<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Cwe-287 — PoC Archive</title><link>https://poc.intelseclab.com/tags/cwe-287/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sun, 09 Aug 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/cwe-287/index.xml" rel="self" type="application/rss+xml"/><item><title>Ivanti Endpoint Manager Mobile (EPMM) Unauthenticated Remote API Access (CVE-2023-35078)</title><link>https://poc.intelseclab.com/pocs/network/2026-08-09_cve-2023-35078-ivanti-epmm-unauth-api-access/</link><pubDate>Sun, 09 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-08-09_cve-2023-35078-ivanti-epmm-unauth-api-access/</guid><description>Critical severity (CVSS 9.8) — network · CVE-2023-35078 (Ivanti advisory; CWE-287 per NVD). Status: Patched (Ivanti EPMM 11.8.1.1, 11.9.1.1, 11.10.0.2 and later). Affects: Ivanti Endpoint Manager Mobile (EPMM), previously branded MobileIron Core — the /mifs/aad/api/ administrative API surface. Tags: ivanti, epmm, mobileiron-core, mdm, authentication-bypass, cwe-287, unauthenticated, api, pii-disclosure, cisa-kev, ransomware, scanner.</description><category>network</category><category>Critical</category><category>ivanti</category><category>epmm</category><category>mobileiron-core</category><category>mdm</category><category>authentication-bypass</category><category>cwe-287</category><category>unauthenticated</category><category>api</category><category>pii-disclosure</category><category>cisa-kev</category><category>ransomware</category><category>scanner</category></item><item><title>Check Point Security Management / Multi-Domain Server SmartConsole Authentication Bypass via Forged Application Certificate Bind (CVE-2026-16232)</title><link>https://poc.intelseclab.com/pocs/network/2026-08-09_cve-2026-16232-checkpoint-smartconsole-auth-bypass/</link><pubDate>Sun, 09 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-08-09_cve-2026-16232-checkpoint-smartconsole-auth-bypass/</guid><description>Critical severity (CVSS 9.1) — network · CVE-2026-16232. Status: Patched. Affects: Check Point Security Management Server and Multi-Domain Security Management Server (MDS) — the legacy FWM/CPMI SIC service on TCP 18190 and the CPM SOAP web services on TCP 19009. Tags: check-point, smartconsole, security-management-server, multi-domain-server, cpmi, sic, fwm, authentication-bypass, CWE-287, improper-authentication, privilege-escalation, sso-token-forgery, soap, dle, cisa-kev, bod-26-04, python, firewall-management.</description><category>network</category><category>Critical</category><category>check-point</category><category>smartconsole</category><category>security-management-server</category><category>multi-domain-server</category><category>cpmi</category><category>sic</category><category>fwm</category><category>authentication-bypass</category><category>CWE-287</category><category>improper-authentication</category><category>privilege-escalation</category><category>sso-token-forgery</category><category>soap</category><category>dle</category><category>cisa-kev</category><category>bod-26-04</category><category>python</category><category>firewall-management</category></item><item><title>Xiongmai XM530 IP Camera ONVIF Authentication Bypass (CVE-2025-65856)</title><link>https://poc.intelseclab.com/pocs/hardware/2026-07-06_cve-2025-65856-onvif-camera-auth-bypass/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/hardware/2026-07-06_cve-2025-65856-onvif-camera-auth-bypass/</guid><description>Critical severity (CVSS 9.8) — hardware · CVE-2025-65856. Status: Weaponized. Affects: Xiongmai XM530-based IP camera ONVIF service (tested on model XM530_50X50-WG_8M). Tags: xiongmai, xm530, onvif, ip-camera, iot, auth-bypass, access-control, information-disclosure, rtsp, cwe-306, cwe-287, python, bash, curl.</description><category>hardware</category><category>Critical</category><category>xiongmai</category><category>xm530</category><category>onvif</category><category>ip-camera</category><category>iot</category><category>auth-bypass</category><category>access-control</category><category>information-disclosure</category><category>rtsp</category><category>cwe-306</category><category>cwe-287</category><category>python</category><category>bash</category><category>curl</category></item><item><title>WP Directory Kit Auto-Login Authentication Bypass to Full Site Takeover (CVE-2025-13390)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-13390-wp-directory-kit-auth-bypass/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-13390-wp-directory-kit-auth-bypass/</guid><description>Critical severity (CVSS 10) — web · CVE-2025-13390. Status: Weaponized. Affects: WP Directory Kit (WordPress plugin). Tags: wordpress, wp-directory-kit, authentication-bypass, predictable-token, account-takeover, webshell-upload, python, cwe-287.</description><category>web</category><category>Critical</category><category>wordpress</category><category>wp-directory-kit</category><category>authentication-bypass</category><category>predictable-token</category><category>account-takeover</category><category>webshell-upload</category><category>python</category><category>cwe-287</category></item><item><title>RestroPress WordPress Plugin Unauthenticated Information Exposure Leading to JWT Forgery / Account Takeover (CVE-2025-9209)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-9209-restropress-jwt-forgery/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-9209-restropress-jwt-forgery/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-9209. Status: Weaponized. Affects: RestroPress – Online Food Ordering System (WordPress plugin). Tags: restropress, wordpress, wordpress-plugin, information-exposure, jwt, authentication-bypass, account-takeover, rest-api, mass-scanner, cwe-200, cwe-287, python.