<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Authentication-Bypass — PoC Archive</title><link>https://poc.intelseclab.com/tags/authentication-bypass/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sun, 09 Aug 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/authentication-bypass/index.xml" rel="self" type="application/rss+xml"/><item><title>Ivanti Endpoint Manager Mobile (EPMM) Unauthenticated Remote API Access (CVE-2023-35078)</title><link>https://poc.intelseclab.com/pocs/network/2026-08-09_cve-2023-35078-ivanti-epmm-unauth-api-access/</link><pubDate>Sun, 09 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-08-09_cve-2023-35078-ivanti-epmm-unauth-api-access/</guid><description>Critical severity (CVSS 9.8) — network · CVE-2023-35078 (Ivanti advisory; CWE-287 per NVD). Status: Patched (Ivanti EPMM 11.8.1.1, 11.9.1.1, 11.10.0.2 and later). Affects: Ivanti Endpoint Manager Mobile (EPMM), previously branded MobileIron Core — the /mifs/aad/api/ administrative API surface. Tags: ivanti, epmm, mobileiron-core, mdm, authentication-bypass, cwe-287, unauthenticated, api, pii-disclosure, cisa-kev, ransomware, scanner.</description><category>network</category><category>Critical</category><category>ivanti</category><category>epmm</category><category>mobileiron-core</category><category>mdm</category><category>authentication-bypass</category><category>cwe-287</category><category>unauthenticated</category><category>api</category><category>pii-disclosure</category><category>cisa-kev</category><category>ransomware</category><category>scanner</category></item><item><title>Check Point Security Management / Multi-Domain Server SmartConsole Authentication Bypass via Forged Application Certificate Bind (CVE-2026-16232)</title><link>https://poc.intelseclab.com/pocs/network/2026-08-09_cve-2026-16232-checkpoint-smartconsole-auth-bypass/</link><pubDate>Sun, 09 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-08-09_cve-2026-16232-checkpoint-smartconsole-auth-bypass/</guid><description>Critical severity (CVSS 9.1) — network · CVE-2026-16232. Status: Patched. Affects: Check Point Security Management Server and Multi-Domain Security Management Server (MDS) — the legacy FWM/CPMI SIC service on TCP 18190 and the CPM SOAP web services on TCP 19009. Tags: check-point, smartconsole, security-management-server, multi-domain-server, cpmi, sic, fwm, authentication-bypass, CWE-287, improper-authentication, privilege-escalation, sso-token-forgery, soap, dle, cisa-kev, bod-26-04, python, firewall-management.</description><category>network</category><category>Critical</category><category>check-point</category><category>smartconsole</category><category>security-management-server</category><category>multi-domain-server</category><category>cpmi</category><category>sic</category><category>fwm</category><category>authentication-bypass</category><category>CWE-287</category><category>improper-authentication</category><category>privilege-escalation</category><category>sso-token-forgery</category><category>soap</category><category>dle</category><category>cisa-kev</category><category>bod-26-04</category><category>python</category><category>firewall-management</category></item><item><title>CVE-2022-40684 — FortiOS / FortiProxy / FortiSwitchManager Authentication Bypass (vamp-forticheck Scanner)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-31_cve-2022-40684-fortios-auth-bypass-scanner/</link><pubDate>Fri, 31 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-31_cve-2022-40684-fortios-auth-bypass-scanner/</guid><description>Critical severity (CVSS 9.8) — network · CVE-2022-40684. Status: Patched (FortiOS ≥7.2.2, ≥7.0.7; FortiProxy ≥7.2.1, ≥7.0.7; FortiSwitchManager ≥7.2.1). Affects: Fortinet FortiOS (FortiGate firewalls), FortiProxy web proxy, FortiSwitchManager web management interface / administrative REST API. Tags: fortios, fortiproxy, fortiswitchmanager, authentication-bypass, rest-api, header-injection, loopback-spoofing, fortigate, ssl-vpn, scanner.</description><category>network</category><category>Critical</category><category>fortios</category><category>fortiproxy</category><category>fortiswitchmanager</category><category>authentication-bypass</category><category>rest-api</category><category>header-injection</category><category>loopback-spoofing</category><category>fortigate</category><category>ssl-vpn</category><category>scanner</category></item><item><title>SimpleHelp OIDC Authentication Bypass via Unverified JWT Signature (CVE-2026-48558)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-19_cve-2026-48558-simplehelp-oidc-auth-bypass/</link><pubDate>Sun, 19 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-19_cve-2026-48558-simplehelp-oidc-auth-bypass/</guid><description>Critical severity (CVSS 10) — web · CVE-2026-48558. Status: Weaponized — forges valid privileged sessions with no credentials. Affects: SimpleHelp — remote support / RMM (remote monitoring and management) platform, OIDC authentication flow. Tags: simplehelp, rmm, oidc, jwt, alg-none, cwe-347, authentication-bypass, unauthenticated, remote, kev, actively-exploited, ransomware.