VulnWatch VulnWatch
← Back to dashboard
#

Auth Bypass

164 entries

Every Auth Bypass entry VulnWatch has indexed, sorted by publication date.

Subscribe to this tag's RSS feed

High github

Traefik: Incomplete fix for CVE-2026-33433 + CVE-2026-39858 cross-cohort: headerField underscore-variant identity spoofing in BasicAuth / DigestAuth / ForwardAuth

## Summary There is a high severity vulnerability in Traefik's BasicAuth, DigestAuth, and ForwardAuth middlewares. The fix for CVE-2026-33433 stripped canonical-cased spoofed identity headers (e.g. `...

Auth Bypass anthropic claude
0.0
CVSS
1 day ago
High nvd

CVE-2026-9130: IBM Langflow OSS 1.0.0 through 1.10.3 contain an authorization bypass vulnerability in the MemoryComponent that allows a

IBM Langflow OSS 1.0.0 through 1.10.3 contain an authorization bypass vulnerability in the MemoryComponent that allows authenticated users to access chat history of other users via session_id collisio...

7.1
CVSS
2 days ago
High nvd

CVE-2026-8446: IBM Langflow OSS 1.0.0 through 1.10.3 contain an authentication bypass vulnerability in the Model Context Protocol (MCP)

IBM Langflow OSS 1.0.0 through 1.10.3 contain an authentication bypass vulnerability in the Model Context Protocol (MCP) composer endpoint when mcp_composer_enabled=true (default) and projects are con...

Auth Bypass Agentic / MCP model context protocol langflow
7.5
CVSS
2 days ago
Unknown rss_securityweek

CISA Warns of Exploited Langflow, N-central, and Tomcat Vulnerabilities

The flaws can be exploited for remote code execution, authentication bypass, and EncryptInterceptor bypass. The post CISA Warns of Exploited Langflow, N-central, and Tomcat Vulnerabilities appeared fi...

2 days ago
High nvd

CVE-2026-70475: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the PUT /api/v1

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the PUT /api/v1/executions/:id endpoint in packages/server/src/routes/executions/index.ts lacks...

Auth Bypass large language model
7.1
CVSS
3 days ago
High github

Flowise: Information Disclosure in GET /api/v1/upsert-history returns the entire server-wide upsert history

### Summary The **GET `/api/v1/upsert-history`** endpoint returns the **entire server-wide upsert history** (response size **>100MB**) instead of being scoped to the requesting user/tenant/workspace....

0.0
CVSS
3 days ago
Unknown rss_bleepingcomputer

Varonis Agent IBAC keeps AI agents within their intended boundaries

AI agents need broad access to be useful, but traditional access controls cannot determine whether an action aligns with a user's intent. Varonis explains how Agent IBAC detects intent drift and enfor...

3 days ago
Medium github

@dynatrace-oss/dynatrace-mcp-server has a DQL injection via parameters not documented as DQL

### Summary A DQL injection vulnerability in several read tools lets a caller bypass the tools' documented field-scope, time-window, and display caps by injecting DQL pipeline stages through parameter...

4.3
CVSS
1 week ago
Medium nvd

CVE-2026-10700: IBM Langflow OSS 1.0.0 through 1.8.4 contains multiple broken access control vulnerabilities in its file handling API th

IBM Langflow OSS 1.0.0 through 1.8.4 contains multiple broken access control vulnerabilities in its file handling API that allow unauthorized access to user files.The /api/v1/files/images/{flow_id}/{f...

Auth Bypass langflow
6.5
CVSS
1 week ago
High nvd

CVE-2026-12945: IBM Langflow OSS 1.0.0 through 1.10.1 allows authenticated users to access and manipulate other users' build jobs throug

IBM Langflow OSS 1.0.0 through 1.10.1 allows authenticated users to access and manipulate other users' build jobs through improper access control on log retrieval and unauthenticated build endpoints.

Auth Bypass langflow
7.1
CVSS
1 week ago
High github

Quarkus: Authentication/Authorization Bypass via Advanced Path Normalization Vulnerabilities

Quarkus HTTP path-based authorization policies can be bypassed using encoded semicolons (%3B) to smuggle matrix parameters past the security layer, and using encoded slashes (%2F) or backslashes (%5...

