Group",
"versions": [
{
"lessThanOrEqual": "4.7.2",
"status": "affected",
"version": "4.7.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "4.6.7",
"status": "affected",
"version": "4.6.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "4.5.12",
"status": "affected",
"version": "4.5.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "4.4.17",
"status": "affected",
"version": "4.4.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "4.3.20",
"status": "affected",
"version": "4.3.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "4.2.x",
"status": "affected",
"version": "3.5.x",
"versionType": "semver"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Pgpool-II contains an incorrect implementation of an authentication algorithm, which may allow an unauthenticated attacker to promote an arbitrary watchdog node to the leader node."
}
],
"metrics": [
{
"cvssV3_0": {
"baseScore": 7.3,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
"version": "3.0"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en-US",
"value": "GENERAL"
}
]
},
{
"cvssV4_0": {
"baseScore": 6.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N",
"version": "4.0"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en-US",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-303",
"description": "Incorrect Implementation of Authentication Algorithm",
"lang": "en-US",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T07:51:52.401Z",
"orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"shortName": "jpcert"
},
"references": [
{
"url": "https://pgpool.net/news/2026-09-29/"
},
{
"url": "https://jvn.jp/en/jp/JVN22475874/"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"assignerShortName": "jpcert",
"cveId": "CVE-2026-92873",
"datePublished": "2026-09-30T07:51:52.401Z",
"dateReserved": "2026-09-17T06:31:54.745Z",
"dateUpdated": "2026-09-30T16:58:20.542Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-77244 (GCVE-0-2026-77244)
Vulnerability from cvelistv5 – Published: 2026-09-22 17:49 – Updated: 2026-09-23 14:38| URL | Tags |
|---|---|
| https://github.com/sooperset/mcp-atlassian/securi… | x_refsource_CONFIRM |
| https://github.com/sooperset/mcp-atlassian/pull/1448 | x_refsource_MISC |
| https://github.com/sooperset/mcp-atlassian/commit… | x_refsource_MISC |
| https://github.com/sooperset/mcp-atlassian/releas… | x_refsource_MISC |
| Vendor | Product | Version | |
|---|---|---|---|
| sooperset | mcp-atlassian |
Affected:
< 0.22.0
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-77244",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-22T18:55:17.366068Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-23T14:38:20.138Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "mcp-atlassian",
"vendor": "sooperset",
"versions": [
{
"status": "affected",
"version": "\u003c 0.22.0"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the HTTP transport accepts requests without a verified user identity and downstream fetcher construction falls back to the operator\u0027s globally configured Jira or Confluence credentials. A network client that can reach the MCP endpoint can invoke Atlassian tools as the operator, including read and write operations available to that account. The advisory traces the vulnerable input and processing flow through UserTokenMiddleware, AtlassianOpaqueTokenVerifier, _get_fetcher, and streamable-http, which identify the affected entry points, controls, and code paths. This issue is fixed in version 0.22.0."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 10,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "CHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-287",
"description": "CWE-287: Improper Authentication",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-303",
"description": "CWE-303: Incorrect Implementation of Authentication Algorithm",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-862",
"description": "CWE-862: Missing Authorization",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-22T17:49:38.296Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/sooperset/mcp-atlassian/security/advisories/GHSA-wrhw-j3f9-8vc6",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/sooperset/mcp-atlassian/security/advisories/GHSA-wrhw-j3f9-8vc6"
},
{
"name": "https://github.com/sooperset/mcp-atlassian/pull/1448",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/sooperset/mcp-atlassian/pull/1448"
},
{
"name": "https://github.com/sooperset/mcp-atlassian/commit/b041733473f95119dd539542a43c280737a8e460",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/sooperset/mcp-atlassian/commit/b041733473f95119dd539542a43c280737a8e460"
},
{
"name": "https://github.com/sooperset/mcp-atlassian/releases/tag/v0.22.0",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/sooperset/mcp-atlassian/releases/tag/v0.22.0"
}
],
"source": {
"advisory": "GHSA-wrhw-j3f9-8vc6",
"discovery": "UNKNOWN"
},
"title": "[mcp-atlassian] Authentication bypass in HTTP transport: AtlassianOpaqueTokenVerifier accepts any non-empty token"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-77244",