</description><category>web</category><category>Critical</category><category>simplehelp</category><category>rmm</category><category>oidc</category><category>jwt</category><category>alg-none</category><category>cwe-347</category><category>authentication-bypass</category><category>unauthenticated</category><category>remote</category><category>kev</category><category>actively-exploited</category><category>ransomware</category></item><item><title>Flowise Enterprise Authentication Bypass via Hardcoded Default JWT Secrets (CVE-2026-56271)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-12_cve-2026-56271-flowise-hardcoded-jwt-authbypass/</link><pubDate>Sun, 12 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-12_cve-2026-56271-flowise-hardcoded-jwt-authbypass/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-56271 (GHSA-cc4f-hjpj-g9p8). Status: Weaponized (functional PoC forges valid admin JWTs and confirms bypass against real endpoints). Affects: Flowise — open-source low-code LLM/agent orchestration platform (enterprise edition, passport authentication middleware). Tags: flowise, ai-gateway, llm-orchestration, jwt, hardcoded-secret, authentication-bypass, cwe-321, unauthenticated, remote, privilege-escalation.</description><category>web</category><category>Critical</category><category>flowise</category><category>ai-gateway</category><category>llm-orchestration</category><category>jwt</category><category>hardcoded-secret</category><category>authentication-bypass</category><category>cwe-321</category><category>unauthenticated</category><category>remote</category><category>privilege-escalation</category></item><item><title>Gitea Docker Image Reverse-Proxy Authentication Bypass — "One Header, Any User" (CVE-2026-20896)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-11_cve-2026-20896-gitea-docker-reverse-proxy-auth-bypass/</link><pubDate>Sat, 11 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-11_cve-2026-20896-gitea-docker-reverse-proxy-auth-bypass/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-20896 (GHSA-f75j-4cw6-rmx4). Status: Weaponized (public PoC + detector script, actively exploited in the wild per Sysdig). Affects: Gitea — official Docker images (gitea/gitea), both root and rootless variants. Tags: gitea, docker, authentication-bypass, reverse-proxy, header-spoofing, unauthenticated, remote, cwe-290, actively-exploited.</description><category>web</category><category>Critical</category><category>gitea</category><category>docker</category><category>authentication-bypass</category><category>reverse-proxy</category><category>header-spoofing</category><category>unauthenticated</category><category>remote</category><category>cwe-290</category><category>actively-exploited</category></item><item><title>WP Directory Kit Auto-Login Authentication Bypass to Full Site Takeover (CVE-2025-13390)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-13390-wp-directory-kit-auth-bypass/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-13390-wp-directory-kit-auth-bypass/</guid><description>Critical severity (CVSS 10) — web · CVE-2025-13390. Status: Weaponized. Affects: WP Directory Kit (WordPress plugin). Tags: wordpress, wp-directory-kit, authentication-bypass, predictable-token, account-takeover, webshell-upload, python, cwe-287.</description><category>web</category><category>Critical</category><category>wordpress</category><category>wp-directory-kit</category><category>authentication-bypass</category><category>predictable-token</category><category>account-takeover</category><category>webshell-upload</category><category>python</category><category>cwe-287</category></item><item><title>WordPress Simple Link Directory Unauthenticated Password Reset to Admin Takeover (CVE-2025-49901)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-49901-simple-link-directory-password-reset-bypass/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-49901-simple-link-directory-password-reset-bypass/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-49901. Status: Weaponized. Affects: WordPress "Simple Link Directory" plugin (qc-simple-link-directory by quantumcloud). Tags: wordpress, wordpress-plugin, simple-link-directory, qc-opd, authentication-bypass, password-reset, broken-authentication, cwe-288, username-enumeration, python.</description><category>web</category><category>Critical</category><category>wordpress</category><category>wordpress-plugin</category><category>simple-link-directory</category><category>qc-opd</category><category>authentication-bypass</category><category>password-reset</category><category>broken-authentication</category><category>cwe-288</category><category>username-enumeration</category><category>python</category></item><item><title>WordPress Service Finder Bookings ≤ 6.0 Authentication Bypass via `original_user_id` Cookie (CVE-2025-5947)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-5947-servicefinder-bookings-cookie-auth-bypass/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-5947-servicefinder-bookings-cookie-auth-bypass/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-5947. Status: Weaponized. Affects: WordPress plugin "Service Finder Bookings" (sf-booking). Tags: wordpress, service-finder-bookings, sf-booking, authentication-bypass, cookie-forgery, privilege-escalation, cwe-639.</description><category>web</category><category>Critical</category><category>wordpress</category><category>service-finder-bookings</category><category>sf-booking</category><category>authentication-bypass</category><category>cookie-forgery</category><category>privilege-escalation</category><category>cwe-639</category></item><item><title>WordPress Mobile Builder Plugin JWT Authentication Bypass to Admin Account Creation (CVE-2025-68860)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-68860-wp-jwt-admin-forge/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-68860-wp-jwt-admin-forge/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-68860. Status: Weaponized. Affects: WordPress "Mobile Builder" plugin. Tags: wordpress, mobile-builder, jwt, authentication-bypass, hardcoded-secret, privilege-escalation, rest-api, python, cwe-288.