7.5
CVSS
1 week ago
Unknown rss_bleepingcomputer

Your AI Agents Are Guessing at Scale: Permissions Decide the Damage

AI agents are designed to improvise as they complete tasks, making broad permissions a growing security risk. Token Security explains why identity, intent-based access controls, and least privilege ar...

1 week ago
High github

etcd: Watch API authorization bypass via open-ended range requests

### Impact _What kind of vulnerability is it? Who is impacted?_ A user granted READ permission on a single, exact key can use the Watch gRPC API with `clientv3.WithFromKey()` (an open-ended, "from th...

Auth Bypass anthropic
0.0
CVSS
2 weeks ago
High github

AWS API MCP Server Security Policy Bypass via Startup Initialization Failure

## Summary The AWS API MCP Server is an open source Model Context Protocol (MCP) server that enables AI assistants to interact with AWS services and resources through AWS CLI commands. It provides pro...

Auth Bypass Agentic / MCP model context protocol mcp server
7.0
CVSS
2 weeks ago
Medium github

Open WebUI: Arena task endpoints can bypass underlying model access controls

## Summary An authenticated non-admin user with read access to an arena wrapper model can reach a restricted underlying model through task endpoints such as `/api/v1/tasks/moa/completions`. The norm...

5.4
CVSS
2 weeks ago
High nvd

CVE-2026-66027: Suna before 0.9.102 contains a broken access control vulnerability in the message queue API that allows authenticated at

Suna before 0.9.102 contains a broken access control vulnerability in the message queue API that allows authenticated attackers to access and manipulate queue resources belonging to other users by exp...

8.7
CVSS
2 weeks ago
Unknown rss_thehackernews

Seeing AI Agents Is Not Enough. Security Teams Must Enforce What They Can Do

AI agent security is moving through a familiar maturity curve: adoption, then visibility, and finally, control. But what we've collectively discovered is that enforcing least privilege for AI agents i...

2 weeks ago
Low nvd

CVE-2026-65699: AgentGPT through 1.0.0 contains an authorization bypass through user-controlled key vulnerability that allows authentica

AgentGPT through 1.0.0 contains an authorization bypass through user-controlled key vulnerability that allows authenticated users to attach tasks to another user's agent run by supplying a target run_...

2.3
CVSS
2 weeks ago
Medium osv

LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback

### Impact LiteLLM's MCP Streamable HTTP endpoint could allow an unauthenticated attacker to establish an authenticated MCP session using an arbitrary Bearer token. The MCP auth handler supported OA...

4.0
CVSS
2 weeks ago
Medium osv

LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback

### Impact LiteLLM's MCP Streamable HTTP endpoint could allow an unauthenticated attacker to establish an authenticated MCP session using an arbitrary Bearer token. The MCP auth handler supported OA...

4.0
CVSS
2 weeks ago
High github

n8n: AI Agents Project Viewer Privilege Escalation via run_node_tool

## Impact In n8n's AI Agents feature, a user with the read-only Project Viewer role could escalate their privileges by chatting with an agent that has node tools enabled. The agent's node-execution to...

0.0
CVSS
2 weeks ago
High github

Duplicate Advisory: AI Agents Project Viewer Privilege Escalation via run_node_tool

## Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-x5vx-c2c8-m3w9. This link is maintained to preserve external references. ## Original Description n8n versions...

0.0
CVSS
2 weeks ago
High nvd

CVE-2026-65015: n8n versions before 2.30.1 contain a privilege escalation vulnerability in the AI Agents feature where the node-executio

n8n versions before 2.30.1 contain a privilege escalation vulnerability in the AI Agents feature where the node-execution tool lacks proper authorization checks. A Project Viewer user can escalate pri...

7.2
CVSS
2 weeks ago
High github

Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write

## Vulnerability Header | Field | Value | | ------------------- | -----------------------------------------...

Auth Bypass anthropic claude
8.8
CVSS
2 weeks ago
Medium github

Gitea LFS Deploy-Key Privilege Escalation

## Vulnerability Header | Field | Value | | ------------------- | ----------------------------------------------------------- | | V...

Auth Bypass anthropic claude
5.4
CVSS
2 weeks ago