"datePublished": "2026-09-22T17:49:38.296Z",
"dateReserved": "2026-08-20T19:02:23.416Z",
"dateUpdated": "2026-09-23T14:38:20.138Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-73458 (GCVE-0-2026-73458)
Vulnerability from cvelistv5 – Published: 2026-09-15 19:30 – Updated: 2026-09-15 19:38- CWE-303 - Incorrect Implementation of Authentication Algorithm
| URL | Tags |
|---|---|
| https://www.arista.com/en/support/advisories-noti… | vendor-advisory |
| Vendor | Product | Version | |
|---|---|---|---|
| Arista Networks | EOS |
Affected:
4.36.0 , ≤ 4.36.1F
(custom)
Affected: 4.35.0 , ≤ 4.35.5M (custom) Affected: 4.34.0 , ≤ 4.34.7M (custom) Affected: 4.33.0 , ≤ 4.33.8M (custom) |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-73458",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-15T19:38:30.537124Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-15T19:38:38.389Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"platforms": [
"710 Series",
"720D Series",
"720XP/722XPM Series",
"750X Series",
"7010TX Series",
"7020R/R4 Series",
"7130 Series running EOS",
"7170 Series",
"7050X3/X4 Series",
"7060X/X2/X4/X5/X6 Series",
"7260X/X3 Series",
"7280R/R2/R3/R4 Series",
"7300X/X3 Series",
"7320X Series",
"7358X4 Series",
"7368X4 Series",
"7388X5 Series",
"7500R/R2/R3 Series",
"7800R3/R4 Series",
"7700R4 Series",
"AWE 5000 Series",
"AWE 7200R Series",
"CloudEOS",
"cEOS-lab",
"vEOS-lab",
"CloudVision eXchange",
"virtual or physical appliance"
],
"product": "EOS",
"vendor": "Arista Networks",
"versions": [
{
"changes": [
{
"at": "4.36.2F",
"status": "unaffected"
}
],
"lessThanOrEqual": "4.36.1F",
"status": "affected",
"version": "4.36.0",
"versionType": "custom"
},
{
"changes": [
{
"at": "4.35.6M",
"status": "unaffected"
}
],
"lessThanOrEqual": "4.35.5M",
"status": "affected",
"version": "4.35.0",
"versionType": "custom"
},
{
"changes": [
{
"at": "4.34.8M",
"status": "unaffected"
}
],
"lessThanOrEqual": "4.34.7M",
"status": "affected",
"version": "4.34.0",
"versionType": "custom"
},
{
"changes": [
{
"at": "4.33.9M",
"status": "unaffected"
}
],
"lessThanOrEqual": "4.33.8M",
"status": "affected",
"version": "4.33.0",
"versionType": "custom"
}
]
}
],
"configurations": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eIn order to be vulnerable to CVE-2026-73458, the following condition must be met:\u003c/p\u003e\u003cdiv\u003eBFD sessions configured with authentication are affected by this issue. All supported authentication modes are impacted. The full list of authentication modes is below:\u003c/div\u003e\u003cdiv\u003e\u0026nbsp;\u003c/div\u003e\u003cul\u003e\u003cli\u003ePassword\u003c/li\u003e\u003cli\u003eKeyed MD5\u003c/li\u003e\u003cli\u003eMeticulous MD5\u003c/li\u003e\u003cli\u003eKeyed SHA1\u003c/li\u003e\u003cli\u003eMeticulous SHA1\u003c/li\u003e\u003c/ul\u003e\u003cp\u003eTo determine whether your sessions are affected, run the following show command. If the authentication mode is set to anything other than None, your configuration is impacted. In the example below, the authentication mode is set to Password, indicating an affected configuration.\u003c/p\u003e\u003cpre\u003eswitch\u0026gt;show bfd peers detail\nVRF name: default\n-----------------\nPeer Addr 1.0.0.2, Intf Ethernet3/30/3, Type normal, Role active, State Up\nVRF default, LAddr 1.0.0.1, LD/RD 2432996710/3471785639\nSession state is Up and not using echo function\nHardware Acceleration: Async Off, Echo Off\nLast Up 06/04/26 13:55:50.630\nLast Down 06/04/26 13:55:49.725\nLast Diag: No Diagnostic\nAuthentication mode: Password\nShared-secret profile: bfdProfile_0\nTxInt: 500 ms, RxInt: 500 ms, Multiplier: 20\nReceived RxInt: 500 ms, Received Multiplier: 20\nRx Count: 2308, Rx Interval (ms) min/max/avg: 81/538/438 last: 188 ms ago\nTx Count: 2206, Tx Interval (ms) min/max/avg: 380/516/458 last: 476 ms ago\nDetect Time: 10000 ms\nSched Delay: 1*TxInt: 1762, 2*TxInt: 443, 3*TxInt: 0, GT 3*TxInt: 0\nRegistered protocols: bgp\nUptime: 16:51.08\nLast packet:\u0026nbsp; Version: 1 \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; - Diagnostic: 0\n\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;State bit: Up\u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; - Demand bit: 0\n\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;Poll bit: 0\u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; - Final bit: 0\n\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;Multiplier: 20 \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; - Length: 38\n\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;My Discr.: 3471785639\u0026nbsp; - Your Discr.: 2432996710\n\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;Min tx interval: 500 \u0026nbsp; - Min rx interval: 500\n\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;Min Echo interval: 500\n\u003c/pre\u003e\u003cdiv\u003e\u0026nbsp;\u003c/div\u003e\u003cp\u003eIf BFD is not configured, there is no exposure to this issue. The below show command command will return empty