</description><category>web</category><category>Critical</category><category>wordpress</category><category>mobile-builder</category><category>jwt</category><category>authentication-bypass</category><category>hardcoded-secret</category><category>privilege-escalation</category><category>rest-api</category><category>python</category><category>cwe-288</category></item><item><title>SmarterMail Auth Bypass via Password Reset to Pre-Auth RCE (CVE-2025-52691 / WT-2026-0001)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-52691-smartermail-auth-bypass-rce/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-52691-smartermail-auth-bypass-rce/</guid><description>Critical severity (CVSS 10) — web · CVE-2025-52691. Status: Weaponized. Affects: SmarterMail (SmarterTools webmail/mail server). Tags: smartermail, smartertools, webmail, authentication-bypass, password-reset, rce, volume-mounts, pre-auth, watchtowr, python.</description><category>web</category><category>Critical</category><category>smartermail</category><category>smartertools</category><category>webmail</category><category>authentication-bypass</category><category>password-reset</category><category>rce</category><category>volume-mounts</category><category>pre-auth</category><category>watchtowr</category><category>python</category></item><item><title>RustFS Hardcoded gRPC Authentication Token Leading to Full Node Compromise (CVE-2025-68926)</title><link>https://poc.intelseclab.com/pocs/cloud/2026-07-06_cve-2025-68926-rustfs-grpc-token-bypass/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/cloud/2026-07-06_cve-2025-68926-rustfs-grpc-token-bypass/</guid><description>Critical severity (CVSS 9.8) — cloud · CVE-2025-68926. Status: Weaponized. Affects: RustFS (Rust-based S3-compatible distributed object storage) — internal node-to-node gRPC service. Tags: rustfs, grpc, hardcoded-credentials, authentication-bypass, object-storage, s3-compatible, information-disclosure, credential-theft, data-destruction, cwe-798, cwe-306.</description><category>cloud</category><category>Critical</category><category>rustfs</category><category>grpc</category><category>hardcoded-credentials</category><category>authentication-bypass</category><category>object-storage</category><category>s3-compatible</category><category>information-disclosure</category><category>credential-theft</category><category>data-destruction</category><category>cwe-798</category><category>cwe-306</category></item><item><title>RestroPress WordPress Plugin Unauthenticated Information Exposure Leading to JWT Forgery / Account Takeover (CVE-2025-9209)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-9209-restropress-jwt-forgery/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-9209-restropress-jwt-forgery/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-9209. Status: Weaponized. Affects: RestroPress – Online Food Ordering System (WordPress plugin). Tags: restropress, wordpress, wordpress-plugin, information-exposure, jwt, authentication-bypass, account-takeover, rest-api, mass-scanner, cwe-200, cwe-287, python.</description><category>web</category><category>Critical</category><category>restropress</category><category>wordpress</category><category>wordpress-plugin</category><category>information-exposure</category><category>jwt</category><category>authentication-bypass</category><category>account-takeover</category><category>rest-api</category><category>mass-scanner</category><category>cwe-200</category><category>cwe-287</category><category>python</category></item><item><title>Oracle Identity Manager `;.wadl` Authentication Bypass + Groovy Script RCE (CVE-2025-61757)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-61757-oracle-identity-manager-auth-bypass-groovy-rce/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-61757-oracle-identity-manager-auth-bypass-groovy-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-61757. Status: PoC. Affects: Oracle Identity Manager (OIM) — applicationmanagement REST API. Tags: oracle, identity-manager, oim, authentication-bypass, rce, groovy, wadl, security-filter, cwe-287, cwe-94.</description><category>web</category><category>Critical</category><category>oracle</category><category>identity-manager</category><category>oim</category><category>authentication-bypass</category><category>rce</category><category>groovy</category><category>wadl</category><category>security-filter</category><category>cwe-287</category><category>cwe-94</category></item><item><title>Mitel MiCollab Path Normalization Bypass to Internal Endpoints (CVE-2025-52913)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-52913-mitel-micollab-path-traversal/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-52913-mitel-micollab-path-traversal/</guid><description>Critical severity (CVSS 9.8) — network · CVE-2025-52913. Status: PoC. Affects: Mitel MiCollab (unified communications appliance). Tags: mitel, micollab, path-traversal, path-normalization, access-control-bypass, authentication-bypass, cwe-22, axis2, python, unified-communications.