WordPress Plugin Flaw Opens Door to Admin Takeover
CVE-2026-15826 in User Profile Builder exposes 40,000+ WordPress sites to admin takeover.
19 results for “authentication bypass”
CVE-2026-15826 in User Profile Builder exposes 40,000+ WordPress sites to admin takeover.
Fortinet resolves eight flaws, including high-severity authentication bugs in FortiWeb and FortiManager.
Threat actors are exploiting a critical SharePoint authentication bypass after Rapid7 released a PoC exploit.
A critical authentication bypass in Azure SQL Database allows unauthorized attackers to gain elevated privileges over a network.
CISA has added an authentication bypass vulnerability in N-able N-central to its Known Exploited Vulnerabilities catalog, requiring immediate action.
A missing authentication vulnerability in OpenCode Studio versions prior to 2.4.4 allows unauthenticated attackers to steal files and delete user videos.
A critical vulnerability in the Single Sign On For TNG WordPress plugin allows unauthenticated attackers to reset any user password and take over sites.
A critical authentication bypass vulnerability in SolarWinds Web Help Desk allows unauthorized access for systems with SAML 2.0 enabled.
A flaw in the Pheditor forced password-change flow allows unauthenticated attackers to hijack administrative accounts on systems using default credentials.
A hardcoded secret in LightRAG allows unauthenticated attackers to bypass API key protections and gain full control over document operations.
A critical authentication bypass vulnerability identified in VMware Avi Load Balancer could allow unauthorized access to the control plane.
A critical authentication bypass flaw in VMware Avi Load Balancer has been disclosed, requiring immediate attention to specific versions.
A critical vulnerability in IBM Langflow OSS allows remote actors to execute flows without authentication.
A critical authentication bypass vulnerability has been identified in VMware Avi Load Balancer, documented as CVE-2026-47865.
A critical authentication bypass in Android allows unauthorized users to send messages via Gemini without requiring a device PIN.
A critical vulnerability in the Grav login plugin allows attackers to bypass two-factor authentication protections.
A critical flaw in Grav versions before 2.0.4 permits attackers to bypass two-factor authentication by overwriting existing security secrets.
A critical vulnerability in Envoy Gateway allows attackers to bypass path validation and access sensitive files on the gateway controller pod.
As hackers exploit a critical Gitea Docker flaw, the ease of bypassing authentication exposes the fragility of self-hosted DevOps security.