output:\u003c/p\u003e\u003cpre\u003eswitch\u0026gt;show running-config section bfd\nswitch\u0026gt;\n\u003c/pre\u003e\u003cdiv\u003e\u0026nbsp;\u003c/div\u003e\u003cp\u003eIf BFD is configured but not operational, there is no exposure to this issue. The below show command will return empty output:\u003c/p\u003e\u003cpre\u003eswitch\u0026gt;show bfd peers detail\nswitch\u0026gt;\n\u003c/pre\u003e\u003cdiv\u003e\u0026nbsp;\u003c/div\u003e\u003cp\u003eIf BFD is configured, and operational but not in authentication mode, there is no exposure to this issue and the output of below show command will look something like:\u003c/p\u003e\u003cpre\u003eswitch\u0026gt;show bfd peers detail\nVRF name: default\n-----------------\nPeer Addr 1.0.0.2, Intf Ethernet3/30/3, Type normal, Role active, State Up\nVRF default, LAddr 1.0.0.1, LD/RD 2432996710/3471785639\nSession state is Up and not using echo function\nHardware Acceleration: Async On, Echo Off\nLast Up 06/04/26 14:15:32.259\nLast Down 06/04/26 14:14:50.328\nLast Diag: No Diagnostic\nAuthentication mode: None\nShared-secret profile: None\nTxInt: 500 ms, RxInt: 500 ms, Multiplier: 20\nReceived RxInt: 500 ms, Received Multiplier: 20\nRx Count: 34, Rx Interval (ms) min/max/avg: 161/496/408 last: 163 ms ago\nTx Count: 29, Tx Interval (ms) min/max/avg: 375/499/440 last: 720 ms ago\nDetect Time: 10000 ms\nSched Delay: 1*TxInt: 76, 2*TxInt: 0, 3*TxInt: 0, GT 3*TxInt: 0\nRegistered protocols: bgp\nUptime: 13.65\nLast packet:\u0026nbsp; Version: 1 \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; - Diagnostic: 0\n\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;State bit: Up\u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; - Demand bit: 0\n\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;Poll bit: 0\u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; - Final bit: 0\n\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;Multiplier: 20 \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; - Length: 24\n\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;My Discr.: 3471785639\u0026nbsp; - Your Discr.: 2432996710\n\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;Min tx interval: 500 \u0026nbsp; - Min rx interval: 500\n\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;Min Echo interval: 500\u003c/pre\u003e"
}
],
"value": "In order to be vulnerable to CVE-2026-73458, the following condition must be met:\n\nBFD sessions configured with authentication are affected by this issue. All supported authentication modes are impacted. The full list of authentication modes is below:\n\n\u00a0\n\n * Password\n * Keyed MD5\n * Meticulous MD5\n * Keyed SHA1\n * Meticulous SHA1\n\n\n\n\nTo determine whether your sessions are affected, run the following show command. If the authentication mode is set to anything other than None, your configuration is impacted. In the example below, the authentication mode is set to Password, indicating an affected configuration.\n\n\n\nswitch\u003eshow bfd peers detail\nVRF name: default\n-----------------\nPeer Addr 1.0.0.2, Intf Ethernet3/30/3, Type normal, Role active, State Up\nVRF default, LAddr 1.0.0.1, LD/RD 2432996710/3471785639\nSession state is Up and not using echo function\nHardware Acceleration: Async Off, Echo Off\nLast Up 06/04/26 13:55:50.630\nLast Down 06/04/26 13:55:49.725\nLast Diag: No Diagnostic\nAuthentication mode: Password\nShared-secret profile: bfdProfile_0\nTxInt: 500 ms, RxInt: 500 ms, Multiplier: 20\nReceived RxInt: 500 ms, Received Multiplier: 20\nRx Count: 2308, Rx Interval (ms) min/max/avg: 81/538/438 last: 188 ms ago\nTx Count: 2206, Tx Interval (ms) min/max/avg: 380/516/458 last: 476 ms ago\nDetect Time: 10000 ms\nSched Delay: 1*TxInt: 1762, 2*TxInt: 443, 3*TxInt: 0, GT 3*TxInt: 0\nRegistered protocols: bgp\nUptime: 16:51.08\nLast packet:\u00a0 Version: 1 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 - Diagnostic: 0\n\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0State bit: Up\u00a0 \u00a0 \u00a0 \u00a0 \u00a0 - Demand bit: 0\n\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0Poll bit: 0\u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 - Final bit: 0\n\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0Multiplier: 20 \u00a0 \u00a0 \u00a0 \u00a0 - Length: 38\n\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0My Discr.: 3471785639\u00a0 - Your Discr.: 2432996710\n\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0Min tx interval: 500 \u00a0 - Min rx interval: 500\n\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0Min Echo interval: 500\n\n\n\u00a0\n\n\n\nIf BFD is not configured, there is no exposure to this issue. The below show command command will return empty output:\n\n\n\nswitch\u003eshow running-config section bfd\nswitch\u003e\n\n\n\u00a0\n\n\n\nIf BFD is configured but not operational, there is no exposure to this issue. The below show command will return empty output:\n\n\n\nswitch\u003eshow bfd peers detail\nswitch\u003e\n\n\n\u00a0\n\n\n\nIf BFD is configured, and operational but not in authentication