VulnWatch VulnWatch
← Back to dashboard
#

Auth Bypass

208 entries

Every Auth Bypass entry VulnWatch has indexed, sorted by publication date.

Subscribe to this tag's RSS feed

Critical github

MCP Toolbox for Databases has an Origin Validation Error

The Model Context Protocol has a security warning advising servers to validate the "Origin" header on all incoming connections to prevent DNS rebinding attacks. Prior to the v0.25.0 release, users had...

Auth Bypass Agentic / MCP model context protocol
0.0
CVSS
3 months ago
Critical nvd

CVE-2026-11624: The Model Context Protocol has a security warning advising servers to validate the "Origin" header on all incoming conne

The Model Context Protocol has a security warning advising servers to validate the "Origin" header on all incoming connections to prevent DNS rebinding attacks. Prior to the v0.25.0 release, users had...

Auth Bypass Agentic / MCP model context protocol
9.4
CVSS
3 months ago
High nvd

CVE-2026-47138: Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.77 and 9.9.1-alpha.1, an unauthenticated attacker who knows a publicly-kno...

Auth Bypass adversarial
8.7
CVSS
3 months ago
Medium nvd

CVE-2026-47250: mcp-server-kubernetes is a Model Context Protocol server for Kubernetes cluster management. Prior to version 3.7.0, the

mcp-server-kubernetes is a Model Context Protocol server for Kubernetes cluster management. Prior to version 3.7.0, the kubectl_generic tool in mcp-server-kubernetes passes user-supplied flags directl...

Auth Bypass Agentic / MCP model context protocol mcp server ai agent
6.1
CVSS
3 months ago
High nvd

CVE-2026-46519: mcp-server-kubernetes is a Model Context Protocol server for Kubernetes cluster management. Prior to version 3.6.0, mcp-

mcp-server-kubernetes is a Model Context Protocol server for Kubernetes cluster management. Prior to version 3.6.0, mcp-server-kubernetes exposes three environment variables (ALLOW_ONLY_READONLY_TOOLS...

Auth Bypass Agentic / MCP model context protocol
8.8
CVSS
3 months ago
Medium nvd

CVE-2025-54509: Improper access control for register interface in the input-output memory management unit (IOMMU) could allow a privileg

Improper access control for register interface in the input-output memory management unit (IOMMU) could allow a privileged attacker to cause non-coherent accesses by the AMD secure processor (ASP) pot...

4.0
CVSS
3 months ago
Low github

Weaviate has an Improper Authorization issue

A vulnerability was identified in Weaviate up to 1.37.7. This vulnerability affects the function validateConfig of the file usecases/auth/authentication/apikey/client.go of the component Static API Ke...

Auth Bypass weaviate
5.0
CVSS
3 months ago
Low nvd

CVE-2026-11500: A vulnerability was identified in Weaviate up to 1.37.7. This vulnerability affects the function validateConfig of the f

A vulnerability was identified in Weaviate up to 1.37.7. This vulnerability affects the function validateConfig of the file usecases/auth/authentication/apikey/client.go of the component Static API Ke...

Auth Bypass weaviate
1.3
CVSS
3 months ago
Medium github

MCP Server Kubernetes: kubectl-generic flag injection enables Kubernetes bearer token exfiltration

### Summary The `kubectl_generic` tool in `mcp-server-kubernetes` passes user-supplied flags directly to kubectl without any allowlist, enabling a **privilege escalation attack** within Kubernetes env...

Prompt Injection Auth Bypass Agentic / MCP prompt injection indirect prompt mcp server anthropic ai agent claude
6.1
CVSS
3 months ago
Medium github

praisonai-platform: Any workspace member can rewrite workspace name, description, and settings via PATCH /workspaces/{id}

## Summary **Type:** Authorization bypass enabling workspace metadata + settings tampering. The `PATCH /workspaces/{workspace_id}` endpoint is gated only by `require_workspace_member(workspace_id)` (...

6.5
CVSS
3 months ago
High github

@agenticmail/mcp Missing Authentication for Critical Function

# AgenticMail MCP HTTP authorization bypass ## Summary `@agenticmail/mcp` exposes a Streamable HTTP transport when started with `--http` or `MCP_HTTP=1`. In that mode, the `/mcp` endpoint accepts re...

