Authentication Bypass
Vulnerabilities that let a request skip the login boundary entirely, with the guard that failed and how it was reached.
Published work on this topic
| 2026-08-19 | CVE-2026-15571 | CVE-2026-15571: Keycloak Account Linking Auth Bypass | PoC | |
| 2026-08-17 | CVE-2026-19598 | CVE-2026-19598: Pods Auth Bypass - Privilege Escalation | PoC | |
| 2026-08-17 | CVE-2026-28185 | CVE-2026-28185: Login with Google Auth Bypass | PoC | |
| 2026-08-13 | CVE-2026-72772 | CVE-2026-72772: n8n Auth Bypass | PoC | |
| 2026-08-12 | CVE-2026-59083 | CVE-2026-59083: Apache Tomcat - Auth Bypass | PoC | |
| 2026-08-11 | CVE-2026-72898 | CVE-2026-72898: Metabase SQL Injection - Admin Takeover | PoC | |
| 2026-08-08 | CVE-2026-14364 | CVE-2026-14364: TrueBooker Auth Bypass | PoC | |
| 2026-08-01 | CVE-2026-66012 | CVE-2026-66012: SiYuan - Auth Bypass to Admin Takeover | PoC | |
| 2026-07-31 | CVE-2026-18363 | CVE-2026-18363: osTicket Auth Bypass | PoC | |
| 2026-05-08 | CVE-2026-37709 | CVE-2026-37709: Snipe-IT - Auth Bypass | PoC | |
| 2026-05-06 | CVE-2026-27960 | CVE-2026-27960: OpenCTI Authentication Bypass via Hardcoded UUID | PoC | |
| 2026-01-26 | CVE-2026-24061 | CVE-2026-24061: GNU Inetutils - Auth Bypass | PoC |