mode, there is no exposure to this issue and the output of below show command will look something like:\n\n\n\nswitch\u003eshow bfd peers detail\nVRF name: default\n-----------------\nPeer Addr 1.0.0.2, Intf Ethernet3/30/3, Type normal, Role active, State Up\nVRF default, LAddr 1.0.0.1, LD/RD 2432996710/3471785639\nSession state is Up and not using echo function\nHardware Acceleration: Async On, Echo Off\nLast Up 06/04/26 14:15:32.259\nLast Down 06/04/26 14:14:50.328\nLast Diag: No Diagnostic\nAuthentication mode: None\nShared-secret profile: None\nTxInt: 500 ms, RxInt: 500 ms, Multiplier: 20\nReceived RxInt: 500 ms, Received Multiplier: 20\nRx Count: 34, Rx Interval (ms) min/max/avg: 161/496/408 last: 163 ms ago\nTx Count: 29, Tx Interval (ms) min/max/avg: 375/499/440 last: 720 ms ago\nDetect Time: 10000 ms\nSched Delay: 1*TxInt: 76, 2*TxInt: 0, 3*TxInt: 0, GT 3*TxInt: 0\nRegistered protocols: bgp\nUptime: 13.65\nLast packet:\u00a0 Version: 1 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 - Diagnostic: 0\n\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0State bit: Up\u00a0 \u00a0 \u00a0 \u00a0 \u00a0 - Demand bit: 0\n\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0Poll bit: 0\u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 - Final bit: 0\n\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0Multiplier: 20 \u00a0 \u00a0 \u00a0 \u00a0 - Length: 24\n\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0My Discr.: 3471785639\u00a0 - Your Discr.: 2432996710\n\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0Min tx interval: 500 \u00a0 - Min rx interval: 500\n\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0Min Echo interval: 500"
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "This issue was discovered internally by Arista."
}
],
"datePublic": "2026-09-09T19:27:00.000Z",
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eOn affected platforms running Arista EOS with authenticated Bidirectional Forwarding Detection (BFD) sessions configured, a specially crafted packet can cause the BFD session(s) to go down. This may result in undesirable network changes because various routing protocols monitor status on BFD session(s).\u003c/p\u003e"
}
],
"value": "On affected platforms running Arista EOS with authenticated Bidirectional Forwarding Detection (BFD) sessions configured, a specially crafted packet can cause the BFD session(s) to go down. This may result in undesirable network changes because various routing protocols monitor status on BFD session(s)."
}
],
"impacts": [
{
"capecId": "CAPEC-115",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-115 Authentication Bypass"
}
]
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 8.2,
"baseSeverity": "HIGH",
"confidentialityImpact": "NONE",
"integrityImpact": "LOW",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
},
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 9.2,
"baseSeverity": "CRITICAL",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "HIGH",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:H",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "LOW",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-303",
"description": "CWE-303 Incorrect Implementation of Authentication Algorithm",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-15T19:30:16.014Z",
"orgId": "c8b34d1a-69ae-45c3-88fe-f3b3d44f39b7",
"shortName": "Arista"
},
"references": [
{
"tags": [
"vendor-advisory"
],
"url": "https://www.arista.com/en/support/advisories-notices/security-advisory/24710-security-advisory-0154"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eThe recommended resolution is to upgrade to a remediated software version at your earliest convenience. CVE-2026-73458 has been fixed in the following releases:\u003c/p\u003e\u003cul\u003e\u003cli\u003e4.36.2F and later releases in the 4.36.x train\u003c/li\u003e\u003cli\u003e4.35.6M and later releases in the 4.35.x train\u003c/li\u003e\u003cli\u003e4.34.8M and later releases in the 4.34.x train\u003c/li\u003e\u003cli\u003e4.33.9M and later releases in the 4.33.x train\u003c/li\u003e\u003c/ul\u003e"
}
],
"value": "The recommended resolution is to upgrade to a remediated software version at your earliest convenience. CVE-2026-73458 has been fixed in the following releases:\n\n * 4.36.2F and later releases in the 4.36.x train\n * 4.35.6M and later releases in the 4.35.x train\n * 4.34.8M and later releases in the 4.34.x train\n * 4.33.9M and later releases in the 4.33.x train"
}
],
"source": {
"advisory": "154",
"defect": [
"1787150"
],
"discovery": "INTERNAL"
},
"title": "On affected platforms running Arista EOS with authenticated Bidirectional Forwarding Detection (BFD) sessions configured, a specially crafted packet can cause the BFD session(s) to go down. This may result in undesirable network changes because various rou",
"workarounds": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eNo mitigation is available for this issue.\u003c/p\u003e"
}
],
"value": "No mitigation is available for this issue."
