Common Weakness Enumeration

CWE-305

Allowed

Authentication Bypass by Primary Weakness

Abstraction: Base · Status: Draft

The authentication algorithm is sound, but the implemented mechanism can be bypassed as the result of a separate weakness that is primary to the authentication error.

316 vulnerabilities reference this CWE, most recent first.

GHSA-VX8H-4PRV-G744

Vulnerability from github – Published: 2026-07-01 20:57 – Updated: 2026-07-01 20:57
VLAI
Summary
Rancher has Privilege Escalation from Project Owner to Host
Details

Impact

A vulnerability has been identified in Rancher Manager that allows users assigned the Project Owner role to modify Pod Security Admission (PSA) labels on namespaces within their projects. Under the default role configuration, an attacker with the following access pattern can exploit this issue: 1. Cluster Access: The user is granted Cluster Member access. 2. Project Ownership: The user creates or is assigned ownership of a project. 3. Namespace Creation: The user creates a namespace within that project. 4. PSA Modification: The user modifies the namespace PSA configuration to use the privileged profile. 5. Privilege Escalation: The user deploys privileged workloads within the namespace.

As outlined in the Kubernetes Pod Security Standards documentation, privileged containers disable core Kubernetes security protections, allowing workloads to bypass standard container isolation boundaries. This can result in privilege escalation within the cluster environment.

Potential impacts include: - Deployment of privileged containers - Access to host-level resources - Container breakout - Cluster privilege escalation - Compromise of workloads running on affected nodes

Please refer to the associated MITRE ATT&CK techniques for further information about this category of attack: - Deploy Container - Escape to Host - Exploitation for Privilege Escalation

Reference: Kubernetes Pod Security Standards — Privileged Profile

Patches

This vulnerability is resolved by modifying the project-owner role to explicitly define the allowed verbs for projects resources instead of using the wildcard (*) permission.

The updated role configuration removes access to the updatepsa verb. This prevents project owners from modifying PSA settings in a manner that could enable privilege escalation.

Patched versions of Rancher include releases v2.12.10, v2.13.6, and v2.14.2.

Workarounds

If upgrading is not immediately possible, administrators should create a custom project role based on the existing Project Owner role, while removing unrestricted wildcard permissions for project resources.

The allowed verbs for projects should be restricted to: “get, update, delete, patch, create, list, watch, deletecollection” instead of “*”.

This prevents access to the updatepsa capability that enables the privilege escalation path.

References

If you have any questions or comments about this advisory: - Reach out to the SUSE Rancher Security team for security related inquiries. - Open an issue in the Rancher repository. - Verify with our support matrix and product support lifecycle.