0.0
CVSS
3 months ago
Medium github

nono: Sandbox escape on Linux via D-Bus: `systemd-run --user`

### Summary The nono Landlock/seccomp policies allow access to local Unix domain sockets (concrete and abstract). This allows an easy sandbox escape by talking to the per-user systemd dbus socket. T...

Auth Bypass Agentic / MCP claude code ai agent claude aider
6.1
CVSS
3 months ago
High github

Parse Server: Pre-authentication denial of service via client version header regex backtracking

### Impact An unauthenticated attacker who knows a publicly-known Parse Application ID can submit a single HTTP request whose client SDK version field contains adversarial input that triggers polynom...

Auth Bypass adversarial
0.0
CVSS
3 months ago
Medium osv

LiteLLM allows an authenticated internal_user to create API keys with access to routes that their role does not permit

LiteLLM prior to 1.83.14 allows an authenticated internal_user to create API keys with access to routes that their role does not permit. When generating a key, the allowed_routes field is stored witho...

4.0
CVSS
4 months ago
High nvd

CVE-2026-47101: LiteLLM prior to 1.83.14 allows an authenticated internal_user to create API keys with access to routes that their role

LiteLLM prior to 1.83.14 allows an authenticated internal_user to create API keys with access to routes that their role does not permit. When generating a key, the allowed_routes field is stored witho...

8.7
CVSS
4 months ago
High github

MCP Server Kubernetes: Tool Access Control Bypass via Presentation-Layer Filtering Without Execution-Layer Enforcement

## Summary `mcp-server-kubernetes` exposes three environment variables (`ALLOW_ONLY_READONLY_TOOLS`, `ALLOW_ONLY_NON_DESTRUCTIVE_TOOLS`, `ALLOWED_TOOLS`) documented as access controls for restricting...

Auth Bypass Agentic / MCP mcp server ai agent gemini
8.8
CVSS
4 months ago
High github

wger: cross-tenant account deletion / deactivation / activation by gym.manage_gym + gym=None

## Summary GHSA-mhc8-p3jx-84mm (CVE-2026-43948) reported that wger's `reset_user_password` and `gym_permissions_user_edit` views in `wger/gym/views/user.py` performed a gym-scope authorization check...

Auth Bypass claude code claude
8.5
CVSS
4 months ago
Critical nvd

CVE-2026-24207: NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an authentication bypass. A succes

NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an authentication bypass. A successful exploit of this vulnerability might lead to code execution, escalation of p...

9.8
CVSS
4 months ago
High nvd

CVE-2026-24206: NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an authentication bypass. A succes

NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an authentication bypass. A successful exploit of this vulnerability might lead to escalation of privileges, denia...

7.3
CVSS
4 months ago
Medium github

Caddy: Remote Admin Authorization Bypass on PKI Endpoints via Prefix-Based Path Matching

## AI Disclosure I used an LLM to help review the source code, reason about attack surface, and help draft and refine this report. I manually validated the finding by reproducing it locally, conf...

4.3
CVSS
4 months ago
Medium github

Caddy: Remote Admin Authorization Bypass in `/config` API via Array Index Normalization

This report is not about a normal textual prefix-expansion case. The issue here is that the authorization layer and the `/config` traversal layer do **not agree on what object the path refers to**....

5.4
CVSS
4 months ago
High nvd

CVE-2026-41949: Dify version 1.14.1 and prior contain an authorization bypass vulnerability in the file preview endpoint that allows any

Dify version 1.14.1 and prior contain an authorization bypass vulnerability in the file preview endpoint that allows any authenticated user to read up to 3,000 characters of any uploaded document acro...

8.2
CVSS
4 months ago
Critical nvd

CVE-2026-41947: Dify version 1.14.1 and prior contains an authorization bypass vulnerability that allows authenticated editor users to s

Dify version 1.14.1 and prior contains an authorization bypass vulnerability that allows authenticated editor users to set and enable trace configurations for any application regardless of tenant owne...

Auth Bypass dify llm
9.1
CVSS
4 months ago
Medium nvd

CVE-2026-45365: Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.8.11, an i

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.8.11, an internal-only bypass_filter parameter is exposed on the /openai/chat/completions...

Auth Bypass ollama openai
5.4
CVSS
4 months ago
High nvd

CVE-2026-44556: Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the /

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the /responses endpoint in the OpenAI router accepts any authenticated user and forwa...

Auth Bypass openai llm
7.1
CVSS
4 months ago