}
],
"x_generator": {
"engine": "Vulnogram 1.0.5"
}
}
},
"cveMetadata": {
"assignerOrgId": "c8b34d1a-69ae-45c3-88fe-f3b3d44f39b7",
"assignerShortName": "Arista",
"cveId": "CVE-2026-73458",
"datePublished": "2026-09-15T19:30:16.014Z",
"dateReserved": "2026-08-12T16:45:03.510Z",
"dateUpdated": "2026-09-15T19:38:38.389Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-73444 (GCVE-0-2026-73444)
Vulnerability from cvelistv5 – Published: 2026-09-15 21:11 – Updated: 2026-09-16 18:04- CWE-303 - Incorrect Implementation of Authentication Algorithm
| URL | Tags |
|---|---|
| https://www.arista.com/en/support/advisories-noti… | vendor-advisory |
| Vendor | Product | Version | |
|---|---|---|---|
| Arista Networks | EOS |
Affected:
4.36.0 , ≤ 4.36.1F
(custom)
Affected: 4.35.0 , ≤ 4.35.5M (custom) Affected: 4.34.0 , ≤ 4.34.7M (custom) Affected: 4.33.0 , ≤ 4.33.9M (custom) Affected: 0 |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-73444",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-16T18:04:26.052032Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-16T18:04:45.344Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"platforms": [
"710 Series",
"720D Series",
"720XP/722XPM Series",
"750X Series",
"7010TX Series",
"7020R/R4 Series",
"7130 Series running EOS",
"7170 Series",
"7050X3/X4 Series",
"7060X/X2/X4/X5/X6 Series",
"7260X/X3 Series",
"7280R/R2/R3/R4 Series",
"7300X/X3 Series",
"7320X Series",
"7358X4 Series",
"7368X4 Series",
"7388X5 Series",
"7500R/R2/R3 Series",
"7800R3/R4 Series",
"7700R4 Series",
"AWE 5000 Series",
"AWE 7200R Series",
"CloudEOS",
"cEOS-lab",
"vEOS-lab",
"CloudVision eXchange",
"virtual or physical appliance"
],
"product": "EOS",
"vendor": "Arista Networks",
"versions": [
{
"changes": [
{
"at": "4.36.2F",
"status": "unaffected"
}
],
"lessThanOrEqual": "4.36.1F",
"status": "affected",
"version": "4.36.0",
"versionType": "custom"
},
{
"changes": [
{
"at": "4.35.6M",
"status": "unaffected"
}
],
"lessThanOrEqual": "4.35.5M",
"status": "affected",
"version": "4.35.0",
"versionType": "custom"
},
{
"changes": [
{
"at": "4.34.8M",
"status": "unaffected"
}
],
"lessThanOrEqual": "4.34.7M",
"status": "affected",
"version": "4.34.0",
"versionType": "custom"
},
{
"changes": [
{
"at": "4.33.10M",
"status": "unaffected"
}
],
"lessThanOrEqual": "4.33.9M",
"status": "affected",
"version": "4.33.0",
"versionType": "custom"
},
{
"status": "affected",
"version": "0"
}
]
}
],
"configurations": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eIn order to be vulnerable to CVE-2026-73444, VRRPv2 must be configured with IP-AH authentication on at least one interface:\u003c/p\u003e\u003cpre\u003eswitch\u0026gt;show running-config section vrrp\ninterface Ethernet1\n vrrp 1 ipv4 version 2\n vrrp 1 peer authentication ietf-md5 key-string 7 \u0026lt;key\u0026gt;\u003c/pre\u003e\u003cp\u003eIf VRRP is not configured, or is configured as version 3, or is configured without authentication, there is no exposure.\u003c/p\u003e"
}
],
"value": "In order to be vulnerable to CVE-2026-73444, VRRPv2 must be configured with IP-AH authentication on at least one interface:\n\n\n\nswitch\u003eshow running-config section vrrp\ninterface Ethernet1\n vrrp 1 ipv4 version 2\n vrrp 1 peer authentication ietf-md5 key-string 7 \u003ckey\u003e\n\n\n\nIf VRRP is not configured, or is configured as version 3, or is configured without authentication, there is no exposure."
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "This issue was discovered internally by Arista."
}
],
"datePublic": "2026-09-09T21:09:00.000Z",
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eOn affected platforms running Arista EOS with VRRPv2 IP Authentication Header (IP-AH) authentication configured, an unauthenticated attacker with access to the layer 2 network segment on which VRRP is running could bypass VRRP authentication and claim the virtual router master role, enabling the attacker to intercept, modify, or discard traffic that hosts on the segment send to the virtual gateway address.\u003c/p\u003e"
}
],
"value": "On affected platforms running Arista EOS with VRRPv2 IP Authentication Header (IP-AH) authentication configured, an unauthenticated attacker with access to the layer 2 network segment on which VRRP is running could bypass VRRP authentication and claim the virtual router master role, enabling the attacker to intercept, modify, or discard traffic that hosts on the segment send to the virtual gateway address."