Show details on source website

{
  "affected": [
    {
      "package": {
        "ecosystem": "Go",
        "name": "github.com/rancher/rancher"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "2.14.0"
            },
            {
              "fixed": "2.14.2"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "package": {
        "ecosystem": "Go",
        "name": "github.com/rancher/rancher"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "2.13.0"
            },
            {
              "fixed": "2.13.6"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "package": {
        "ecosystem": "Go",
        "name": "github.com/rancher/rancher"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "2.12.0"
            },
            {
              "fixed": "2.12.10"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "package": {
        "ecosystem": "Go",
        "name": "github.com/rancher/rancher"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "0.0.0-20260513182521-2800aaac25b5"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "aliases": [
    "CVE-2026-41052"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-305"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-07-01T20:57:49Z",
    "nvd_published_at": "2026-06-29T16:16:39Z",
    "severity": "CRITICAL"
  },
  "details": "### Impact\n\nA vulnerability has been identified in Rancher Manager that allows users assigned the Project Owner role to modify Pod Security Admission (PSA) labels on namespaces within their projects. Under the default role configuration, an attacker with the following access pattern can exploit this issue:\n1. **Cluster Access:** The user is granted Cluster Member access.\n2. **Project Ownership:** The user creates or is assigned ownership of a project.\n3. **Namespace Creation:** The user creates a namespace within that project.\n4. **PSA Modification:** The user modifies the namespace PSA configuration to use the privileged profile.\n5. **Privilege Escalation:** The user deploys privileged workloads within the namespace.\n\nAs outlined in the [Kubernetes Pod Security Standards](https://kubernetes.io/docs/concepts/security/pod-security-standards/) documentation, `privileged` containers disable core Kubernetes security protections, allowing workloads to bypass standard container isolation boundaries. This can result in privilege escalation within the cluster environment.\n\nPotential impacts include:\n- Deployment of privileged containers\n- Access to host-level resources\n- Container breakout\n- Cluster privilege escalation\n- Compromise of workloads running on affected nodes\n\nPlease refer to the associated MITRE ATT\u0026CK techniques for further information about this category of attack:\n- [Deploy Container](https://attack.mitre.org/techniques/T1610/)\n- [Escape to Host](https://attack.mitre.org/techniques/T1611/)\n- [Exploitation for Privilege Escalation](https://attack.mitre.org/techniques/T1068)\n\nReference:\n[Kubernetes Pod Security Standards \u2014 Privileged Profile](https://kubernetes.io/docs/concepts/security/pod-security-standards/#privileged)\n\n### Patches\nThis vulnerability is resolved by modifying the `project-owner` role to explicitly define the allowed verbs for `projects` resources instead of using the wildcard `(*)` permission.\n\nThe updated role configuration removes access to the `updatepsa` verb. This prevents project owners from modifying PSA settings in a manner that could enable privilege escalation.\n\nPatched versions of Rancher include releases `v2.12.10`, `v2.13.6`, and `v2.14.2`.\n\n### Workarounds\nIf upgrading is not immediately possible, administrators should create a custom project role based on the existing Project Owner role, while removing unrestricted wildcard permissions for project resources.\n\nThe allowed verbs for projects should be restricted to: \u201c`get`, `update`, `delete`, `patch`, `create`, `list`, `watch`, `deletecollection`\u201d instead of \u201c`*`\u201d.\n\nThis prevents access to the `updatepsa` capability that enables the privilege escalation path.\n\n### References\nIf you have any questions or comments about this advisory:\n- Reach out to the [SUSE Rancher Security team](https://github.com/rancher/rancher/security/policy) for security related inquiries.\n- Open an issue in the [Rancher](https://github.com/rancher/rancher/issues/new/choose) repository.\n- Verify with our [support matrix](https://www.suse.com/suse-rancher/support-matrix/all-supported-versions/) and [product support lifecycle](https://www.suse.com/lifecycle/).",
  "id": "GHSA-vx8h-4prv-g744",
  "modified": "2026-07-01T20:57:49Z",
  "published": "2026-07-01T20:57:49Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://github.com/rancher/rancher/security/advisories/GHSA-vx8h-4prv-g744"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41052"
    },
    {
      "type": "WEB",
      "url": "https://github.com/rancher/rancher/pull/55061"
    },
    {
      "type": "WEB",
      "url": "https://github.com/rancher/rancher/commit/2800aaac25b5a2c448f800e1f46d"
    },
    {
      "type": "PACKAGE",
      "url": "https://github.com/rancher/rancher"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H",
      "type": "CVSS_V3"
    },
    {
      "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H",
      "type": "CVSS_V4"
    }
  ],
  "summary": "Rancher has Privilege Escalation from Project Owner to Host"
}

GHSA-WF33-6X33-WCF9

Vulnerability from github – Published: 2022-12-27 15:30 – Updated: 2024-10-25 21:41
VLAI
Summary
rdiffweb vulnerable to Authentication Bypass by Primary Weakness
Details

In rdiffweb prior to 2.5.5, the username field is not unique to users. This allows exploitation of primary key logic by creating the same name with different combinations & may allow unauthorized access.