</description><category>network</category><category>Critical</category><category>mitel</category><category>micollab</category><category>path-traversal</category><category>path-normalization</category><category>access-control-bypass</category><category>authentication-bypass</category><category>cwe-22</category><category>axis2</category><category>python</category><category>unified-communications</category></item><item><title>JAY Login &amp; Register "Switch Back" Cookie Authentication Bypass (CVE-2025-14440)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-14440-jay-login-register-auth-bypass/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-14440-jay-login-register-auth-bypass/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-14440. Status: Weaponized. Affects: JAY Login &amp; Register (WordPress plugin). Tags: wordpress, jay-login-register, authentication-bypass, cookie-manipulation, unauthenticated, python, cwe-287, cwe-290.</description><category>web</category><category>Critical</category><category>wordpress</category><category>jay-login-register</category><category>authentication-bypass</category><category>cookie-manipulation</category><category>unauthenticated</category><category>python</category><category>cwe-287</category><category>cwe-290</category></item><item><title>Gladinet CentreStack / Triofox Hardcoded AES Key Access-Ticket Forgery to Arbitrary File Read (CVE-2025-14611)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-14611-centrestack-triofox-file-read/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-14611-centrestack-triofox-file-read/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-14611. Status: Weaponized. Affects: Gladinet CentreStack and Triofox (GladCtrl64.dll / filesvr.dn file-download handler). Tags: gladinet, centrestack, triofox, hardcoded-key, aes-256-cbc, access-ticket-forgery, arbitrary-file-read, authentication-bypass, iis-app-pool, python, cwe-798, cwe-321.</description><category>web</category><category>Critical</category><category>gladinet</category><category>centrestack</category><category>triofox</category><category>hardcoded-key</category><category>aes-256-cbc</category><category>access-ticket-forgery</category><category>arbitrary-file-read</category><category>authentication-bypass</category><category>iis-app-pool</category><category>python</category><category>cwe-798</category><category>cwe-321</category></item><item><title>FreePBX Framework Module Authentication Bypass via Forged Authorization Header (CVE-2025-66039)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-66039-freepbx-auth-bypass/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-66039-freepbx-auth-bypass/</guid><description>Critical severity (CVSS 9.8) — network · CVE-2025-66039. Status: PoC. Affects: FreePBX (Sangoma) framework module — web-based administration panel for Asterisk-based VoIP/PBX systems. Tags: freepbx, sangoma, voip, telephony, authentication-bypass, access-control, authtype, webserver-auth, cwe-287, cwe-863, nuclei, version-fingerprinting.</description><category>network</category><category>Critical</category><category>freepbx</category><category>sangoma</category><category>voip</category><category>telephony</category><category>authentication-bypass</category><category>access-control</category><category>authtype</category><category>webserver-auth</category><category>cwe-287</category><category>cwe-863</category><category>nuclei</category><category>version-fingerprinting</category></item><item><title>FortiWeb `cgi-bin/fwbcgi` Path Traversal Authentication Bypass Leading to Rogue Admin Creation (CVE-2025-64446)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-64446-fortiweb-cgiinfo-auth-bypass/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-64446-fortiweb-cgiinfo-auth-bypass/</guid><description>Critical severity (CVSS 9.8) — network · CVE-2025-64446. Status: PoC. Affects: Fortinet FortiWeb (Web Application Firewall appliance). Tags: fortiweb, fortinet, waf, authentication-bypass, path-traversal, cgiinfo, cwe-22, cwe-288, admin-account-creation, python.</description><category>network</category><category>Critical</category><category>fortiweb</category><category>fortinet</category><category>waf</category><category>authentication-bypass</category><category>path-traversal</category><category>cgiinfo</category><category>cwe-22</category><category>cwe-288</category><category>admin-account-creation</category><category>python</category></item><item><title>FortiOS/FortiProxy/FortiSwitchManager/FortiWeb FortiCloud SSO Authentication Bypass Detection Tool (CVE-2025-59718)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-59718-fortios-version-detection-scanner/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-59718-fortios-version-detection-scanner/</guid><description>Critical severity (CVSS 9.8) — network · CVE-2025-59718 (Fortinet advisory FG-IR-25-647; related: CVE-2025-59719). Status: PoC. Affects: Fortinet FortiOS, FortiProxy, FortiSwitchManager, FortiWeb. Tags: fortinet, fortios, fortiproxy, fortiswitchmanager, fortiweb, forticloud-sso, authentication-bypass, version-detection, ssh, scanner, cwe-347.</description><category>network</category><category>Critical</category><category>fortinet</category><category>fortios</category><category>fortiproxy</category><category>fortiswitchmanager</category><category>fortiweb</category><category>forticloud-sso</category><category>authentication-bypass</category><category>version-detection</category><category>ssh</category><category>scanner</category><category>cwe-347</category></item><item><title>CrushFTP AS2 Header Authentication Bypass (CVE-2025-54309)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-54309-crushftp-as2-auth-bypass/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-54309-crushftp-as2-auth-bypass/</guid><description>Critical severity (CVSS 9) — web · CVE-2025-54309. Status: Patched. Affects: CrushFTP server, AS2 (Applicability Statement 2) authentication module / web admin interface. Tags: crushftp, as2, authentication-bypass, cwe-287, cwe-306, cwe-807, session-hijacking, shell, ftp-server.