}
],
"impacts": [
{
"capecId": "CAPEC-115",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-115 Authentication Bypass"
}
]
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "ADJACENT_NETWORK",
"availabilityImpact": "LOW",
"baseScore": 4.7,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "CHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
},
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "ADJACENT",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "LOW",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-303",
"description": "CWE-303 Incorrect Implementation of Authentication Algorithm",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-15T21:11:37.625Z",
"orgId": "c8b34d1a-69ae-45c3-88fe-f3b3d44f39b7",
"shortName": "Arista"
},
"references": [
{
"tags": [
"vendor-advisory"
],
"url": "https://www.arista.com/en/support/advisories-notices/security-advisory/24713-security-advisory-0157"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eThe recommended resolution is to upgrade to a remediated software version at your earliest convenience. CVE-2026-73444 has been fixed in the following releases:\u003c/p\u003e\u003cul\u003e\u003cli\u003e4.36.2F and later releases in the 4.36.x train\u003c/li\u003e\u003cli\u003e4.35.6M and later releases in the 4.35.x train\u003c/li\u003e\u003cli\u003e4.34.8M and later releases in the 4.34.x train\u003c/li\u003e\u003cli\u003e4.33.10M and later releases in the 4.33.x train\u003c/li\u003e\u003c/ul\u003e"
}
],
"value": "The recommended resolution is to upgrade to a remediated software version at your earliest convenience. CVE-2026-73444 has been fixed in the following releases:\n\n * 4.36.2F and later releases in the 4.36.x train\n * 4.35.6M and later releases in the 4.35.x train\n * 4.34.8M and later releases in the 4.34.x train\n * 4.33.10M and later releases in the 4.33.x train"
}
],
"source": {
"advisory": "157",
"defect": [
"1866656"
],
"discovery": "INTERNAL"
},
"title": "On affected platforms running Arista EOS with VRRPv2 IP Authentication Header (IP-AH) authentication configured, an unauthenticated attacker with access to the layer 2 network segment on which VRRP is running could bypass VRRP authentication and claim the",
"workarounds": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eRestricting physical and logical access to VRRP-enabled segments reduces the attack surface. Additionally, migrating virtual routers from VRRP version 2 with authentication to VRRP version 3 removes the vulnerable code path:\u003c/p\u003e\u003cpre\u003eswitch(config)# interface vlan 20\nswitch(config-if-vl20)# vrrp 1 ipv4 version 3\u003c/pre\u003e"
}
],
"value": "Restricting physical and logical access to VRRP-enabled segments reduces the attack surface. Additionally, migrating virtual routers from VRRP version 2 with authentication to VRRP version 3 removes the vulnerable code path:\n\n\n\nswitch(config)# interface vlan 20\nswitch(config-if-vl20)# vrrp 1 ipv4 version 3"
}
],
"x_generator": {
"engine": "Vulnogram 1.0.5"
}
}
},
"cveMetadata": {
"assignerOrgId": "c8b34d1a-69ae-45c3-88fe-f3b3d44f39b7",
"assignerShortName": "Arista",
"cveId": "CVE-2026-73444",
"datePublished": "2026-09-15T21:11:37.625Z",
"dateReserved": "2026-08-12T16:39:35.977Z",
"dateUpdated": "2026-09-16T18:04:45.344Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-66411 (GCVE-0-2026-66411)
Vulnerability from cvelistv5 – Published: 2026-08-10 08:13 – Updated: 2026-08-10 11:01- CWE-303 - Incorrect Implementation of Authentication Algorithm
| Vendor | Product | Version | |
|---|---|---|---|
| ECOVACS ROBOTICS | DEEBOT PRO M1 |
Affected:
0 , < M1-1.7.27
(semver)
|
|
| ECOVACS ROBOTICS | DEEBOT PRO K1VAC |
Affected:
0 , < V1.7.821
(semver)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-66411",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-10T10:58:14.457734Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-08-10T11:01:17.836Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "DEEBOT PRO M1",
"vendor": "ECOVACS ROBOTICS",
"versions": [
{
"lessThan": "M1-1.7.27",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "DEEBOT PRO K1VAC",
"vendor": "ECOVACS ROBOTICS",
"versions": [
{
"lessThan": "V1.7.821",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "DEEBOT PRO M1 and DEEBOT PRO K1VAC incorrectly implement authentication algorithm in Websocket communications.\r\nAn unauthenticated attacker may connect and operate the affected robot."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en-US",
"value": "GENERAL"
}
]
},
{
"cvssV4_0": {
"baseScore": 6.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N",
"version": "4.0"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en-US",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-303",
"description": "Incorrect Implementation of Authentication Algorithm",
"lang": "en-US",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-10T08:13:34.748Z",
"orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"shortName": "jpcert"
},
"references": [
{
"url": "https://robot.hellohas.co.jp/news/update_20260331/"
},
{
"url": "https://jvn.jp/en/vu/JVNVU92804348/"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"assignerShortName": "jpcert",
"cveId": "CVE-2026-66411",
"datePublished": "2026-08-10T08:13:34.748Z",
"dateReserved": "2026-07-27T00:45:20.457Z",
"dateUpdated": "2026-08-10T11:01:17.836Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-66028 (GCVE-0-2026-66028)