</description><category>web</category><category>Critical</category><category>restropress</category><category>wordpress</category><category>wordpress-plugin</category><category>information-exposure</category><category>jwt</category><category>authentication-bypass</category><category>account-takeover</category><category>rest-api</category><category>mass-scanner</category><category>cwe-200</category><category>cwe-287</category><category>python</category></item><item><title>PrestaShop Checkout Zero-Click Account Takeover via ExpressCheckout Endpoint (CVE-2025-61922)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-61922-prestashop-checkout-account-takeover/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-61922-prestashop-checkout-account-takeover/</guid><description>Critical severity (CVSS 9.1) — web · CVE-2025-61922. Status: PoC. Affects: PrestaShop Checkout module (ps_checkout). Tags: prestashop, ps_checkout, account-takeover, express-checkout, paypal, zero-click, session-hijacking, e-commerce, cwe-287.</description><category>web</category><category>Critical</category><category>prestashop</category><category>ps_checkout</category><category>account-takeover</category><category>express-checkout</category><category>paypal</category><category>zero-click</category><category>session-hijacking</category><category>e-commerce</category><category>cwe-287</category></item><item><title>Oracle Identity Manager `;.wadl` Authentication Bypass + Groovy Script RCE (CVE-2025-61757)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-61757-oracle-identity-manager-auth-bypass-groovy-rce/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-61757-oracle-identity-manager-auth-bypass-groovy-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-61757. Status: PoC. Affects: Oracle Identity Manager (OIM) — applicationmanagement REST API. Tags: oracle, identity-manager, oim, authentication-bypass, rce, groovy, wadl, security-filter, cwe-287, cwe-94.</description><category>web</category><category>Critical</category><category>oracle</category><category>identity-manager</category><category>oim</category><category>authentication-bypass</category><category>rce</category><category>groovy</category><category>wadl</category><category>security-filter</category><category>cwe-287</category><category>cwe-94</category></item><item><title>JAY Login &amp; Register "Switch Back" Cookie Authentication Bypass (CVE-2025-14440)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-14440-jay-login-register-auth-bypass/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-14440-jay-login-register-auth-bypass/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-14440. Status: Weaponized. Affects: JAY Login &amp; Register (WordPress plugin). Tags: wordpress, jay-login-register, authentication-bypass, cookie-manipulation, unauthenticated, python, cwe-287, cwe-290.</description><category>web</category><category>Critical</category><category>wordpress</category><category>jay-login-register</category><category>authentication-bypass</category><category>cookie-manipulation</category><category>unauthenticated</category><category>python</category><category>cwe-287</category><category>cwe-290</category></item><item><title>Grafana Enterprise SCIM User ID Collision / Impersonation (CVE-2025-41115)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-41115-grafana-scim-user-impersonation/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-41115-grafana-scim-user-impersonation/</guid><description>Critical severity (CVSS 10) — web · CVE-2025-41115. Status: PoC. Affects: Grafana Enterprise / Grafana Cloud, SCIM provisioning component (/api/scim/v2/Users). Tags: grafana, grafana-enterprise, scim, user-impersonation, privilege-escalation, id-collision, python, docker, cwe-287.</description><category>web</category><category>Critical</category><category>grafana</category><category>grafana-enterprise</category><category>scim</category><category>user-impersonation</category><category>privilege-escalation</category><category>id-collision</category><category>python</category><category>docker</category><category>cwe-287</category></item><item><title>FreePBX Framework Module Authentication Bypass via Forged Authorization Header (CVE-2025-66039)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-66039-freepbx-auth-bypass/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-66039-freepbx-auth-bypass/</guid><description>Critical severity (CVSS 9.8) — network · CVE-2025-66039. Status: PoC. Affects: FreePBX (Sangoma) framework module — web-based administration panel for Asterisk-based VoIP/PBX systems. Tags: freepbx, sangoma, voip, telephony, authentication-bypass, access-control, authtype, webserver-auth, cwe-287, cwe-863, nuclei, version-fingerprinting.