</description><category>web</category><category>Critical</category><category>crushftp</category><category>as2</category><category>authentication-bypass</category><category>cwe-287</category><category>cwe-306</category><category>cwe-807</category><category>session-hijacking</category><category>shell</category><category>ftp-server</category></item><item><title>Apache mod_ssl TLS 1.3 Session Resumption Client Certificate Bypass (CVE-2025-23048)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-23048-apache-tls13-session-resumption-client-cert-bypass/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-23048-apache-tls13-session-resumption-client-cert-bypass/</guid><description>Critical severity (CVSS 9.1) — web · CVE-2025-23048. Status: PoC. Affects: Apache HTTP Server (mod_ssl). Tags: apache, mod_ssl, httpd, tls1.3, session-resumption, client-certificate, authentication-bypass, cwe-295, openssl.</description><category>web</category><category>Critical</category><category>apache</category><category>mod_ssl</category><category>httpd</category><category>tls1.3</category><category>session-resumption</category><category>client-certificate</category><category>authentication-bypass</category><category>cwe-295</category><category>openssl</category></item><item><title>Apache Druid Kerberos Cookie-Signing Secret Recovery via ThreadLocalRandom Seed Inversion (CVE-2025-59390)</title><link>https://poc.intelseclab.com/pocs/crypto/2026-07-06_cve-2025-59390-druid-kerberos-threadlocalrandom-seed-recovery/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/crypto/2026-07-06_cve-2025-59390-druid-kerberos-threadlocalrandom-seed-recovery/</guid><description>Critical severity (CVSS 9.8) — crypto · CVE-2025-59390. Status: PoC. Affects: Apache Druid — Kerberos authenticator (druid.auth.authenticator.kerberos). Tags: apache-druid, kerberos, threadlocalrandom, prng, seed-recovery, cookie-forgery, authentication-bypass, cwe-338.</description><category>crypto</category><category>Critical</category><category>apache-druid</category><category>kerberos</category><category>threadlocalrandom</category><category>prng</category><category>seed-recovery</category><category>cookie-forgery</category><category>authentication-bypass</category><category>cwe-338</category></item><item><title>YAMCS LdapAuthModule LDAP Injection Authentication Bypass (CVE-2026-42568)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-42568-yamcs-ldap-injection/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-42568-yamcs-ldap-injection/</guid><description>Medium severity — network · CVE-2026-42568 / GHSA-cqh3-jg8p-336j. Status: PoC. Affects: YAMCS (org.yamcs.security.LdapAuthModule). Tags: ldap-injection, authentication-bypass, yamcs, ldap, python, cwe-90.</description><category>network</category><category>Medium</category><category>ldap-injection</category><category>authentication-bypass</category><category>yamcs</category><category>ldap</category><category>python</category><category>cwe-90</category></item><item><title>SmarterMail Admin Password-Reset Authentication Bypass (CVE-2026-23760)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-23760-smartermail-auth-bypass/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-23760-smartermail-auth-bypass/</guid><description>Critical severity (CVSS 9.3) — web · CVE-2026-23760. Status: PoC. Affects: SmarterTools SmarterMail. Tags: smartermail, authentication-bypass, password-reset, account-takeover, rce, email-server, watchtowr.</description><category>web</category><category>Critical</category><category>smartermail</category><category>authentication-bypass</category><category>password-reset</category><category>account-takeover</category><category>rce</category><category>email-server</category><category>watchtowr</category></item><item><title>Rack::Session::Cookie Decrypt-Failure Fallback to Unencrypted Cookies (CVE-2026-39324)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-39324-rack-session-cookie-forgery/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-39324-rack-session-cookie-forgery/</guid><description>Critical severity — web · CVE-2026-39324 / GHSA-33qg-7wpp-89cq. Status: PoC. Affects: rack-session (RubyGems), Rack::Session::Cookie with secrets: option. Tags: ruby, rack, session-forgery, cookie, authentication-bypass, ruby-on-rails-adjacent, cwe-287.</description><category>web</category><category>Critical</category><category>ruby</category><category>rack</category><category>session-forgery</category><category>cookie</category><category>authentication-bypass</category><category>ruby-on-rails-adjacent</category><category>cwe-287</category></item><item><title>Nextcloud user_oidc ID4me JWT Signature Bypass (CVE-2026-45156)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-45156-nextcloud-id4me-jwt-bypass/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-45156-nextcloud-id4me-jwt-bypass/</guid><description>High severity (CVSS 8.1) — web · CVE-2026-45156. Status: PoC. Affects: Nextcloud user_oidc app — ID4me identity provider integration. Tags: nextcloud, user_oidc, id4me, jwt, alg-none, authentication-bypass, cwe-347.