Show details on source website

{
  "affected": [
    {
      "package": {
        "ecosystem": "PyPI",
        "name": "rdiffweb"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "2.5.5"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "aliases": [
    "CVE-2022-4722"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-287",
      "CWE-305"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2022-12-30T18:01:28Z",
    "nvd_published_at": "2022-12-27T15:15:00Z",
    "severity": "HIGH"
  },
  "details": "In rdiffweb prior to 2.5.5, the username field is not unique to users. This allows exploitation of primary key logic by creating the same name with different combinations \u0026 may allow unauthorized access.",
  "id": "GHSA-wf33-6x33-wcf9",
  "modified": "2024-10-25T21:41:19Z",
  "published": "2022-12-27T15:30:19Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-4722"
    },
    {
      "type": "WEB",
      "url": "https://github.com/ikus060/rdiffweb/commit/d1aaa96b665a39fba9e98d6054a9de511ba0a837"
    },
    {
      "type": "PACKAGE",
      "url": "https://github.com/ikus060/rdiffweb"
    },
    {
      "type": "WEB",
      "url": "https://github.com/pypa/advisory-database/tree/main/vulns/rdiffweb/PYSEC-2022-43008.yaml"
    },
    {
      "type": "WEB",
      "url": "https://huntr.dev/bounties/c62126dc-d9a6-4d3e-988d-967031876c58"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
      "type": "CVSS_V3"
    },
    {
      "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
      "type": "CVSS_V4"
    }
  ],
  "summary": "rdiffweb vulnerable to Authentication Bypass by Primary Weakness"
}

GHSA-WWQ6-XMJH-4F52

Vulnerability from github – Published: 2024-12-19 15:31 – Updated: 2024-12-19 15:31
VLAI
Details

A relative path traversal vulnerability (CWE-23) in FortiWAN version 4.5.7 and below, 4.4 all versions may allow a remote non-authenticated attacker to delete files on the system by sending a crafted POST request. In particular, deleting specific configuration files will reset the Admin password to its default value.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2021-26102"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-22",
      "CWE-305"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2024-12-19T14:15:05Z",
    "severity": "CRITICAL"
  },
  "details": "A relative path traversal vulnerability (CWE-23) in FortiWAN version 4.5.7 and below, 4.4 all versions may allow a remote non-authenticated attacker to delete files on the system by sending a crafted POST request. In particular, deleting specific configuration files will reset the Admin password to its default value.",
  "id": "GHSA-wwq6-xmjh-4f52",
  "modified": "2024-12-19T15:31:11Z",
  "published": "2024-12-19T15:31:11Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-26102"
    },
    {
      "type": "WEB",
      "url": "https://fortiguard.fortinet.com/psirt/FG-IR-21-048"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-XC4X-F462-G6P7

Vulnerability from github – Published: 2023-07-13 03:30 – Updated: 2025-02-13 18:31
VLAI
Details

The authentication mechanism in SonicWall GMS and Analytics Web Services had insufficient checks, allowing authentication bypass. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2023-34124"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-287",
      "CWE-305"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2023-07-13T01:15:08Z",
    "severity": "CRITICAL"
  },
  "details": "The authentication mechanism in SonicWall GMS and Analytics Web Services had insufficient checks, allowing authentication bypass. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.",
  "id": "GHSA-xc4x-f462-g6p7",
  "modified": "2025-02-13T18:31:40Z",
  "published": "2023-07-13T03:30:47Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-34124"
    },
    {
      "type": "WEB",
      "url": "https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2023-0010"
    },
    {
      "type": "WEB",
      "url": "https://www.sonicwall.com/support/notices/230710150218060"
    },
    {
      "type": "WEB",
      "url": "http://packetstormsecurity.com/files/174571/Sonicwall-GMS-9.9.9320-Remote-Code-Execution.html"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-XFG3-G2VF-G46C

Vulnerability from github – Published: 2025-07-07 03:30 – Updated: 2025-07-07 03:30
VLAI
Details

Authentication vulnerability in the distributed collaboration framework module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2025-53167"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-305"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2025-07-07T03:15:27Z",
    "severity": "MODERATE"
  },
  "details": "Authentication vulnerability in the distributed collaboration framework module\nImpact: Successful exploitation of this vulnerability may affect service confidentiality.",
  "id": "GHSA-xfg3-g2vf-g46c",
  "modified": "2025-07-07T03:30:22Z",
  "published": "2025-07-07T03:30:22Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-53167"
    },
    {
      "type": "WEB",
      "url": "https://consumer.huawei.com/en/support/bulletin/2025/7"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:L",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-XV4R-VCCV-MG4W

Vulnerability from github – Published: 2021-05-24 21:13 – Updated: 2021-12-20 18:07
VLAI
Summary
MinIO Admin API security issue
Details

During an internal security audit, we detected an authentication bypass issue in the MinIO admin API. The security issue has been reported internally. We have not observed this exploit in the wild or reported elsewhere in the community at large. All users are advised to upgrade ASAP.