Vulnerability from cvelistv5 – Published: 2026-07-27 18:00 – Updated: 2026-07-28 01:06- CWE-303 - Incorrect Implementation of Authentication Algorithm
| URL | Tags |
|---|---|
| https://github.com/aaronamran/CVE-Disclosures/tre… | technical-descriptionexploit |
| https://www.vulncheck.com/advisories/ekushey-proj… | third-party-advisory |
| https://codecanyon.net/item/ekushey-project-manag… | product |
| Vendor | Product | Version | |
|---|---|---|---|
| Creativeitem | Ekushey Project Manager CRM |
Affected:
0 , ≤ 5.0
(custom)
cpe:2.3:a:creativeitem:ekushey_project_manager_crm:*:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-66028",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-07-27T18:24:50.620701Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-07-27T18:25:18.297Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "affected",
"product": "Ekushey Project Manager CRM",
"vendor": "Creativeitem",
"versions": [
{
"lessThanOrEqual": "5.0",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:creativeitem:ekushey_project_manager_crm:*:*:*:*:*:*:*:*",
"versionEndIncluding": "5.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Aaron Amran Bin Amiruddin"
}
],
"datePublic": "2026-07-25T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Ekushey Project Manager CRM through version 5.0 contains a missing uniqueness constraint vulnerability that allows authenticated administrators to create duplicate client accounts with identical email and password credentials. Attackers can exploit the lack of email field uniqueness enforcement to create conflicting account states where multiple accounts share the same email address with different passwords, resulting in unpredictable authentication behavior and unauthorized account access."
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 7.1,
"baseSeverity": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "HIGH",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "LOW",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 6.7,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "HIGH",
"privilegesRequired": "HIGH",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-303",
"description": "Incorrect Implementation of Authentication Algorithm",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-07-28T01:06:22.634Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "Researcher Disclosure",
"tags": [
"technical-description",
"exploit"
],
"url": "https://github.com/aaronamran/CVE-Disclosures/tree/main/CVE-2026/CVE-2026-66028"
},
{
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/ekushey-project-manager-crm-missing-uniqueness-constraint-via-client-email"
},
{
"name": "Product Webpage",
"tags": [
"product"
],
"url": "https://codecanyon.net/item/ekushey-project-manager-crm/9492104"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "Ekushey Project Manager CRM 5.0 Missing Uniqueness Constraint via Client Email",
"x_generator": {
"engine": "vulncheck"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-66028",
"datePublished": "2026-07-27T18:00:54.581Z",
"dateReserved": "2026-07-23T20:45:17.816Z",
"dateUpdated": "2026-07-28T01:06:22.634Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-59309 (GCVE-0-2026-59309)
Vulnerability from cvelistv5 – Published: 2026-07-30 12:19 – Updated: 2026-07-30 15:08- CWE-303 - Incorrect implementation of authentication algorithm
| Vendor | Product | Version | |
|---|---|---|---|
| VMware | Cloud Foundation |
Affected:
9.1.x.x
Affected: 9.0.x.x Affected: 5.x |
|
| VMware | vSphere Foundation |
Affected:
9.1.x.x
Affected: 9.0.x.x |
|
| VMware | vCenter |
Affected:
9.1.x.x , < 9.1.0.0300
(custom)
Affected: 9.0.x.x , < 9.0.2.0100 (custom) Affected: 8.0 , < 8.0 U3k (custom) |
|
| VMware | Telco Cloud Infrastructure |
Affected:
3.0
|
|
| VMware | Telco Cloud Platform |
Affected:
5.1.x
Affected: 5.0.x Affected: 4.x Affected: 3.0 |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-59309",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-07-30T15:07:53.144480Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-07-30T15:08:05.176Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Cloud Foundation",
"vendor": "VMware",
"versions": [
{
"status": "affected",
"version": "9.1.x.x"
},
{
"status": "affected",
"version": "9.0.x.x"
},
{
"status": "affected",
"version": "5.x"
}
]
},
{
"defaultStatus": "unaffected",
"product": "vSphere Foundation",
"vendor": "VMware",
"versions": [
{
"status": "affected",
"version": "9.1.x.x"
},
{
"status": "affected",
"version": "9.0.x.x"
}
]
},
{
"defaultStatus": "unaffected",
"product": "vCenter",
"vendor": "VMware",
"versions": [
{
"lessThan": "9.1.0.0300",
"status": "affected",
"version": "9.1.x.x",
"versionType": "custom"
},
{
"lessThan": "9.0.2.0100",
"status": "affected",
"version": "9.0.x.x",
"versionType": "custom"
},
{
"lessThan": "8.0 U3k",
"status": "affected",
"version": "8.0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Telco Cloud Infrastructure",
"vendor": "VMware",
"versions": [
{
"status": "affected",
"version": "3.0"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Telco Cloud Platform",
"vendor": "VMware",
"versions": [
{
"status": "affected",
"version": "5.1.x"
},
{
"status": "affected",
"version": "5.0.x"
},
{
"status": "affected",
"version": "4.x"
},
{
"status": "affected",
"version": "3.0"
}
]
}
],
"datePublic": "2026-07-29T04:54:00.000Z",