</description><category>web</category><category>High</category><category>nextcloud</category><category>user_oidc</category><category>id4me</category><category>jwt</category><category>alg-none</category><category>authentication-bypass</category><category>cwe-347</category></item><item><title>LiteLLM Authentication Bypass via OIDC Userinfo Cache Key Collision (CVE-2026-35030)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-35030-litellm-oidc-cache-collision-authbypass/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-35030-litellm-oidc-cache-collision-authbypass/</guid><description>Critical severity (CVSS 9.1) — web · CVE-2026-35030. Status: Weaponized. Affects: LiteLLM proxy (with enable_jwt_auth: true). Tags: authentication-bypass, litellm, oidc, jwt, cache-collision, ai-gateway, cwe-287.</description><category>web</category><category>Critical</category><category>authentication-bypass</category><category>litellm</category><category>oidc</category><category>jwt</category><category>cache-collision</category><category>ai-gateway</category><category>cwe-287</category></item><item><title>Keycloak Unauthorized Organization Registration via Invitation Token Flaw — CVE-2026-1529</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-1529-keycloak-org-registration-bypass/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-1529-keycloak-org-registration-bypass/</guid><description>Critical severity — web · CVE-2026-1529. Status: PoC. Affects: Keycloak (organization/invitation feature). Tags: keycloak, jwt, invitation-token, organization-registration, authentication-bypass, sso, wordpress-adjacent, identity-provider.</description><category>web</category><category>Critical</category><category>keycloak</category><category>jwt</category><category>invitation-token</category><category>organization-registration</category><category>authentication-bypass</category><category>sso</category><category>wordpress-adjacent</category><category>identity-provider</category></item><item><title>JeecgBoot mLogin Endpoint CAPTCHA Bypass Enabling Credential Brute Force (CVE-2026-8196)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-8196-jeecgboot-mlogin-captcha-bypass/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-8196-jeecgboot-mlogin-captcha-bypass/</guid><description>High severity — web · CVE-2026-8196. Status: PoC. Affects: JeecgBoot (/sys/mLogin endpoint). Tags: jeecgboot, captcha-bypass, credential-stuffing, brute-force, missing-rate-limiting, authentication-bypass.</description><category>web</category><category>High</category><category>jeecgboot</category><category>captcha-bypass</category><category>credential-stuffing</category><category>brute-force</category><category>missing-rate-limiting</category><category>authentication-bypass</category></item><item><title>HPE Aruba AOS-CX Pre-Auth REST API Bypass via nginx Version Smuggling (CVE-2026-23813)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-23813-aruba-aoscx-auth-bypass/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-23813-aruba-aoscx-auth-bypass/</guid><description>Critical severity (CVSS 9.8) — network · CVE-2026-23813. Status: PoC. Affects: HPE Aruba Networking AOS-CX. Tags: aruba, aos-cx, authentication-bypass, nginx, ovsdb, network-switch, config-disclosure, cwe-287.</description><category>network</category><category>Critical</category><category>aruba</category><category>aos-cx</category><category>authentication-bypass</category><category>nginx</category><category>ovsdb</category><category>network-switch</category><category>config-disclosure</category><category>cwe-287</category></item><item><title>Hippoo Mobile App for WooCommerce — Unauthenticated Admin Account Takeover (CVE-2026-10580)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-10580-hippoo-woocommerce-authbypass/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-10580-hippoo-woocommerce-authbypass/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-10580. Status: Weaponized. Affects: Hippoo Mobile App for WooCommerce (WordPress plugin). Tags: wordpress, plugin, woocommerce, hippoo, authentication-bypass, account-takeover, rest-api, unauthenticated.</description><category>web</category><category>Critical</category><category>wordpress</category><category>plugin</category><category>woocommerce</category><category>hippoo</category><category>authentication-bypass</category><category>account-takeover</category><category>rest-api</category><category>unauthenticated</category></item><item><title>GNU inetutils telnetd Local Privilege Escalation via NEW-ENVIRON Injection — CVE-2026-28372</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-28372-telnetd-lpe/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-28372-telnetd-lpe/</guid><description>High severity (CVSS 7.4) — binary · CVE-2026-28372. Status: PoC. Affects: GNU inetutils telnetd. Tags: telnetd, inetutils, lpe, new-environ, login-noauth, authentication-bypass, privilege-escalation, util-linux.</description><category>binary</category><category>High</category><category>telnetd</category><category>inetutils</category><category>lpe</category><category>new-environ</category><category>login-noauth</category><category>authentication-bypass</category><category>privilege-escalation</category><category>util-linux</category></item><item><title>Form Notify WordPress Plugin — LINE OAuth Authentication Bypass to Account Takeover (CVE-2026-5229)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-5229-form-notify-line-oauth-bypass/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-5229-form-notify-line-oauth-bypass/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-5229. Status: PoC. Affects: Form Notify WordPress plugin, LINE Login OAuth 2.0 integration (src/APIs/Line/Login/Route.php, User.php). Tags: wordpress, form-notify, oauth, line-login, authentication-bypass, account-takeover, cookie-injection, cve-2026-5229.