Impact

Given an admin access key, it is possible to perform admin API operations i.e. creating new service accounts for existing access keys without knowing the admin secret key. This security issue was found during a regular internal security audit.

Patches

This issue was fixed by @vadmeste in PR https://github.com/minio/minio/pull/9422

Binary Download

Please download the latest server binary that contains the fix from

Platform Architecture URL
Apple macOS 64-bit Intel https://dl.min.io/server/minio/release/darwin-amd64/minio
GNU/Linux 64-bit Intel https://dl.min.io/server/minio/release/linux-amd64/minio
Microsoft Windows 64-bit https://dl.min.io/server/minio/release/windows-amd64/minio.exe

Docker Container Download

docker pull minio/minio:RELEASE.2020-04-23T00-58-49Z

Questions

If you have any questions or comments regarding this advisory please reach out to us any of the following means.

  • If you are a community user minio/minio
  • Email us at security@min.io
  • If you are a paid customer please open an issue at https://subnet.min.io
Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2020-11012"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-287",
      "CWE-305",
      "CWE-755"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2020-04-23T22:15:00Z",
    "severity": "HIGH"
  },
  "details": "During an internal security audit, we detected an authentication bypass issue in the MinIO admin API. The security issue has been reported internally. We have not observed this exploit in the wild or reported elsewhere in the community at large. All users are advised to upgrade ASAP.\n\n### Impact\nGiven an admin access key, it is possible to perform admin API operations i.e. creating new service accounts for existing access keys without knowing the admin secret key. This security issue was found during a regular internal security audit. \n\n### Patches\nThis issue was fixed by @vadmeste in PR https://github.com/minio/minio/pull/9422 \n\n### Binary Download\nPlease download the latest server binary that contains the fix from\n\n| Platform    | Architecture | URL                                                       |\n| ----------  | --------     | ------                                                    |\n| Apple macOS | 64-bit Intel | https://dl.min.io/server/minio/release/darwin-amd64/minio |\n| GNU/Linux  | 64-bit Intel | https://dl.min.io/server/minio/release/linux-amd64/minio |\n| Microsoft Windows | 64-bit       | https://dl.min.io/server/minio/release/windows-amd64/minio.exe |\n\n### Docker Container Download\n```\ndocker pull minio/minio:RELEASE.2020-04-23T00-58-49Z\n```\n\n### Questions\nIf you have any questions or comments regarding this advisory please reach out to us any of the following means.\n\n- If you are a community user [minio/minio](https://github.com/minio/minio/issues)\n- Email us at [security@min.io](mailto:security@min.io)\n- If you are a paid customer please open an issue at https://subnet.min.io",
  "id": "GHSA-xv4r-vccv-mg4w",
  "modified": "2021-12-20T18:07:48Z",
  "published": "2021-05-24T21:13:59Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://github.com/minio/minio/security/advisories/GHSA-xv4r-vccv-mg4w"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-11012"
    },
    {
      "type": "WEB",
      "url": "https://github.com/minio/minio/pull/9422"
    },
    {
      "type": "WEB",
      "url": "https://github.com/minio/minio/commit/4cd6ca02c7957aeb2de3eede08b0754332a77923"
    },
    {
      "type": "PACKAGE",
      "url": "https://github.com/minio/minio"
    },
    {
      "type": "WEB",
      "url": "https://github.com/minio/minio/releases/tag/RELEASE.2020-04-23T00-58-49Z"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N",
      "type": "CVSS_V3"
    }
  ],
  "summary": "MinIO Admin API security issue"
}

No mitigation information available for this CWE.

No CAPEC attack patterns related to this CWE.