</description><category>network</category><category>Critical</category><category>freepbx</category><category>sangoma</category><category>voip</category><category>telephony</category><category>authentication-bypass</category><category>access-control</category><category>authtype</category><category>webserver-auth</category><category>cwe-287</category><category>cwe-863</category><category>nuclei</category><category>version-fingerprinting</category></item><item><title>CrushFTP AS2 Header Authentication Bypass (CVE-2025-54309)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-54309-crushftp-as2-auth-bypass/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-54309-crushftp-as2-auth-bypass/</guid><description>Critical severity (CVSS 9) — web · CVE-2025-54309. Status: Patched. Affects: CrushFTP server, AS2 (Applicability Statement 2) authentication module / web admin interface. Tags: crushftp, as2, authentication-bypass, cwe-287, cwe-306, cwe-807, session-hijacking, shell, ftp-server.</description><category>web</category><category>Critical</category><category>crushftp</category><category>as2</category><category>authentication-bypass</category><category>cwe-287</category><category>cwe-306</category><category>cwe-807</category><category>session-hijacking</category><category>shell</category><category>ftp-server</category></item><item><title>Rack::Session::Cookie Decrypt-Failure Fallback to Unencrypted Cookies (CVE-2026-39324)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-39324-rack-session-cookie-forgery/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-39324-rack-session-cookie-forgery/</guid><description>Critical severity — web · CVE-2026-39324 / GHSA-33qg-7wpp-89cq. Status: PoC. Affects: rack-session (RubyGems), Rack::Session::Cookie with secrets: option. Tags: ruby, rack, session-forgery, cookie, authentication-bypass, ruby-on-rails-adjacent, cwe-287.</description><category>web</category><category>Critical</category><category>ruby</category><category>rack</category><category>session-forgery</category><category>cookie</category><category>authentication-bypass</category><category>ruby-on-rails-adjacent</category><category>cwe-287</category></item><item><title>PocketBase OAuth2 Account Pre-Hijacking (CVE-2026-44166)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-44166-pocketbase-oauth2-account-prehijack/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-44166-pocketbase-oauth2-account-prehijack/</guid><description>Medium severity (CVSS 6.1) — web · CVE-2026-44166 / [GHSA-pq7p-mc74-g65w](https://github.com/pocketbase/pocketbase/security/advisories/GHSA-pq7p-mc74-g65w). Status: PoC. Affects: [PocketBase](https://github.com/pocketbase/pocketbase) (Go backend / BaaS). Tags: pocketbase, oauth2, account-takeover, account-pre-hijacking, cwe-287, improper-authentication, go.</description><category>web</category><category>Medium</category><category>pocketbase</category><category>oauth2</category><category>account-takeover</category><category>account-pre-hijacking</category><category>cwe-287</category><category>improper-authentication</category><category>go</category></item><item><title>LiteLLM Authentication Bypass via OIDC Userinfo Cache Key Collision (CVE-2026-35030)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-35030-litellm-oidc-cache-collision-authbypass/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-35030-litellm-oidc-cache-collision-authbypass/</guid><description>Critical severity (CVSS 9.1) — web · CVE-2026-35030. Status: Weaponized. Affects: LiteLLM proxy (with enable_jwt_auth: true). Tags: authentication-bypass, litellm, oidc, jwt, cache-collision, ai-gateway, cwe-287.</description><category>web</category><category>Critical</category><category>authentication-bypass</category><category>litellm</category><category>oidc</category><category>jwt</category><category>cache-collision</category><category>ai-gateway</category><category>cwe-287</category></item><item><title>HPE Aruba AOS-CX Pre-Auth REST API Bypass via nginx Version Smuggling (CVE-2026-23813)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-23813-aruba-aoscx-auth-bypass/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-23813-aruba-aoscx-auth-bypass/</guid><description>Critical severity (CVSS 9.8) — network · CVE-2026-23813. Status: PoC. Affects: HPE Aruba Networking AOS-CX. Tags: aruba, aos-cx, authentication-bypass, nginx, ovsdb, network-switch, config-disclosure, cwe-287.</description><category>network</category><category>Critical</category><category>aruba</category><category>aos-cx</category><category>authentication-bypass</category><category>nginx</category><category>ovsdb</category><category>network-switch</category><category>config-disclosure</category><category>cwe-287</category></item><item><title>Burst Statistics WordPress Plugin Authentication Bypass to Admin Account Takeover (CVE-2026-8181)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-8181-burst-statistics-auth-bypass/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-8181-burst-statistics-auth-bypass/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-8181. Status: PoC. Affects: Burst Statistics – Privacy-Friendly WordPress Analytics (burst-statistics plugin). Tags: wordpress, burst-statistics, authentication-bypass, cwe-287, application-password, account-takeover, mainwp.</description><category>web</category><category>Critical</category><category>wordpress</category><category>burst-statistics</category><category>authentication-bypass</category><category>cwe-287</category><category>application-password</category><category>account-takeover</category><category>mainwp</category></item></channel></rss>