</description><category>web</category><category>Critical</category><category>wordpress</category><category>form-notify</category><category>oauth</category><category>line-login</category><category>authentication-bypass</category><category>account-takeover</category><category>cookie-injection</category><category>cve-2026-5229</category></item><item><title>diskover-community — CSRF Leading to Authentication Bypass (CVE-2026-38934)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-38934-diskover-community-csrf-authbypass/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-38934-diskover-community-csrf-authbypass/</guid><description>High severity (CVSS 8.8) — web · CVE-2026-38934. Status: PoC. Affects: diskover-community. Tags: diskover, csrf, authentication-bypass, php, elasticsearch, settings-tampering.</description><category>web</category><category>High</category><category>diskover</category><category>csrf</category><category>authentication-bypass</category><category>php</category><category>elasticsearch</category><category>settings-tampering</category></item><item><title>CodeAstro Simple Attendance Management System 1.0 — SQL Injection Auth Bypass (CVE-2026-37749)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-37749-attendance-management-sqli-authbypass/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-37749-attendance-management-sqli-authbypass/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-37749. Status: PoC. Affects: CodeAstro Simple Attendance Management System 1.0. Tags: php, sql-injection, authentication-bypass, cwe-89, unauthenticated, codeastro.</description><category>web</category><category>Critical</category><category>php</category><category>sql-injection</category><category>authentication-bypass</category><category>cwe-89</category><category>unauthenticated</category><category>codeastro</category></item><item><title>Cisco Catalyst SD-WAN Peering Authentication Bypass — CVE-2026-20182</title><link>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-20182-cisco-sdwan-auth-bypass/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-20182-cisco-sdwan-auth-bypass/</guid><description>Critical severity (CVSS 10) — network · CVE-2026-20182. Status: Weaponized. Affects: Cisco Catalyst SD-WAN Controller (formerly vSmart) and Cisco Catalyst SD-WAN Manager (formerly vManage) — vdaemon control-connection process. Tags: cisco, sd-wan, vdaemon, dtls, authentication-bypass, netconf, vmanage, vsmart.</description><category>network</category><category>Critical</category><category>cisco</category><category>sd-wan</category><category>vdaemon</category><category>dtls</category><category>authentication-bypass</category><category>netconf</category><category>vmanage</category><category>vsmart</category></item><item><title>Burst Statistics WordPress Plugin Authentication Bypass to Admin Account Takeover (CVE-2026-8181)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-8181-burst-statistics-auth-bypass/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-8181-burst-statistics-auth-bypass/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-8181. Status: PoC. Affects: Burst Statistics – Privacy-Friendly WordPress Analytics (burst-statistics plugin). Tags: wordpress, burst-statistics, authentication-bypass, cwe-287, application-password, account-takeover, mainwp.</description><category>web</category><category>Critical</category><category>wordpress</category><category>burst-statistics</category><category>authentication-bypass</category><category>cwe-287</category><category>application-password</category><category>account-takeover</category><category>mainwp</category></item><item><title>Apache HTTP Server mod_auth_digest Timing Attack — CVE-2026-33006</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-33006-apache-mod-auth-digest-timing/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-33006-apache-mod-auth-digest-timing/</guid><description>Medium severity (CVSS 4.8) — web · CVE-2026-33006. Status: PoC. Affects: Apache HTTP Server (mod_auth_digest module). Tags: apache, mod_auth_digest, timing-attack, authentication-bypass, digest-auth, http, side-channel.</description><category>web</category><category>Medium</category><category>apache</category><category>mod_auth_digest</category><category>timing-attack</category><category>authentication-bypass</category><category>digest-auth</category><category>http</category><category>side-channel</category></item><item><title>Apache APISIX forward-auth CRLF Header Injection — CVE-2026-31908</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-31908-apisix-crlf-header-injection/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-31908-apisix-crlf-header-injection/</guid><description>Critical severity (CVSS 10) — web · CVE-2026-31908. Status: PoC. Affects: Apache APISIX. Tags: apisix, crlf-injection, header-injection, authentication-bypass, forward-auth, api-gateway, reverse-proxy.