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service.\u0026nbsp;\u003cspan\u003eA malicious actor with network access to vCenter\u0026nbsp;may exploit this issue to bypass authentication and gain unauthorized access to the system.\u003c/span\u003e\u003cbr\u003e\u003cbr\u003e"
}
],
"value": "VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service.\u00a0A malicious actor with network access to vCenter\u00a0may exploit this issue to bypass authentication and gain unauthorized access to the system."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-303",
"description": "CWE-303 Incorrect implementation of authentication algorithm",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-07-30T12:27:12.963Z",
"orgId": "dcf2e128-44bd-42ed-91e8-88f912c1401d",
"shortName": "vmware"
},
"references": [
{
"url": "https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "vCenter authentication-bypass vulnerability",
"x_generator": {
"engine": "Vulnogram 1.0.4"
}
}
},
"cveMetadata": {
"assignerOrgId": "dcf2e128-44bd-42ed-91e8-88f912c1401d",
"assignerShortName": "vmware",
"cveId": "CVE-2026-59309",
"datePublished": "2026-07-30T12:19:52.390Z",
"dateReserved": "2026-07-04T18:13:57.026Z",
"dateUpdated": "2026-07-30T15:08:05.176Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-57852 (GCVE-0-2026-57852)
Vulnerability from cvelistv5 – Published: 2026-07-20 22:09 – Updated: 2026-07-21 14:55- CWE-303 - Incorrect Implementation of Authentication Algorithm
| URL | Tags |
|---|---|
| https://github.com/getgrav/grav/security/advisori… | vendor-advisory |
| https://github.com/getgrav/grav | |
| https://www.vulncheck.com/advisories/authenticati… | third-party-advisory |
| Vendor | Product | Version | |
|---|---|---|---|
| Trilby Media | Grav CMS scheduler-webhook plugin |
Affected:
0 , ≤ 1.1.3
(semver)
Affected: 0 , ≤ 2.0.8 (semver) |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-57852",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-07-21T13:12:46.072253Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-07-21T14:55:56.254Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "affected",
"product": "Grav CMS scheduler-webhook plugin",
"vendor": "Trilby Media",
"versions": [
{
"lessThanOrEqual": "1.1.3",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "2.0.8",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Saidakbarxon Maxsudxonov"
}
],
"datePublic": "2026-07-20T22:10:00.000Z",
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eGrav CMS scheduler-webhook plugin contains an authentication bypass vulnerability that allows unauthenticated remote attackers to trigger configured scheduled jobs by exploiting a short-circuit logic flaw in the webhook token validation. Attackers can send a single unauthenticated POST request to the scheduler webhook endpoint to execute all configured scheduled jobs or target a specific job, causing unintended execution of operator-defined commands under the web server process user.\u003c/p\u003e"
}
],
"value": "Grav CMS scheduler-webhook plugin contains an authentication bypass vulnerability that allows unauthenticated remote attackers to trigger configured scheduled jobs by exploiting a short-circuit logic flaw in the webhook token validation. Attackers can send a single unauthenticated POST request to the scheduler webhook endpoint to execute all configured scheduled jobs or target a specific job, causing unintended execution of operator-defined commands under the web server process user."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "LOW",
"baseScore": 5.6,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
},
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "HIGH",
"attackRequirements": "PRESENT",
"attackVector": "NETWORK",
"baseScore": 6.3,
"baseSeverity": "MEDIUM",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "LOW",
"vulnConfidentialityImpact": "LOW",
"vulnIntegrityImpact": "LOW",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-303",
"description": "CWE-303 Incorrect Implementation of Authentication Algorithm",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-07-21T11:08:15.685Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "GitHub Security Advisory (GHSA-xwv3-2mv2-w33x)",
"tags": [
"vendor-advisory"
],
"url": "https://github.com/getgrav/grav/security/advisories/GHSA-xwv3-2mv2-w33x"
},
{
"name": "Product",
"url": "https://github.com/getgrav/grav"
},
{
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/authentication-bypass-via-null-short-circuit-in-grav-cms-scheduler-webhook-token-check"
}
],
"title": "Authentication Bypass via Null Short-Circuit in Grav CMS Scheduler Webhook Token Check",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-57852",
"datePublished": "2026-07-20T22:09:01.640Z",
"dateReserved": "2026-06-25T18:48:00.282Z",
"dateUpdated": "2026-07-21T14:55:56.254Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
No mitigation information available for this CWE.
CAPEC-90: Reflection Attack in Authentication Protocol
An adversary can abuse an authentication protocol susceptible to reflection attack in order to defeat it. Doing so allows the adversary illegitimate access to the target system, without possessing the requisite credentials. Reflection attacks are of great concern to authentication protocols that rely on a challenge-handshake or similar mechanism. An adversary can impersonate a legitimate user and can gain illegitimate access to the system by successfully mounting a reflection attack during authentication.