</description><category>web</category><category>Critical</category><category>apisix</category><category>crlf-injection</category><category>header-injection</category><category>authentication-bypass</category><category>forward-auth</category><category>api-gateway</category><category>reverse-proxy</category></item><item><title>Apache Airflow AWS Auth Manager SAML Host Header Injection (CVE-2026-25604)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-25604-airflow-saml-host-header-injection/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-25604-airflow-saml-host-header-injection/</guid><description>High severity — web · CVE-2026-25604. Status: PoC. Affects: Apache Airflow — apache-airflow-providers-amazon (AWS Auth Manager). Tags: saml, host-header-injection, authentication-bypass, apache-airflow, aws-iam-identity-center, cwe-346, origin-validation, token-replay.</description><category>web</category><category>High</category><category>saml</category><category>host-header-injection</category><category>authentication-bypass</category><category>apache-airflow</category><category>aws-iam-identity-center</category><category>cwe-346</category><category>origin-validation</category><category>token-replay</category></item><item><title>AdForest WordPress Theme OTP Login Authentication Bypass — CVE-2026-1729</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-1729-adforest-wp-auth-bypass/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-1729-adforest-wp-auth-bypass/</guid><description>Critical severity — web · CVE-2026-1729. Status: PoC. Affects: AdForest theme for WordPress. Tags: wordpress, adforest-theme, authentication-bypass, otp-login, ajax, admin-takeover, unauthenticated.</description><category>web</category><category>Critical</category><category>wordpress</category><category>adforest-theme</category><category>authentication-bypass</category><category>otp-login</category><category>ajax</category><category>admin-takeover</category><category>unauthenticated</category></item><item><title>NodeBB ActivityPub attributedTo Local UID Spoof</title><link>https://poc.intelseclab.com/pocs/web/2026-07-03_nodebb-activitypub-uid-spoof/</link><pubDate>Fri, 03 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-03_nodebb-activitypub-uid-spoof/</guid><description>High severity — web · None assigned as of 2026-07-03. Status: PoC. Affects: NodeBB — ActivityPub server-to-server inbox. Tags: nodebb, activitypub, federation, authentication-bypass, spoofing, uid-forgery, forum-software, nodejs.</description><category>web</category><category>High</category><category>nodebb</category><category>activitypub</category><category>federation</category><category>authentication-bypass</category><category>spoofing</category><category>uid-forgery</category><category>forum-software</category><category>nodejs</category></item><item><title>Fortinet FortiClient EMS Pre-Auth Bypass — "FortiBleed" (CVE-2026-35616)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-03_cve-2026-35616-forticlient-ems-auth-bypass/</link><pubDate>Fri, 03 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-03_cve-2026-35616-forticlient-ems-auth-bypass/</guid><description>Critical severity (CVSS 9.1) — network · CVE-2026-35616. Status: Weaponized. Affects: Fortinet FortiClient Endpoint Management Server (EMS). Tags: authentication-bypass, header-spoofing, Fortinet, FortiClient-EMS, FortiBleed, credential-theft, CISA-KEV, active-exploitation, ransomware.</description><category>network</category><category>Critical</category><category>authentication-bypass</category><category>header-spoofing</category><category>Fortinet</category><category>FortiClient-EMS</category><category>FortiBleed</category><category>credential-theft</category><category>CISA-KEV</category><category>active-exploitation</category><category>ransomware</category></item><item><title>libcurl mTLS Connection Reuse Authentication Bypass (CVE-2026-8932)</title><link>https://poc.intelseclab.com/pocs/network/2026-06-30_cve-2026-8932-libcurl-mtls-auth-bypass/</link><pubDate>Tue, 30 Jun 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-06-30_cve-2026-8932-libcurl-mtls-auth-bypass/</guid><description>Low severity — network · CVE-2026-8932. Status: PoC. Affects: libcurl (embedded library; standalone curl CLI unaffected). Tags: authentication-bypass, mTLS, TLS, libcurl, connection-reuse, client-certificate, C, Low.</description><category>network</category><category>Low</category><category>authentication-bypass</category><category>mTLS</category><category>TLS</category><category>libcurl</category><category>connection-reuse</category><category>client-certificate</category><category>C</category><category>Low</category></item><item><title>GNU Inetutils telnetd Unauthenticated Root RCE via NEW-ENVIRON (CVE-2026-24061)</title><link>https://poc.intelseclab.com/pocs/network/2026-06-30_cve-2026-24061-gnu-telnetd-rce/</link><pubDate>Tue, 30 Jun 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-06-30_cve-2026-24061-gnu-telnetd-rce/</guid><description>Critical severity (CVSS 9.8) — network · CVE-2026-24061. Status: Weaponized. Affects: GNU Inetutils telnetd. Tags: RCE, unauthenticated, authentication-bypass, telnetd, GNU-Inetutils, NEW-ENVIRON, legacy, OT, CISA-KEV, active-exploitation, Python.</description><category>network</category><category>Critical</category><category>RCE</category><category>unauthenticated</category><category>authentication-bypass</category><category>telnetd</category><category>GNU-Inetutils</category><category>NEW-ENVIRON</category><category>legacy</category><category>OT</category><category>CISA-KEV</category><category>active-exploitation</category><category>Python</category></item></channel></rss>